INSIGHT // 43 Critical Compliance

NIS2 in Austria: The NISG 2026 Cybersecurity Deadline for US Pharma R&D

Abstract: Austria was among the last EU Member States to transpose the NIS2 Directive. Its NISG 2026, promulgated on 23 December 2025, does not begin to apply until 1 October 2026, when a newly created federal cybersecurity authority takes up its functions and a registration duty, a self-declaration clock, and a staged proof-of-implementation regime start to run against in-scope pharmaceutical research and development entities. For US pharma groups with Austrian research sites, the operative date is this back-loaded national timetable, not the missed 2024 EU deadline, and the ordinances that will define what compliance actually requires were still to come as of publication.
Plain Language Summary

The EU's NIS2 Directive requires organizations in critical sectors, including pharmaceutical research and development, to meet mandatory cybersecurity standards. Austria transposed it late, through a national law called the NISG 2026 (the kind of horizontal cybersecurity statute the United States does not have at the federal level). The Austrian law was published in December 2025 but takes effect only on 1 October 2026. After that date, affected companies must register with a newly created authority, report the security measures they have put in place, and later prove that those measures work. For a US pharmaceutical company running a research site in Austria, the practical questions are when the clock starts, what the company has to show, and to which regulator.

Table of Contents
  1. An October Date, Not an October Deadline
  2. Health, Research, or Neither
  3. A New Authority and a Cascade
  4. Reporting Clocks and Board Liability
  5. Strategic Considerations

US pharmaceutical groups with research operations in Austria have spent the period since October 2024 under a comfortable misreading. The EU deadline for transposing the NIS2 Directive passed on 17 October 2024, Austria did not meet it, and a US general counsel scanning the headlines could reasonably conclude either that Austrian cybersecurity obligations already bind the company or that they remain indefinitely stalled. Neither is correct. Austria put its transposition on the statute book on 23 December 2025, and the obligations begin to apply on 1 October 2026. The date that matters is still in the future, and it behaves less like a deadline than like a starting gun.

1. An October Date, Not an October Deadline

The instinct a US legal team brings to this is shaped by the absence of a domestic analogue. The United States has no horizontal federal cybersecurity statute that regulates private companies by sector; what exists is a patchwork of state breach-notification laws, sectoral rules, and a securities-disclosure overlay in the form of the SEC cyber-incident Item 1.05 Form 8-K obligation. Against that baseline, the NIS2 Directive reads as a single instrument with a single 2024 date.1Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) [2022] OJ L333/80; Art. 41 (transposition by 17 October 2024, application from 18 October 2024). The Directive, however, does not regulate companies directly. It obliges Member States to legislate, and the operative obligations are the national ones. Austria's national instrument is the Netz- und Informationssystemsicherheitsgesetz 2026, the NISG 2026.

Getting from the Directive to that national instrument took Austria almost three years from the Directive's entry into force on 16 January 2023. A first attempt, the NISG 2024 draft, foundered in the Nationalrat on 3 July 2024 because its constitutional provisions could not reach the two-thirds majority that a Verfassungsbestimmung requires. Austria then missed the 17 October 2024 transposition deadline, and the European Commission opened infringement proceedings, issuing a letter of formal notice in November 2024 and a reasoned opinion, the stage before referral to the Court of Justice, in May 2025.2NISG 2024 draft rejected by the Nationalrat on 3 July 2024 for want of the two-thirds majority required for its constitutional provisions; European Commission letter of formal notice (23 Member States) of 28 November 2024 and reasoned opinion (19 Member States, incl. Austria) of 7 May 2025 for non-notification of full NIS2 transposition. Only with a new federal government in place did the second attempt succeed. The NISG 2026 was promulgated in the Bundesgesetzblatt as BGBl I 94/2025 on 23 December 2025, again carrying a constitutional provision, and it provides for entry into force nine months after promulgation, rounded forward to the first day of the following month: 1 October 2026.3Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), BGBl I 94/2025 (Austria), promulgated 23 December 2025, transposing Directive (EU) 2022/2555; entry into force 1 October 2026, the first day of the month following the nine-month vacatio legis.

For the US reader the consequence runs in two directions at once, and both cut against the intuition. The missed 2024 deadline did not silently render an Austrian subsidiary non-compliant in the interim: a directive does not impose obligations on a private company of its own force, so there was nothing for the company to breach while Austria legislated. Yet the same delay does not make the obligations optional. They simply attach on the national date. A compliance posture built around 17 October 2024, whether to panic about it or to discount it, reaches for the wrong date. The date that governs is 1 October 2026, and what it triggers is not a single moment of compliance but the first tick of several clocks.

Austria spent more than a year in breach of the NIS2 transposition deadline and then wrote a nine-month delay into its own law, so the date a US pharma group should mark is not a compliance deadline at all but a starting gun: 1 October 2026, the moment the registration, declaration, and proof clocks begin to run.

2. Health, Research, or Neither: The Annex and Tier Question

NIS2 brought pharmaceutical research and development within the scope of EU cybersecurity regulation for the first time, an expansion examined for the EU-level scope in the firm's analysis of the fragmented Nordic landscape (Insight 26). The point that travels into the Austrian setting is that the scoping is entity-based, not activity-based, and that the Health sector of NIS2 Annex I expressly names entities carrying out research and development of medicinal products.4NIS2 (n 1), Annex I point 5 (Health), listing entities carrying out R&D of medicinal products (medicinal product as defined in Art. 1(2) of Directive 2001/83/EC) and manufacturers of basic pharmaceutical products and preparations (NACE Rev. 2, section C division 21); NISG 2026 (n 3), Anlage 1 (sectors of high criticality, incl. Gesundheitswesen) and Anlage 2 (other critical sectors, incl. Forschung); NISG 2026 (n 3), §§ 24 to 26 (essential/important classification, size thresholds on Commission Recommendation 2003/361/EC, the partner-and-linked-undertaking aggregation and its independence exception, and size-independent classification by authority decision); contrast § 28(3) of the German BSI-Gesetz of 2 December 2025. The NISG 2026 carries that structure into its own annexes: Anlage 1 lists the sectors of high criticality, health among them, while a separate research sector sits in Anlage 2, the other critical sectors.

That two-annex structure is the first place a US pharma group can misjudge its position. A research site is naturally thought of as a research operation, which would point to Anlage 2. But research and development of medicinal products is named in the Health sector, Anlage 1, and the annex an entity falls under is not a cosmetic label. Annex placement, combined with size, drives the classification into a wesentliche Einrichtung (essential entity) or a wichtige Einrichtung (important entity): broadly, a large entity in an Anlage 1 sector is essential and subject to ex ante supervision, while a medium-sized entity is important and supervised only where suspected non-compliance surfaces. The size assessment runs on the Union definition in Commission Recommendation 2003/361/EC, qualified by classifications that apply irrespective of size in specified cases. Whether a given Austrian site is the essential entity its medicinal-product research suggests, or the important one its self-image as a research unit assumes, is not a question the company can resolve by reading its own org chart.

Two features of the Austrian transposition sharpen the exposure rather than soften it. The NISG 2026 declines the relief Germany built into its own NIS2 law, under which business activities that are negligible in relation to the entity's overall business activity may be left out of account when the entity is assigned to an entity type; the Austrian act contains no general carve-out for ancillary or negligible activities. Because NIS2 regulates at the level of the entity, an in-scope ancillary activity can pull the entire legal entity into the regime, not merely the system that performs that activity. The size test then aggregates the headcount and turnover of partner and linked undertakings, so a modest Austrian subsidiary can be sized as part of a global group rather than as the standalone operation its local footprint suggests, subject to a narrow exception where the entity is organizationally, technically, and operationally independent of those undertakings in respect of the network and information systems it uses to provide its services. A US group that sizes its Vienna or Tyrol site against a mental model of fifty employees and concludes it sits below the threshold has applied the wrong unit of analysis.

The same entity-level logic reaches the group's shared technology functions. Austria provides no privilege for intra-group services, so a company that operates a group-wide IT helpdesk, an internal cloud, or managed services for affiliates may itself be drawn into scope on the strength of those services, independently of whether its pharmaceutical research is what triggered the analysis. The obvious response, that a centralized US security function already covers all of this, assumes the risk is technical. It is also definitional, and the definitions are Austrian.

3. A New Authority and a Cascade That Starts on 1 October

The counterparty for all of this did not exist before the NISG 2026. The law establishes the Bundesamt für Cybersicherheit as a monocratic federal authority with nationwide competence, directly subordinate to the Federal Minister of the Interior but organizationally separate from the general directorate for public security, seated in Vienna. The existing GovCERT functions as the sector-specific computer security incident response team (CSIRT) for public administration and, transitionally, performs the national CSIRT role until a national CSIRT is authorized.5NISG 2026 (n 3), §§ 3a and 3b (establishment of the Bundesamt für Cybersicherheit as a monocratic authority subordinate to the Federal Minister of the Interior; seat in Vienna per § 3b(3)); § 8(4) (GovCERT as sector-specific CSIRT for public administration entities and, for as long as no national CSIRT exists, national CSIRT), read with § 51(6) (transitional continuation by the CSIRT authorized under the predecessor NISG). For a US group, this is not the agency it has already met in another context; it is a new registration counterparty whose interpretive habits do not yet exist.

What follows entry into force is a sequence, and its shape is the point. Affected entities must register in the authority's register within three months of the 1 October 2026 entry into force, a window that closes with the turn of the year. Registration is not the end of the exercise but the event that starts the next clock: within twelve months of the registration obligation, essential and important entities must file a Selbstdeklaration, a structured account of the risk-management measures actually implemented, covering in particular the network and information systems used, supply-chain security, and the results of the entity's risk analysis. The authority's power to demand external proof of implementation comes later still, no earlier than two years after entry into force, after which the demand can run on a short fuse: an essential entity can be required to produce evidence of the organizational and operational implementation of its risk-management measures within two months of the request, with technical proof due within two years, and a relevant valid certification, of the kind the ISO/IEC 27001 series produces, reaching only the organizational and operational half of that proof.6NISG 2026 (n 3), §§ 29 and 33: registration within three months of entry into force; self-declaration (Selbstdeklaration) within twelve months of the registration duty arising; first authority request for proof of implementation no earlier than two years after entry into force; for essential entities, organizational and operational proof within two months of the request and technical proof within two years; a relevant valid certificate can evidence the organizational and operational implementation only.

The staggering has the shape of a realistic run-up, and for a well-resourced company it is. The difficulty is that the run-up reads as breathing room while front-loading nothing visible and back-loading the binding test. The substantive risk-management duty is set out in the law as a proportionate, risk-based, all-hazards obligation whose ten statutory minimum contents include supply-chain security, but the technical and methodological detail is left to ordinances the authority is empowered to issue, including the option to declare the EU implementing regulation on technical and methodological requirements applicable across sectors.7NISG 2026 (n 3), § 32(1) to (4) (risk-management measures: proportionate, risk-based, all-hazards, with ten minimum contents, of which lit. d is supply-chain security, covering direct suppliers or service providers and the security of their development processes) and § 32(5) (ordinance-making power, incl. the option to declare Commission implementing acts under Art. 21(5) NIS2, as of publication Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, applicable to other sectors or types of entity); cf. NIS2 (n 1), Art. 21(2). As of publication those defining ordinances had not been adopted. The standard against which a 2028 proof request will be judged is therefore not yet knowable, even as the two-month essential-entity response window makes the cost of discovering it late acute. A position that looks adequate against the bare statutory language may not survive the detail that the ordinances supply.

The NISG 2026 compliance cascade for in-scope entities A horizontal timeline showing five milestones of the Austrian NISG 2026 regime for pharmaceutical research and development entities: promulgation in the Federal Law Gazette on 23 December 2025; entry into force and the start of obligations on 1 October 2026; registration with the Bundesamt für Cybersicherheit within three months; self-declaration within twelve months of the registration duty arising; and the authority's first possible request for proof of implementation no earlier than two years after entry into force, with a two-month response window for essential entities. The NISG 2026 Cascade: One Date Starts Several Clocks 23 Dec 2025 Promulgated BGBl I 94/2025 1 Oct 2026 Entry into force Obligations start to apply STARTING GUN Within 3 months Register with the Bundesamt f. Cybersicherheit +12 months from the registration duty: Self-declaration ≥ 2 years after entry: first proof request essential: 2-month window Entry into force on 1 October 2026 starts the registration, declaration, and proof clocks; the binding proof window lands last.
The NISG 2026 timetable for in-scope entities: promulgation (December 2025), entry into force and the start of obligations (1 October 2026), and the staged registration, self-declaration, and proof-of-implementation duties that run from that date

4. Reporting Clocks, Board Liability, and the GxP Overlay

Once the regime applies, the operational edge is incident reporting. The NISG 2026 follows the staged cadence familiar from NIS2: an early warning without undue delay and in any event within 24 hours of awareness of a significant incident, a fuller notification within 72 hours, and a final report within one month of that notification, or, where the incident is still running when that report falls due, a progress report at that point and the final report within one month of the close of incident handling.8NISG 2026 (n 3), § 34 (early warning within 24 hours of awareness, full notification within 72 hours, final report no later than one month after that notification, or, where the incident is still running then, a progress report at that point and the final report within one month of the close of incident handling; duty to inform recipients of services where a significant incident affects service provision); health-sector reports go to the Austrian HealthCERT; cf. NIS2 (n 1), Art. 23(3) (significant-incident definition, disjunctive and forward-looking: an incident that has caused or is capable of causing severe operational disruption or affecting other persons). The threshold runs on the NIS2 definition of a significant incident, which is disjunctive and forward-looking, so an incident that is merely capable of causing severe disruption is already reportable. For a US group whose incident response is centralized in a security operations center (SOC) on US time, the 24-hour clock starts when the Austrian entity becomes aware, which need not coincide with US-side detection, and it runs to the Austrian HealthCERT, the health-sector incident response team designated in the same BGBl I 94/2025 package, on a timetable independent of the SEC's four-business-day materiality-based 8-K trigger. The interaction with the parallel breach-notification duties under GDPR and the Clinical Trials Regulation, which produce different clocks to different authorities for the same incident, is set out in Insight 26 and is not reopened here.

The governance dimension is where the regime reaches individuals. The NISG 2026 places the duty to ensure and oversee compliance with the risk-management measures, and to attend cybersecurity training designed for the role, on the entity's management body, and it narrows that concept: supervisory bodies such as an Aufsichtsrat no longer fall within the Leitungsorgan definition, so the governance duties land squarely on the Geschäftsführung or management board, and on a chief information security officer only where that person is also appointed, by law, articles of association or contract, to conduct the entity's business.9NISG 2026 (n 3), § 31 (governance duties of the Leitungsorgan: ensuring and overseeing compliance with the risk-management measures, training) and § 3 Z 11 (definition of Leitungsorgan, narrowed against the NISG 2024 draft so that supervisory bodies such as an Aufsichtsrat no longer fall within it); cf. NIS2 (n 1), Art. 20(1)–(2) (management-body approval, oversight and liability; mandatory training for management bodies, encouraged for employees). For a US group, the Austrian management board is frequently staffed with parent-company secondees and regional executives, and it is those individuals on whom the ensure-and-oversee duty, and the personal exposure NIS2 contemplates, come to rest.

Behind the governance duty sits the enforcement architecture. Supervision is two-tier: essential entities can be examined ex ante, while important entities are addressed only where the Selbstdeklaration or other substantiated information indicates suspected non-compliance. The authority's toolkit runs from information and production orders through ad hoc inspections and proactive security scans to the appointment of a monitoring officer (Überwachungsbeauftragter) and, in extremis, a temporary prohibition on a management-body member of an essential entity exercising management functions. The administrative fines track the Directive, but only for the breaches the Directive itself prices: a failure of the risk-management, training or incident-reporting duties exposes an essential entity to up to EUR 10 million or 2% of the total worldwide turnover, in the preceding financial year, of the undertaking to which it belongs, whichever is higher, and an important entity to EUR 7 million or 1.4% on the same base, while a missed registration or a late or knowingly false self-declaration sits in a separate tier capped at EUR 50,000, or EUR 100,000 on repetition. A separate bar on double punishment prevents a second fine under the NISG 2026 where the Austrian Datenschutzbehörde has already fined the same conduct under the GDPR.10NISG 2026 (n 3), § 38(1) and (2) (two-tier supervision, ad hoc audits against essential entities only, and against important entities only on suspected non-compliance); § 39(3) Z 2 and § 39(4) Z 2 (monitoring officer, Überwachungsbeauftragter, and temporary prohibition of management functions, both essential-entity-only); § 45(2) and (3) (fines mirroring NIS2 (n 1), Art. 34, essential: up to EUR 10m or 2% of worldwide turnover, whichever higher; important: EUR 7m or 1.4%, in each case only for the breaches listed in § 45(1)) and § 45(4) (separate tier of up to EUR 50,000, EUR 100,000 on repetition, for the registration and self-declaration breaches); § 44(7) (no second fine under the NISG 2026 where the Datenschutzbehörde has already fined the same conduct under Art. 58(2)(i) GDPR). On a group-level turnover base, the 2% figure converts a subsidiary-level lapse into a parent-level number.

The pharmaceutical specificity sits underneath all of this in the form of the GxP overlay. The risk-management duty meets laboratory and manufacturing systems (GxP-validated environments) that were architected for data integrity and validation under EU GMP Annex 11 rather than for the availability, resilience, and rapid-response posture that NIS2 rewards. The tension between a validated environment and a resilient one, where rapid patching and failover collide with change-control and revalidation, recurs in the Austrian setting without changing shape.

5. Strategic Considerations

The questions that determine exposure are not answered by the statutory text, and several of them cannot be answered without facts the company holds privately. Before asking how to comply, an Austrian-resident pharma R&D entity has to settle whether it is in scope at all and at which tier, and that turns on how its activities have been characterized internally: whether a medicinal-product research site reads onto the Health sector of Anlage 1 as an essential entity, whether an ancillary activity nobody flagged pulls the whole legal entity in given the absence of a negligible-activity carve-out, and whether the aggregation of partner and linked undertakings sizes the entity into a tier its local footprint would not suggest. None of these is resolved by reading the law; each depends on the entity's own facts measured against ordinances that, as of publication, did not yet exist.

For a group with establishments in more than one Member State, the classification question compounds into a jurisdictional one. Germany's NIS2 implementation entered into force in December 2025, Austria's applies from October 2026, and each Member State sets its own risk-management detail by national instrument under a directive that imposes only minimum harmonization. A pan-European pharma group is therefore not satisfying one regime but reconciling several that diverge in scope, supervisory contact, and substantive specificity, a problem whose entity-level concurrent-jurisdiction mechanics are mapped, for the Nordic region, in Insight 26. Whether a single group cybersecurity program can be calibrated to the strictest common denominator, or whether the divergences are structural enough to require jurisdiction-specific builds, is a question a regional template cannot answer.

The back-loaded timetable then introduces a trap that rewards exactly the wrong instinct. The two-year gap before the authority can first demand external proof looks like time, but for an essential entity the operative figure is the two-month window to respond once that demand arrives, measured against risk-management ordinances that may only have crystallized in the interim. Whether a program assembled against the bare statutory language will satisfy a request adjudicated in 2028 against ordinance-level detail cannot be known as of publication, and the company that treats the run-up as breathing room may find it has documented its measures to the wrong specification. The almost-comfortable reading, that a program good enough for NIST and ISO purposes will translate, is the one most worth distrusting: the NISG 2026 lets a certification such as ISO/IEC 27001 stand for the organizational and operational half of the proof only, and leaves the technical half to an independent audit measured against ordinances the authority has yet to issue.

The last question is one of accountability rather than systems. Whether the individuals on the Austrian management board have, in fact, ensured and overseen compliance with the risk-management measures and can evidence that oversight is a documentation question with personal-liability consequences, and it is sharper where those individuals are parent-company secondees presenting a global NIST-based posture as Austrian compliance. Whether to front-load the work before 1 October 2026 or to lean on the statutory run-up is a judgment that depends on the entity's tier, its existing security maturity, and its tolerance for resolving these questions under the gaze of a newly created authority still forming its own enforcement habits. These are not questions a compliance template answers. They require analysis tied to the specific entity structure, operational footprint, and corporate facts that determine, in the first place, whether and how the NISG 2026 applies.

REFERENCES

01
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) [2022] OJ L333/80, Art. 41 (transposition deadline 17 October 2024; application from 18 October 2024).
02
Austria's first transposition attempt, the NISG 2024 draft, was rejected by the Nationalrat on 3 July 2024 for want of the two-thirds majority required for its constitutional provisions (Verfassungsbestimmung). European Commission, letter of formal notice to 23 Member States including Austria for incomplete NIS2 transposition (28 November 2024); reasoned opinion to 19 Member States including Austria (7 May 2025), the stage preceding referral to the Court of Justice under Art. 258 of the Treaty on the Functioning of the European Union.
03
Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), BGBl I 94/2025 (Austria), promulgated in the Bundesgesetzblatt on 23 December 2025, transposing Directive (EU) 2022/2555; entry into force on 1 October 2026, the first day of the month following the nine-month vacatio legis.
04
NIS2 (n 1), Annex I point 5 (Health), listing, among others, entities carrying out research and development activities of medicinal products (medicinal product as defined in Art. 1(2) of Directive 2001/83/EC of the European Parliament and of the Council of 6 November 2001 on the Community code relating to medicinal products for human use [2001] OJ L311/67) and entities manufacturing basic pharmaceutical products and pharmaceutical preparations referred to in section C division 21 of NACE Rev. 2; NISG 2026 (n 3), Anlage 1 (sectors of high criticality, including Gesundheitswesen) and Anlage 2 (other critical sectors, including Forschung); NISG 2026 (n 3), § 24(1) Z 3 (an entity of a kind named in Anlage 1 that operates a large undertaking is a wesentliche Einrichtung) and § 24(2) Z 1 (an entity of a kind named in Anlage 1 or Anlage 2 that operates a large or medium undertaking is a wichtige Einrichtung unless it is already essential), § 25(1) to (3) (size thresholds, applying Art. 1 to 6 of the Annex to Commission Recommendation 2003/361/EC of 6 May 2003 [2003] OJ L124/36 with the exception of Art. 3(4) of that Annex) and § 25(4) (the data of partner and linked undertakings are not aggregated where the entity is organizationally, technically and operationally independent of them in respect of the network and information systems it uses to provide its services), and § 26 (classification as essential or important by decision of the authority irrespective of size). Contrast § 28(3) of the German BSI-Gesetz of 2 December 2025 (BGBl. 2025 I Nr. 301), in force 6 December 2025, under which business activities negligible in relation to the entity's overall business activity may be left out of account when the entity is assigned to an entity type under its Anlagen 1 and 2; the NISG 2026 has no equivalent.
05
NISG 2026 (n 3), §§ 3a and 3b (establishment of the Bundesamt für Cybersicherheit as a monocratic authority of nationwide competence, directly subordinate to the Federal Minister of the Interior but organizationally outside the general directorate for public security, with its seat in Vienna per § 3b(3)); § 8(4) (the GovCERT established at the authority performs the tasks of the sector-specific CSIRT for public administration entities and, for as long as no national CSIRT exists, those of the national CSIRT), read with § 51(6) (the CSIRT authorized under § 15(3) of the predecessor Netz- und Informationssystemsicherheitsgesetz, BGBl I 111/2018, continues to carry the national CSIRT tasks until a national CSIRT is authorized, and for no more than two years from entry into force).
06
NISG 2026 (n 3), § 29(3) (registration in the authority's register within three months of entry into force) and § 33 (Selbstdeklaration: information on the risk-management measures implemented under § 32, in particular the network and information systems used, supply-chain security and the results of the risk analysis, submitted in the form the authority specifies within twelve months of the registration duty under § 29(2) arising, § 33(1); proof of implementation through an audit by an independent body on the authority's specifications, the first request possible no earlier than two years after entry into force and the proof generally due within two years of the request but, for essential entities, within two months as to operational and organizational implementation, with § 38(2) applying by analogy to any request addressed to an important entity, so that such a request presupposes suspected non-compliance, § 33(2); a relevant valid certificate may take the place of the audit for the operational and organizational implementation only, the explanatory materials to the government bill, RV 308 BlgNR 28. GP, tying such certificates to established European and international standards such as the ISO/IEC 27001 series).
07
NISG 2026 (n 3), § 32(1) to (4) (cybersecurity risk-management measures: proportionate, risk-based and all-hazards, with ten statutory minimum contents, of which lit. d is supply-chain security, covering the security-related aspects of the relationship between the entity and its direct suppliers or service providers, the specific vulnerabilities of each of them, and the security of their development processes) and § 32(5) (ordinance-making power for the authority to specify further requirements for those measures and to declare Commission implementing acts adopted under Art. 21(5) NIS2 (n 1) for particular sectors or types of entity applicable to other sectors or types of entity, the act in point as of publication being Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures ... [2024] OJ L 2024/2690); cf. NIS2 (n 1), Art. 21(2).
08
NISG 2026 (n 3), § 34 (reporting of significant cybersecurity incidents: early warning without undue delay and in any event within 24 hours of becoming aware; full notification within 72 hours; intermediate reports on request; final report no later than one month after the 72-hour notification, § 34(2) Z 4, and, where the incident is still running when that report falls due, a progress report at that point with the final report due within one month of the close of incident handling, § 34(2) Z 5; duty to inform recipients of services where a significant incident affects the provision of those services); in the health sector, reports go to the Austrian HealthCERT, designated as the sector-specific computer security incident response team by the GTelG 2012 amendment contained in the same BGBl I 94/2025 package; cf. NIS2 (n 1), Art. 23(3) (significant-incident definition, disjunctive and forward-looking: an incident is significant where it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage), transposed in § 35 NISG 2026. On the parallel notification duties under Art. 33 GDPR and Art. 52 of Regulation (EU) No 536/2014 (Clinical Trials Regulation), see Insight 26.
09
NISG 2026 (n 3), § 31 (governance: the Leitungsorgane must ensure and oversee compliance with the risk-management measures and attend cybersecurity training designed for them, with corresponding training to be offered to employees regularly) and § 3 Z 11 (definition of Leitungsorgan, confined to persons appointed by law, articles of association or contract to conduct the business of an entity; the NISG 2024 draft definition had extended to persons appointed to supervise the conduct of the business, and its explanatory materials named the Aufsichtsrat as an example, while the explanatory materials to the government bill for the NISG 2026, RV 308 BlgNR 28. GP, confine the concept to persons at Geschäftsführung or Vorstand level and state that the position of a chief information security officer is not as such a Leitungsorgan); cf. NIS2 (n 1), Art. 20(1)–(2) (management-body approval, oversight and liability; mandatory training for management-body members, with training for employees to be encouraged).
10
NISG 2026 (n 3), § 38(1) (supervisory measures against essential entities, including inspection of the implementation of the risk-management measures, security scans, requests for information and access, and ad hoc audits) and § 38(2) (the same powers other than ad hoc audits against important entities, only where the self-declaration or other substantiated information indicates suspected non-compliance); § 39(3) Z 2 (monitoring officer, Überwachungsbeauftragter, for essential entities) and § 39(4) Z 2 (temporary prohibition of a management-body member of an essential entity from exercising management functions, where a decision under § 39(2) is not complied with); § 45(2) and (3) (fines mirroring NIS2 (n 1), Art. 34: essential entities up to EUR 10 million or 2% of the total worldwide turnover, in the preceding financial year, of the undertaking to which the entity belongs, whichever is higher, and important entities up to EUR 7 million or 1.4% on the same base, in each case only for the breaches listed in § 45(1), whose risk-management limb, § 45(1) Z 3, is itself qualified so that it does not bite where the authority learned of the non-implementation only from a self-declaration under § 33(1)) and § 45(4) (separate tier of up to EUR 50,000, and up to EUR 100,000 on repetition, covering the registration and self-declaration breaches under §§ 29 and 33); § 44(7) (no fine under the NISG 2026 where the Datenschutzbehörde has already imposed a fine under Art. 58(2)(i) of Regulation (EU) 2016/679 (GDPR) resting on the same conduct).

NIS2 compliance for Austrian pharmaceutical R&D operations turns on entity classification under the NISG 2026 annexes, the essential-or-important tier, corporate structure, and the timing of registration, self-declaration, and proof against a regime whose defining ordinances are still emerging.

Get in Touch