NISG Audits & NIS2 Readiness
Critical infrastructure operators and essential service providers are facing increasing regulatory requirements. With the introduction of the NIS2 Directive, obligations relating to cyber security measures, incident reporting, and management accountability have become significantly more demanding.
CERTAINITY is an officially recognized Qualified Body (QuaSte) under the Austrian NIS Act and provides both formal audits for organizations subject to the NISG as well as comprehensive consulting services to help organizations achieve NIS2 compliance.
We provide clarity about your regulatory status, guide you through the compliance process, and deliver reliable evidence for supervisory authorities.
What Is NIS2 — and What Has Changed?
The new NIS2 Directive aims to establish a consistently high level of cyber security across the European Union. Compared to the original NIS Directive, its scope has been significantly expanded, bringing many more organizations under its requirements.
On 23 December 2025, the Austrian NISG 2026 was officially published in the Federal Law Gazette.
The key implementation deadlines are now fixed:
- The law enters into force on 1 October 2026. By this date, all required measures must be implemented, and the incident reporting obligations become applicable.
- Organizations within scope must register with the competent authority by 1 January 2027.
- By 30 September 2027, affected organizations must submit a self-declaration on their implemented risk management measures to the competent authority.
Who is affected?
- Essential Entities: e.g. energy, healthcare, banking, digital infrastructure, and public administration.
- Important Entities: e.g. postal services, chemicals, food production, IT service providers, research organizations, and manufacturing.
Our Services at a Glance
CERTAINITY is officially recognized as a Qualified Body (QuaSte) and performs audits for Essential and Important Entities in accordance with the Austrian NIS Act.
Our audit includes:
- Assessment of technical and organizational security measures
- Interviews, on-site assessments, and sampling
- Preparation of the official audit report in accordance with Austrian Ministry of the Interior (BMI) requirements
- Optional supplementary report including practical recommendations for addressing identified findings
- Submission of the audit report to the BMI and support during follow-up activities
Your outcome:
Formal evidence of NISG compliance, including a maturity assessment, risk analysis, and a structured action plan to further strengthen your cyber security.
For organizations affected by the NIS2 Directive, we provide:
- Gap analysis and maturity assessment
- Design and implementation of a Cyber Security Management System
- Support with incident reporting processes and communication with supervisory authorities
- Establishment of Business Continuity Management, Incident Response, supply chain security, and related governance processes
- Advisory services for executive management regarding governance, accountability, and oversight obligations
Ready for NIS2? Compliant with the NISG?
Whether you require a mandatory NISG audit or support in implementing the new regulatory requirements, CERTAINITY will guide you through the process with practical expertise, structure, and confidence.
