NISG 2026/CRA

CERT.at will perform functions as a Computer Security Incident Response Team (CSIRT) under the Network and Information Systems Security Act 2026 (NISG 2026) and the Cyber Resilience Act (CRA).

Notifications under NISG 2026

NISG 2026 introduces reporting obligations for essential and important entities in the event of significant incidents. As the national CSIRT, CERT.at will be involved in receiving and handling these notifications.

You can find the NISG 2026 Incident Reporting Platform here: NISG 2026 Meldeplattform

Notifications under the Cyber Resilience Act (CRA)

The Cyber Resilience Act introduces reporting obligations for manufacturers of products with digital elements, including notifications of actively exploited vulnerabilities and severe incidents. The reporting obligations under the CRA will apply from 11 September 2026.

For these notifications, the European Union Agency for Cybersecurity (ENISA) provides a central Single Reporting Platform (SRP). Notifications will be submitted via this platform and forwarded to the relevant CSIRT and to ENISA.

CERT.at will perform the functions assigned to it under the CRA as the competent CSIRT for Austria.

Based on the experience from the first days, we'd like to point out the following:

During the registration

  • We will not accept registrations with free-mailer (e.g., gmail, gmx, hotmail, qq.com) e-mail addresses.
  • There must be a valid company name given - not just the name of a person.
  • Please register a company only once, and then use backup AR for redundant access.

Reporting requirements

ENISA operates a website that collects all the relevant information.

We want stress one point that causes a lot of confusion: Do I have to report when a component of my product is known to be vulnerable? The best answer to this is in the commission's document C(2026) 5252 - Annex - Commission guidance on the application of the Cyber Resilience Act (CRA) paragraph 218, which contains:

However, if a manufacturer is aware that a third-party component contains a vulnerability, but that vulnerability either (i) cannot be exploited in its product with digital elements (e.g. because the vulnerable code is not reachable) or (ii) has not been exploited in its product with digital elements, that vulnerability does not qualify as an actively exploited vulnerability contained in its product with digital elements, and therefore it is not subject to mandatory reporting for that manufacturer.

In other words: even if a component is actively exploited in another context, a reporting requirement only arises if there is active exploitation in my own product.