On 1 October 2026, the Network and Information Systems Security Act 2026 (NISG 2026) entered into force, transposing the NIS 2 Directive. In addition to setting out requirements to increase the level of cybersecurity in Austria, the Act also contains provisions for the establishment of a Federal Office for Cybersecurity (Bundesamt für Cybersicherheit; BCS) subordinate to the Federal Ministry of the Interior. Further information is available on the website of the Federal Office for Cybersecurity.
Pursuant to Article 44 of the Telecommunications Act 2021 (TKG 2021), the regulatory authority plays an important role in maintaining the security of networks and services in Austria. Operators and providers of public communications networks and services must implement appropriate cybersecurity measures. If existing legal requirements are not sufficient, the regulatory authority may lay down additional technical and organizational security measures by means of a regulation.
Austrian Regulatory Authority for Broadcasting and Telecommunications (Rundfunk und Telekom Regulierungs-GmbH; RTR), Telecommunications and Postal Division, performs further tasks in the field of cybersecurity. These include, in particular, regular telecommunications sector risk analyses together with federal ministries or their authorities, network operators and the CSIRT; participation in the development of a model security concept for network operators; and involvement in working groups of ENISA and the NIS Cooperation Group.
The following pages provide further information from RTR, Telecommunications and Postal Division, on these topics.