NISG 2026/CRA
CERT.at will perform functions as a Computer Security Incident Response Team (CSIRT) under the Network and Information Systems Security Act 2026 (NISG 2026) and the Cyber Resilience Act (CRA).
Notifications under NISG 2026
NISG 2026 introduces reporting obligations for essential and important entities in the event of significant incidents. As the national CSIRT, CERT.at will be involved in receiving and handling these notifications.
Notifications under NISG 2026 will have to be submitted via the designated reporting platform. This platform is not yet available.
We will publish the relevant link here as soon as the reporting platform becomes available.
Notifications under the Cyber Resilience Act (CRA)
The Cyber Resilience Act introduces reporting obligations for manufacturers of products with digital elements, including notifications of actively exploited vulnerabilities and severe incidents. The reporting obligations under the CRA will apply from 11 September 2026.
For these notifications, the European Union Agency for Cybersecurity (ENISA) will provide a central Single Reporting Platform (SRP). Notifications will be submitted via this platform and forwarded to the relevant CSIRT and to ENISA.
The Single Reporting Platform is currently still under development.
CERT.at will perform the functions assigned to it under the CRA as the competent CSIRT for Austria.
We will publish the relevant link here as soon as the Single Reporting Platform becomes available.