NISG 2026 is more than just a new security requirement. For many companies, the key challenge will be answering questions such as: Which systems are critical? Where does data flow? And which dependencies exist?

We support you in establishing data, monitoring, and governance for NISG readiness.

Prepare your company for NISG 2026

Why act now?

Most companies already know that NISG 2026 will apply from October 2026. What is often missing is the foundation needed to actually implement the requirements. The most important elements are a comprehensive system overview, documented data flows, monitoring, risk assessment, responsibilities and management reporting.

SPEAK WITH A NISG EXPERT
science technology object select

More companies affected

NISG 2026 significantly expands the scope of affected organizations. In addition to directly regulated companies, suppliers and service providers are increasingly coming under pressure to provide evidence.

group with two users

Management responsibility increases

Cybersecurity is becoming a leadership responsibility. Decision-makers need reliable information on risks, systems, processes, and measures.

folder with big document line

Evidence becomes business-critical

Enterprise sales, tenders, and procurement processes will increasingly require evidence of security, compliance, and resilience.

The foundation for NISG readiness

NISG 2026 readiness is not achieved through documentation alone. What matters is that companies have a clear grip on their systems, data flows, dependencies and risks. craftworks supports this with data engineering, AI, observability, platform engineering and automation, turning regulatory requirements into concrete, manageable processes.

Let’s talk about your NISG-Readiness
Symbolic image for NISG 2026: a central digital platform transforms chaotic data flows into transparent, connected and secure IT structures for monitoring, governance and operational resilience.
white icons with programming code and search loupe

Transparency

Make system landscapes, data flows, interfaces, and critical dependencies visible.

visual integration icon

Monitoring

Capture, structure, and make operational, security, and anomaly signals analyzable.

White icons with Server, Databases and Setting

Automation

Map responsibilities, processes, KPIs, and evidence in dashboards.

Does NISG 2026 apply to you?

NISG 2026 applies to companies with roughly 50 or more employees, or an annual turnover above 10 million euros, in certain sectors - including energy, transport, manufacturing, healthcare, and digital infrastructure.

Smaller companies can also be affected if they provide critical services or act as suppliers to companies subject to NISG.

Non-compliance can result in fines of up to 10 million euros or 2% of global annual turnover for essential entities, and up to 7 million euros or 1,4% for important entities.

Start with a NISG Operational Readiness Check

In a compact assessment, we review how well your company is operationally prepared for NISG 2026. The focus includes system overview, data flows, IT, OT and cloud dependencies, monitoring, detection, risk and escalation processes, management reporting, supply chain requirements, automation potential, data quality and governance.

You receive a prioritized action plan with clear recommendations and concrete implementation steps.

detail showing hands on laptop in a meeting situation

Typical use cases for NISG readiness

NISG readiness becomes tangible when the relevant building blocks work together across the company. Data flows need to be traceable, IT and OT systems must be monitored, risks should be identified as early as possible and management information needs to be presented clearly. We help build these components and connect them in a practical way.

Let’s talk about your NISG-Readiness
three men discussing at meeting table in the craftworks office with laptops in front of them
server databases to synchronize with arrows

Data flow and system transparency

Identification and visualization of critical systems, data sources, interfaces, and dependencies.

eye lock icon

IT/OT monitoring and observability

Establishment of monitoring structures for industrial, operational, and digital environments. Combined with AI-powered anomaly detection as an early indicator of risks.

white icon with blackboard chart

Management dashboards and evidence

Clear visualization of risks, measures, KPIs, status, and evidence. Including automated reports and supply chain assessment.

placeholder

Compliance is the trigger. Operational resilience is the outcome.

Prepare your company operationally for NISG 2026

Why craftworks?

We support companies in implementing the requirements of the NISG 2026 directive as effectively as possible in practice. To do this, we create the necessary foundation of data, monitoring and automation, with experience in complex IT, OT, production, energy and platform environments. The result is not just a concept on paper, but a clear path toward greater transparency, reliable dashboards, continuous monitoring, automated processes and traceable evidence.

READINESS CHECK
craftworks founders Simon Grabher and Jakob Lahmer sitting at a meeting table in front of a laptop talking
human and artificial intelligence

Data & AI instead of pure compliance theory

craftworks builds the data, monitoring, and automation foundation companies need for operational control.

White icons with Server, Databases and Setting

Experience with industrial and complex systems

Especially in IT/OT, production, energy, and platform environments, readiness requires a deep understanding of real-world data and process landscapes.

white icon with hand to select

Implementation instead of paperwork

The goal is not just a concept, but a reliable path toward dashboards, monitoring, automation, and evidence-based compliance.

How well prepared is your company? Self-assessment.

Can you summarize the relevant risks and dependencies in a way that's ready for management review?

A robust NISG readiness starts with a transparent overview of critical systems, data sources, interfaces, and dependencies. Without this overview, risks can neither be assessed nor presented in a management-ready format.

Can you present relevant risks and dependencies in a management-ready format?
Is there centralized monitoring for operational, technical, and security-relevant signals?
Are incident, escalation, and reporting processes documented in a traceable way?
Can you provide customers or auditors with reliable evidence?
Do you know which suppliers, service providers, and interfaces are critical to your resilience?
Does the craftworks Readiness Check replace a certification such as ISO 27001 or the legally required audit report?
What happens if my company fails to meet the NISG 2026 requirements?
What is the difference between "essential" and "important" entities?