How can we help you?
)
craftworks GmbH
Schottenfeldgasse 20/6a
1070 Vienna

NISG 2026 makes cybersecurity, risk management and evidence a management responsibility. We help companies build the operational foundation they need. Transparent data flows, monitoring, governance dashboards, automation and reliable decision-making.
READINESS CHECK

NISG 2026 is more than just a new security requirement. For many companies, the key challenge will be answering questions such as: Which systems are critical? Where does data flow? And which dependencies exist?
Most companies already know that NISG 2026 will apply from October 2026. What is often missing is the foundation needed to actually implement the requirements. The most important elements are a comprehensive system overview, documented data flows, monitoring, risk assessment, responsibilities and management reporting.
SPEAK WITH A NISG EXPERT:quality(90))
NISG 2026 significantly expands the scope of affected organizations. In addition to directly regulated companies, suppliers and service providers are increasingly coming under pressure to provide evidence.
Cybersecurity is becoming a leadership responsibility. Decision-makers need reliable information on risks, systems, processes, and measures.
Enterprise sales, tenders, and procurement processes will increasingly require evidence of security, compliance, and resilience.
NISG 2026 readiness is not achieved through documentation alone. What matters is that companies have a clear grip on their systems, data flows, dependencies and risks. craftworks supports this with data engineering, AI, observability, platform engineering and automation, turning regulatory requirements into concrete, manageable processes.
Let’s talk about your NISG-Readiness:quality(90))
Make system landscapes, data flows, interfaces, and critical dependencies visible.
Capture, structure, and make operational, security, and anomaly signals analyzable.
Map responsibilities, processes, KPIs, and evidence in dashboards.
NISG 2026 applies to companies with roughly 50 or more employees, or an annual turnover above 10 million euros, in certain sectors - including energy, transport, manufacturing, healthcare, and digital infrastructure.
Smaller companies can also be affected if they provide critical services or act as suppliers to companies subject to NISG.
Non-compliance can result in fines of up to 10 million euros or 2% of global annual turnover for essential entities, and up to 7 million euros or 1,4% for important entities.
Start with a NISG Operational Readiness Check
In a compact assessment, we review how well your company is operationally prepared for NISG 2026. The focus includes system overview, data flows, IT, OT and cloud dependencies, monitoring, detection, risk and escalation processes, management reporting, supply chain requirements, automation potential, data quality and governance.
You receive a prioritized action plan with clear recommendations and concrete implementation steps.
:quality(80))
NISG readiness becomes tangible when the relevant building blocks work together across the company. Data flows need to be traceable, IT and OT systems must be monitored, risks should be identified as early as possible and management information needs to be presented clearly. We help build these components and connect them in a practical way.
Let’s talk about your NISG-Readiness:quality(90))
Identification and visualization of critical systems, data sources, interfaces, and dependencies.
Establishment of monitoring structures for industrial, operational, and digital environments. Combined with AI-powered anomaly detection as an early indicator of risks.
Clear visualization of risks, measures, KPIs, status, and evidence. Including automated reports and supply chain assessment.
:quality(80))
We support companies in implementing the requirements of the NISG 2026 directive as effectively as possible in practice. To do this, we create the necessary foundation of data, monitoring and automation, with experience in complex IT, OT, production, energy and platform environments. The result is not just a concept on paper, but a clear path toward greater transparency, reliable dashboards, continuous monitoring, automated processes and traceable evidence.
READINESS CHECK:quality(90))
craftworks builds the data, monitoring, and automation foundation companies need for operational control.
Especially in IT/OT, production, energy, and platform environments, readiness requires a deep understanding of real-world data and process landscapes.
The goal is not just a concept, but a reliable path toward dashboards, monitoring, automation, and evidence-based compliance.
How well prepared is your company? Self-assessment.
A robust NISG readiness starts with a transparent overview of critical systems, data sources, interfaces, and dependencies. Without this overview, risks can neither be assessed nor presented in a management-ready format.