Cybersecurity: NIS2, CRA and the ISG

Cybersecurity has become a condition of market access rather than an IT policy. The EU Cyber Resilience Act attaches the CE marking to security by design and to a vulnerability-reporting duty from September 2026; NIS2 reaches pharmaceutical research sites and connected-device makers through national transpositions that diverge in scope, authority and deadline, as Austria's late NISG 2026 and the fragmented Nordic picture show; and Switzerland's ISG requires operators of critical infrastructure to report a cyberattack to the BACS within 24 hours of discovery, capturing US subsidiaries by license rather than sector label. The analyses below map those regimes for US vendors and life-sciences operators, including the device-specific layer the MDR and IEC 81001-5-1 add for software as a medical device.

6 insights · latest June 2026

Insights on Cybersecurity: NIS2, CRA and the ISG

No. 42 Critical Compliance

The EU Cyber Resilience Act: A 2026/2027 Compliance Map for US Software and Hardware Vendors

The EU Cyber Resilience Act makes cybersecurity a condition of market access: products with digital elements must carry the CE marking and stay supported with security updates, and the vulnerability reporting duty starts 11 September 2026.

No. 19 High Stakes

Cybersecurity Requirements for Connected Medical Devices: NIS2 Implications

Swiss MedTech faces indirect NIS2 pressure through EU customers. Supply chain flowdowns reshape cybersecurity expectations.

No. 18 High Stakes

Cybersecurity for SaMD: Meeting MDR and Beyond

SaMD cybersecurity under the EU MDR, IEC 81001-5-1 and the Swiss ISG: vulnerability management, incident reporting and security updates beyond standard IT.

No. 26 Cross-Border

Nordic NIS2 Enforcement: A Fragmented Cybersecurity Landscape for Pharma R&D

NIS2 enforcement across Denmark, Sweden, Finland, Norway, and Iceland diverges in supervisory authorities, incident-reporting thresholds, and sectoral scope. US pharma R&D operations face fragmented cybersecurity compliance across the region.

No. 43 Critical Compliance

NIS2 in Austria: The NISG 2026 Cybersecurity Deadline for US Pharma R&D

Austria's NISG 2026 transposes NIS2 late: obligations apply from 1 October 2026, when a new federal cybersecurity authority takes up its functions and registration, self-declaration and staged proof-of-implementation duties begin running against in-scope pharmaceutical R&D sites.

No. 58 Critical Compliance

Switzerland's 24-Hour Cyberattack-Reporting Duty: The ISG Obligation for US Operators of Swiss Critical Infrastructure

Since 1 April 2025 the ISG requires operators of Swiss critical infrastructure to report cyberattacks to the BACS within 24 hours of discovery, and its statutory catalogue captures US subsidiaries by Swiss license rather than sector label.

Good questions deserve specific answers.

Get in Touch