EU directive · national transposition Regulations / NIS2

NIS2 & NISG 2026: Cybersecurity for essential and important entities

The second EU Network and Information Security Directive obliges thousands of organisations in the DACH region to implement risk management, reporting duties, and personal management liability. It only takes effect through national transposition — in Austria the NISG 2026, in Germany the NIS2UmsuCG.

What is NIS2

One EU directive, two national laws.

Directive (EU) 2022/2555 ("NIS2") replaces the original NIS Directive from 2016 and significantly widens the range of affected sectors: energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, public administration, and more. Affected organisations are classified as "essential" or "important" entities, depending on sector and size.

As a directive, NIS2 has no direct effect on companies by itself — it only becomes binding through national transposition. In Austria this happens via the Network and Information System Security Act 2026 (NISG 2026); in Germany via the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). Both laws adopt the core of the directive but differ in detail, deadlines, and the responsible supervisory authority.

The core obligations: technical and organisational risk-management measures, a staggered incident-reporting cascade, registration with the national authority, and — much discussed — personal liability of company management for implementation.

Timeline

Key deadlines

16.01.2023In force (EU)

NIS2 Directive enters into force EU-wide

Directive (EU) 2022/2555 enters into force twenty days after publication in the Official Journal; transposition deadline for member states: 17.10.2024.

06.12.2025DE in force

NIS2UmsuCG enters into force with no transition period

Bundestag vote 13.11.2025, Bundesrat approval 20.11.2025, published in the Federal Law Gazette 05.12.2025, in force the following day.

01.10.2026AT in force

NISG 2026 enters into force

Published as BGBl. I No. 94/2025; the core provisions take effect on 01.10.2026.

31.12.2026AT deadline

Registration deadline with the authority

Essential and important entities must register with the competent authority under the NISG 2026.

~30.09.2027AT deadline

Self-declaration / proof of effectiveness due

Affected entities self-declare the effectiveness of their risk-management measures. Date per interpretation of the transitional provisions — check the statutory text before relying on binding deadlines.

Core obligations

What NIS2 / NISG actually requires.

Risk-management measures

Ten minimum measures under Art. 21(2) NIS2 — § 30 BSIG in Germany, § 32 NISG 2026 in Austria — from cryptography and access control to supply-chain security and business-continuity planning.

Incident-reporting cascade

Early warning within 24 hours, full incident notification within 72 hours, final report within one month of becoming aware of a significant security incident.

Registration duty

Essential and important entities must register with the national authority and report contact details, sector, and locations.

Personal liability of management

Executive management and boards must implement the measures under Art. 20 NIS2, supervise their implementation and undergo regular training — § 38 BSIG in Germany, § 31 NISG 2026 in Austria. Austria’s NISG 2026 contains no liability provision of its own; § 38(2) BSIG refers to general company law.

Supply chain compliance · Art. 21 NIS2

Supply chain security you can prove.

Compliance and security for your supply chain — cryptographically sealed, independently verifiable. Art. 21(2)(d) NIS2 makes supply chain security mandatory — and Art. 21(3) requires taking into account the vulnerabilities of each direct supplier and the quality of its cybersecurity practices.

What the law requires

In Germany, § 30 Abs. 2 Nr. 4 BSIG requires "Sicherheit der Lieferkette einschließlich sicherheitsbezogener Aspekte der Beziehungen zu unmittelbaren Anbietern oder Diensteanbietern" (security of the supply chain, including security-related aspects of the relationships with direct suppliers or service providers). In Austria, § 32 Abs. 4 lit. d NISG 2026 regulates the same — the law enters into force on 1 October 2026. For providers of digital infrastructure (DNS, cloud, data centre, CDN, MSP/MSSP providers and others), Implementing Regulation (EU) 2024/2690 further specifies the duty: an up-to-date directory of direct suppliers and service providers, including points of contact and the ICT products and services procured.

How ReportAct fulfils it

The vendor register tracks criticality, contracts, country of origin and concentration flag per provider; security questionnaires are sent and answered per vendor; the "supply chain security" control is continuously assessed from the completeness of vendor due diligence — and every state is cryptographically sealed.

Prove once — credit across regimes

The same register serves supply chain security under NIS2, ICT third-party risk under DORA, and ISO 27001 A.5.19 — one piece of evidence, three regimes.

See the use case: NIS2 Readiness & Evidence →

How ReportAct solves it

A framework pack for NIS2 — with an ISO bridge.

The ReportAct NIS2 Framework Pack maps the ten risk-management measures under Art. 21(2) NIS2 as structured controls, automatically tracks the 24/72/30 reporting cascade with deadline alerts, and maintains an asset register for essential and important entities (Annex I/II).

For the management body’s duty to implement and supervise, ReportAct provides a sealed management record: who approved which measure and when is cryptographically documented and independently verifiable — without ReportAct access.

Because ISO/IEC 27001 covers roughly 70 % of NIS2's requirements in substance, ReportAct automatically credits ISO controls toward NIS2 requirements — one control, used twice, instead of duplicate data entry.

Product/positioning statement, not legal advice.

Primary sources

Read the originals

NISG 2026, BGBl. I No. 94/2025 (RIS, Austria) https://ris.bka.gv.at/eli/bgbl/i/2025/94/P0/NOR40273913
NIS2UmsuCG — German Federal Government overview (in German) https://www.bundesregierung.de/breg-de/aktuelles/nis-2-richtlinie-deutschland-2373174
NIS2 transposition tracker, European Commission https://digital-strategy.ec.europa.eu/en/policies/nis-transposition

ReportAct is not a consultancy. This page does not constitute legal advice. Note on transposition in other EU countries: Italy transposed NIS2 on time (October 2024); France and Spain were still in the legislative process as of this writing — the European Commission has opened infringement proceedings against several member states. Check the current transposition status for your country via the tracker linked above. Our Terms of Service apply.

Next step

An NIS2 record that stands up to scrutiny.

Start right away on your NISG/NIS2 regime — including reporting-cascade tracker and management-accountability record.