NIS2 & NISG 2026: Cybersecurity for essential and important entities
The second EU Network and Information Security Directive obliges thousands of organisations in the DACH region to implement risk management, reporting duties, and personal management liability. It only takes effect through national transposition — in Austria the NISG 2026, in Germany the NIS2UmsuCG.
One EU directive, two national laws.
Directive (EU) 2022/2555 ("NIS2") replaces the original NIS Directive from 2016 and significantly widens the range of affected sectors: energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, public administration, and more. Affected organisations are classified as "essential" or "important" entities, depending on sector and size.
As a directive, NIS2 has no direct effect on companies by itself — it only becomes binding through national transposition. In Austria this happens via the Network and Information System Security Act 2026 (NISG 2026); in Germany via the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). Both laws adopt the core of the directive but differ in detail, deadlines, and the responsible supervisory authority.
The core obligations: technical and organisational risk-management measures, a staggered incident-reporting cascade, registration with the national authority, and — much discussed — personal liability of company management for implementation.
Key deadlines
NIS2 Directive enters into force EU-wide
Directive (EU) 2022/2555 enters into force twenty days after publication in the Official Journal; transposition deadline for member states: 17.10.2024.
NIS2UmsuCG enters into force with no transition period
Bundestag vote 13.11.2025, Bundesrat approval 20.11.2025, published in the Federal Law Gazette 05.12.2025, in force the following day.
NISG 2026 enters into force
Published as BGBl. I No. 94/2025; the core provisions take effect on 01.10.2026.
Registration deadline with the authority
Essential and important entities must register with the competent authority under the NISG 2026.
Self-declaration / proof of effectiveness due
Affected entities self-declare the effectiveness of their risk-management measures. Date per interpretation of the transitional provisions — check the statutory text before relying on binding deadlines.
What NIS2 / NISG actually requires.
Risk-management measures
Ten minimum measures under Art. 21(2) NIS2 — § 30 BSIG in Germany, § 32 NISG 2026 in Austria — from cryptography and access control to supply-chain security and business-continuity planning.
Incident-reporting cascade
Early warning within 24 hours, full incident notification within 72 hours, final report within one month of becoming aware of a significant security incident.
Registration duty
Essential and important entities must register with the national authority and report contact details, sector, and locations.
Personal liability of management
Executive management and boards must implement the measures under Art. 20 NIS2, supervise their implementation and undergo regular training — § 38 BSIG in Germany, § 31 NISG 2026 in Austria. Austria’s NISG 2026 contains no liability provision of its own; § 38(2) BSIG refers to general company law.
Supply chain security you can prove.
Compliance and security for your supply chain — cryptographically sealed, independently verifiable. Art. 21(2)(d) NIS2 makes supply chain security mandatory — and Art. 21(3) requires taking into account the vulnerabilities of each direct supplier and the quality of its cybersecurity practices.
What the law requires
In Germany, § 30 Abs. 2 Nr. 4 BSIG requires "Sicherheit der Lieferkette einschließlich sicherheitsbezogener Aspekte der Beziehungen zu unmittelbaren Anbietern oder Diensteanbietern" (security of the supply chain, including security-related aspects of the relationships with direct suppliers or service providers). In Austria, § 32 Abs. 4 lit. d NISG 2026 regulates the same — the law enters into force on 1 October 2026. For providers of digital infrastructure (DNS, cloud, data centre, CDN, MSP/MSSP providers and others), Implementing Regulation (EU) 2024/2690 further specifies the duty: an up-to-date directory of direct suppliers and service providers, including points of contact and the ICT products and services procured.
How ReportAct fulfils it
The vendor register tracks criticality, contracts, country of origin and concentration flag per provider; security questionnaires are sent and answered per vendor; the "supply chain security" control is continuously assessed from the completeness of vendor due diligence — and every state is cryptographically sealed.
Prove once — credit across regimes
The same register serves supply chain security under NIS2, ICT third-party risk under DORA, and ISO 27001 A.5.19 — one piece of evidence, three regimes.
A framework pack for NIS2 — with an ISO bridge.
The ReportAct NIS2 Framework Pack maps the ten risk-management measures under Art. 21(2) NIS2 as structured controls, automatically tracks the 24/72/30 reporting cascade with deadline alerts, and maintains an asset register for essential and important entities (Annex I/II).
For the management body’s duty to implement and supervise, ReportAct provides a sealed management record: who approved which measure and when is cryptographically documented and independently verifiable — without ReportAct access.
Because ISO/IEC 27001 covers roughly 70 % of NIS2's requirements in substance, ReportAct automatically credits ISO controls toward NIS2 requirements — one control, used twice, instead of duplicate data entry.
Product/positioning statement, not legal advice.
Read the originals
ReportAct is not a consultancy. This page does not constitute legal advice. Note on transposition in other EU countries: Italy transposed NIS2 on time (October 2024); France and Spain were still in the legislative process as of this writing — the European Commission has opened infringement proceedings against several member states. Check the current transposition status for your country via the tracker linked above. Our Terms of Service apply.
NIS2 does not apply the same way everywhere. Choose your country.
Three countries, three laws, three deadlines — and a separate check for each. Switzerland has not transposed NIS2; the ISG applies there instead.
An NIS2 record that stands up to scrutiny.
Start right away on your NISG/NIS2 regime — including reporting-cascade tracker and management-accountability record.