SCRM Supplier Compliance & Risk Management

Home

NISG 2026 · in force 1 October 2026

Five thousand entities are obliged. Ten times as many get asked.

Austria transposed the NIS2 Directive through the NISG 2026. Supplying essential or important entities means receiving their security requirements – by contract, not by statute.

The NISG 2026 was published in late 2025 and enters into force on 1 October 2026. It carries the NIS2 requirements into Austrian law: risk management measures, reporting duties, registration and management accountability.

The interesting figure is not in the statute. Against an estimated 5,000 directly covered entities stands a multiple of companies affected as suppliers. For a Swiss SME with Austrian customers that means the questionnaire arrives regardless of whether you fall in scope yourself.

Who is affected

  • Essential and important entities in the covered sectors in Austria.
  • Their suppliers and service providers, including those in Switzerland and Liechtenstein.
  • Group companies with Austrian sites.
  • Digital service providers operating in Austria.

What is required

Risk management
State-of-the-art measures with evidence of effectiveness.
Supply chain
Assess and govern security in relationships with direct suppliers.
Reporting
Staged reporting of significant incidents, with short initial deadlines.
Registration
Registration with the competent authority within the statutory period.
Management
Approval, oversight and training duties at management level.

How SCRM covers it

Customer demands as tasks

Who needs what evidence by when – with an owner instead of an inbox.

Security profile per supplier

Your own chain assessed, because the requirement travels onward.

Evidence with expiry

Certificates and declarations renewed before the customer asks.

Incident history

Reports and actions documented, in both directions of the chain.

Frequently asked

We are a Swiss supplier. Does the NISG affect us?

Not directly. Your Austrian customer must assess the security of its direct suppliers, and that assessment consists of questions to you.

What changed from the old NISG?

The population of covered entities is considerably larger, requirements are more concrete, and management bodies are explicitly accountable.

How does a supplier prepare?

With the details every questionnaire asks for: security organisation, certificates, reporting routes, subcontractors. Captured once in structure, reused thereafter.

As of July 2026. Not legal advice.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required