Austria requires critical entities through the RKEG to conduct risk analyses, develop resilience plans, and report security incidents to the Interior Ministry.
The Cyber Resilience Act requires manufacturers to report security incidents within 24–72 hours starting September 2026, or face penalties up to 15 million euros.