In brief: Austria requires critical entities through the RKEG to conduct risk analyses, develop resilience plans, and report security incidents to the Interior Ministry.
Austria has enacted the Resilience of Critical Entities Act (RKEG) and thereby tightens requirements for the protection of critical infrastructure and services. On 23 June 2026, the Federal Ministry of the Interior presented the key provisions and their consequences for affected organizations in a legal and technology dialogue.
The Resilience of Critical Entities Act (RKEG) requires all entities classified as critical to conduct systematic risk analyses and to implement protective and resilience measures. The Federal Ministry of the Interior (BMI) classifies which entities fall under this regulation and centrally monitors compliance with legal requirements.
CISOs and security professionals must verify whether their organization is classified as a critical entity and meet the following requirements: conducting regular risk analyses, developing and documenting a resilience plan, implementing infrastructure protection measures, preparing for crisis and emergency scenarios, securing supply chains, and systematically training and raising awareness among personnel. Additionally, there is a mandatory reporting obligation for relevant security incidents to the BMI.
The objective of the RKEG is to ensure supply security and the continuity of essential services even under conditions of crisis and threat. Implementation requires close coordination between IT security, business continuity, and organizational stakeholders.
Source: kompetenzzentrum-sicheres-oesterreich.at · Published 21 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.