Blog
Blog

NIS2: What Swiss companies need to know now

Regulierung 25 August 2026 By fortControl Editorial Team

The EU NIS2 directive obliges companies in critical and important sectors to implement significantly stricter cybersecurity measures. Swiss companies are not directly regulated — but as suppliers or service providers to EU firms, they fall within scope via the supply chain.

Who is affected?

Primarily companies providing services to EU customers in regulated sectors. Those customers must demonstrate the security of their supply chain — and pass the requirements on contractually.

  1. Step 1 NIS2 obliges EU companies Companies in critical and important sectors have to implement stricter cybersecurity measures.
  2. Step 2 Requirements for the supply chain These companies must demonstrate the security of their supply chain and pass the requirements on contractually.
  3. Step 3 Swiss suppliers within scope Swiss companies meet and document the requirements — even without being directly regulated.
NIS2 reaches Swiss companies through the supply chain.

What is required?

  • Risk management with documented technical and organisational measures
  • Incident reporting processes within defined deadlines
  • Demonstrable accountability at management level
  • Security within the company’s own supply chain

Sensible first steps

The pragmatic approach: clarify exposure, inventory existing measures and prioritise gaps. A structured framework such as ISO/IEC 27001 or the Swiss ICT minimum standard already covers a large share of NIS2 requirements.

Conclusion

NIS2 reaches Swiss companies through their customer relationships — the earlier your security posture is documented, the more confidently you can respond to customer enquiries. fortControl lets you manage measures, evidence and responsibilities centrally and audit-proof.

Loslegen

Risiken im Blick. Sicherheit im Griff.

Lernen Sie fortControl in einer persönlichen Demo kennen.

fortControl – Risikomanagement und Informationssicherheit einfach steuern.