Cybersecurity has become a condition of market access rather than an IT policy. The EU Cyber Resilience Act attaches the CE marking to security by design and to a vulnerability-reporting duty from September 2026; NIS2 reaches pharmaceutical research sites and connected-device makers through national transpositions that diverge in scope, authority and deadline, as Austria's late NISG 2026 and the fragmented Nordic picture show; and Switzerland's ISG requires operators of critical infrastructure to report a cyberattack to the BACS within 24 hours of discovery, capturing US subsidiaries by license rather than sector label. The analyses below map those regimes for US vendors and life-sciences operators, including the device-specific layer the MDR and IEC 81001-5-1 add for software as a medical device.
6 insights · latest June 2026
Insights on Cybersecurity: NIS2, CRA and the ISG
No. 42Critical Compliance
The EU Cyber Resilience Act: A 2026/2027 Compliance Map for US Software and Hardware Vendors
The EU Cyber Resilience Act makes cybersecurity a condition of market access: products with digital elements must carry the CE marking and stay supported with security updates, and the vulnerability reporting duty starts 11 September 2026.
No. 19High Stakes
Cybersecurity Requirements for Connected Medical Devices: NIS2 Implications
Swiss MedTech faces indirect NIS2 pressure through EU customers. Supply chain flowdowns reshape cybersecurity expectations.
No. 18High Stakes
Cybersecurity for SaMD: Meeting MDR and Beyond
SaMD cybersecurity under the EU MDR, IEC 81001-5-1 and the Swiss ISG: vulnerability management, incident reporting and security updates beyond standard IT.
No. 26Cross-Border
Nordic NIS2 Enforcement: A Fragmented Cybersecurity Landscape for Pharma R&D
NIS2 enforcement across Denmark, Sweden, Finland, Norway, and Iceland diverges in supervisory authorities, incident-reporting thresholds, and sectoral scope. US pharma R&D operations face fragmented cybersecurity compliance across the region.
No. 43Critical Compliance
NIS2 in Austria: The NISG 2026 Cybersecurity Deadline for US Pharma R&D
Austria's NISG 2026 transposes NIS2 late: obligations apply from 1 October 2026, when a new federal cybersecurity authority takes up its functions and registration, self-declaration and staged proof-of-implementation duties begin running against in-scope pharmaceutical R&D sites.
No. 58Critical Compliance
Switzerland's 24-Hour Cyberattack-Reporting Duty: The ISG Obligation for US Operators of Swiss Critical Infrastructure
Since 1 April 2025 the ISG requires operators of Swiss critical infrastructure to report cyberattacks to the BACS within 24 hours of discovery, and its statutory catalogue captures US subsidiaries by Swiss license rather than sector label.