Registration required by December 31, 2026 — the portal does not exist yet
The NISG 2026 has been passed. Promulgated as BGBl. I No. 94/2025 on December 23, 2025, applicable from October 1, 2026. Until then, the NISG 2018 applies. The registration obligation takes effect within three months of entry into force, with a deadline of December 31, 2026. What does not exist as of today: the portal where this registration is supposed to take place.
This is the content of this post. A deadline without a tool is not a form question, it is a responsibility question. And responsibility cannot be shifted to the regulation.
Current status: Law, not a draft
The National Council passed it with a two-thirds majority on December 12, 2025, the Federal Council approved it on December 18, 2025, and it was published on December 23, 2025. The source is BGBl. I Nr. 94/2025 in RIS. If you hear the claim that this is "still a draft," correct it immediately: It is valid law with a deadline.
The Cyber Security Agency within the BMI is responsible. The department representative stated in parliament the motto "advise instead of penalize". This does not change the obligations from the first day of applicability.
I won't quote the paragraphs here, as the numbers for the registration and penalty provisions are unverified. If you need to work with this, use the main RIS document.
91 days, four metrics
From 1 October to December 31, 2026, there are 91 days. That is how long an operator has to register for something that does not yet have a form. The NIS2 overview from the WKO, being developed with the Ministry of the Interior, notes "by January 1, 2027" for registration, the same deadline, three months after entry into force. Self-assessment follows about a year later. The WKO page lists both 30 September and October 1, 2027 for this date. That does not make the deadline any softer.
The circle is larger than many assume: about 4,000 facilities in Austria, spread across 18 sectors. Manufacturing and food production are listed in Annex 2, making them critical facilities, not just energy suppliers and hospitals.
The calculation that few operations can answer off the cuff. Four metrics must be correct for each company:
- Employee count per EU SME recommendation, including group headcount
- Company revenue
- Total assets of the company
- ÖNACE code with assignment to Annex 1 or 2
The threshold: 50 employees, or turnover above €10 million with a balance sheet total above €10 million. For a GmbH with 60 employees, the answer is simple. In a group with nine companies, it is not. That is the normal case, not the exception. And a company with twelve employees in a group with 200: Does the group trigger the obligation, or does each company assess individually? No portal answers these questions, not even the future one. They are decided in the shareholder circle and then documented.
Two penalty tiers
The number that comes up at every talk is 10 million euros. It is not part of the registration.
| Compliance violation | Fine according to WKO and BMI presentation |
|---|---|
| Missed registration or self-clearing | €50,000 |
| Same violation repeated | €100,000 |
| Missed core obligations, significant setup | €7 million or 1.4% of group turnover |
| Core obligations missed, essential setup | €10 million or 2 % of group turnover |
The size difference between the tiers is the message. If you miss the registration deadline, you pay an amount that is painful but manageable for a Tyrolean mid-sized company. If you cannot prove the risk measures, you pay a single or double-digit million amount, based on group revenue. The core obligations are also what takes months: patch management across all systems, proof of recovery attempts, security awareness up to the executive board. A registration following an empty measures list is the expensive option.
Three steps this week
First: Test applicability. The WKO online guide contains the applicability test. It does not replace legal advice but provides a sorted initial assessment. For each company individually, not for the group.
Second: designate a person and a deputy. In writing, with a date. Notification chains run through GovCERT under nis2.cert.at in three stages: 24 hours for early warning, 72 hours for the notification, one month for the final report. A chain that depends on exactly one person stalls when that person is on vacation. Only the deputy ensures the 24-hour deadline holds on December 24.
Third: document the oversight duty. Management bodies need training themselves, they approve risk measures and monitor their implementation. The comparison with the proof under Article 4 of the AI Regulation fits: at the end, a document is required, not a good feeling. A note in the minutes of the next management meeting is enough for a start: who is responsible, who is the deputy, what is approved.
What this list does not include: registration. There is no way to do it.
Why €50,000 is not the risk
The uncomfortable bill: The €50,000 is the price for waiting at the form. The real risk sits one step further back and becomes acute due to the deadlines.
The second clock in the graphic relates to product notifications under the CRA, which is a separate post. For this NISG clock to work, you need a directory: who reports for which entity to whom, via which channel, with which documentation, within which hour. This directory is missing in most companies, regardless of whether the legislator provides a portal. Registered on December 31, 2026, incident on January 15, 2027, and nobody knows who makes the report: then you have a registration entry and a problem. Even those who operate their own systems and have the logs are not done: having logs is half the battle, condensing them into a report within 24 hours is the other half.
The second point is a warning. In the coming months, someone will offer to "register you now at Portal X." There is no state registration portal; the procedure is reserved for a regulation. Anything promising NISG registration today is self-service without a legal basis or a sales pitch.
The third calculation is an honest one. At the time of our research, no publicly confirmed NIS2 fine in Austria or Germany could be found. This does not mean there will be none. It means that deterrence currently comes from the threat, not from enforcement.
That a portal is tied to the mandate is evident from the situation in Germany. The NIS2UmsuCG was announced on December 5, 2025 and entered into force on December 6, 2025, covering around 29,500 affected entities instead of the previous 4,500. Registration there is a two-step process via "Mein Unternehmenskonto" with ELSTER and via the BSI portal, which has been live since January 6, 2026. One month after it entered into force.
Our recommendation for managing directors at companies our size: use December 31, 2026 as the deadline for clarifying your affected status, not for registration. As long as the regulation is missing, misjudging your own situation is the only mistake you can make here. This is not legal advice, but work you can complete this week without waiting for anyone.
Further Reading
- NISG 2026, BGBl. I No. 94/2025, Source in RIS
- Parliamentary report PK 1145, National Council on December 12, 2025
- WKO: NIS2 overview, sectors and thresholds
- WKO: Online guide NIS2, applicability test
- GovCERT Austria: NIS2 reports
- BSI: NIS2UmsuCG in force, 29,500 affected entities
- BSI: BSI portal for NIS2 registration is live
Can we register today?+
No, and this applies equally to every affected party. NISG 2026 was promulgated in BGBl. I No. 94/2025 and applies from October 1, 2026, but the form and procedure are reserved for a pending regulation. There is currently no state register portal. What must be done between 1 October and December 31, 2026 can be handled without any form: determine affected status, designate a person, document management responsibility.
Could a late registration result in a fine of €10 million?+
No. For breaches of the registration and self-declaration obligations, the WKO and BMI position fines of €50,000, rising to €100,000 for repeat offenses. The millions in penalties, €7 million or 1.4 percent, or €10 million or 2 percent of group turnover, apply to core obligations, meaning missing risk measures. Mixing the two levels leads to assessing the wrong risk.
When is a production facility in Tyrol affected?+
The thresholds are 50 employees or turnover above 10 million EUR combined with a balance sheet total above 10 million EUR, applied according to the EU SME recommendation including group attribution. Manufacturing and food processing fall under Annex 2 and thus into the category of important entities. According to the WKO assessment, this affects around 4,000 entities in 18 sectors in Austria. Whether a single company in a group is affected depends on its own metrics, not on the brand presence.
senn-tech