Reporting of significant cybersecurity incidents
Pursuant to Article 34 of the Network and Information Systems Security Act 2026 (NISG 2026), essential and important entities are required to report any significant cybersecurity incident. Further information is available at https://www.cert.at/en/nis2/.
Notifications relating to the reachability of emergency numbers
Pursuant to Art. 123 Par. 4 of the Telecommunications Act 2021 (TKG 2021), providers and operators must immediately notify the regulatory authority, the affected holders of decisions assigning emergency numbers, and the affected emergency call answering points of security incidents that have had a substantial impact on the reachability of emergency numbers. Notification to the regulatory authority should be submitted via the e-government portal of the Austrian Regulatory Authority for Broadcasting and Telecommunications (Rundfunk und Telekom Regulierungs-GmbH; RTR).
- An incident must in any case be notified if an emergency number is not reachable from a communications network for users of an available publicly available voice communications service.
- The non-reachability of an emergency number must also be notified if the voice communications service is only partially available from the user’s perspective (for example, if only some numbers are reachable for users, but at least one emergency number is not).
- In addition, an incident must also be notified if the voice communications service of the emergency call centre to which an emergency call is terminated is not available for incoming calls, regardless of whether the emergency number is reachable (e.g. by automatic forwarding) or not.