NIS2 Directive, What Swiss Groups with EU Exposure Must Do
Introduction
Directive (EU) 2022/2555 (NIS2) has been in force since 16 January 2023 and should have been transposed into national law by 17 October 2024. The reality: as of May 2026, Germany, France, Italy, Austria and a number of further member states have either passed their national transposition or are close to it; infringement proceedings by the EU Commission against late states are running. The effect on Swiss groups is nonetheless already visible, not through direct applicability, but through contract cascades from the EU.
This guide covers:
- Who counts as ‘essential’ or ‘important’ in the EU
- Why Swiss groups with EU subsidiaries or EU customers get pulled in
- The ten minimum measures under Art. 21(2) NIS2
- The staggered incident reporting under Art. 23 (24 h / 72 h / 30 days)
- Supply-chain pull-through under Art. 21(3)
- The ISO/IEC 27001:2022 ↔ NIS2 mapping
Whoever treats the NIS2 requirements as an ISO 27001 module has a highly efficient implementation path. We show where the overlaps are and where NIS2 adds extra requirements.
Essential vs important
NIS2 distinguishes two categories (Annex I and II): essential entities and important entities. The duties are largely identical; the difference lies in supervisory intensity (ex ante vs. ex post) and the level of fines.
Essential sectors (Annex I): energy, transport (air, rail, water, road), banking and financial market infrastructure, health, drinking water, waste water, digital infrastructure (DNS resolvers, TLD registrars, data centres, cloud providers, CDNs, trust services, B2B telcos), public administration, space.
Important sectors (Annex II): post and courier, waste management, chemicals, food, manufacturing of machinery and electronic devices, digital providers (online marketplaces, search engines, social networks).
The size threshold: usually medium and large companies (from 50 employees or EUR 10 million annual turnover, per the EU SME recommendation). With this threshold NIS2 captures an estimated 100,000+ companies in the EU, multiples of the NIS1 population. Individually classified critical entities can fall under the duties even below the threshold (Art. 2(2)).
Why Swiss groups get pulled in
Switzerland is not a member state, NIS2 does not apply directly. It nonetheless reaches into the Swiss group through three routes:
1. EU subsidiaries: a Zurich-domiciled SAP, insurance or industrial group whose German or Austrian subsidiary conducts Annex I or Annex II activities falls under NIS2 with that subsidiary. Even without group-wide applicability, groups typically coordinate NIS2-compliant controls uniformly, not from obligation but from efficiency.
2. Supply chains (Art. 21(2)(d) and (3)): NIS2 requires essential and important entities to govern the security of their supply chain. Concretely: assessment of the security practices of each ‘direct supplier and service provider’, including non-NIS2 third-country ones. Swiss vendors who deliver SaaS, managed services, outsourcing or advisory to German banks, utilities, hospitals or authorities will be drawn into the contractual NIS2 reflex, with annexes on security requirements, audit rights, incident reporting to the EU customer and right-to-test clauses.
3. EU representative duty for digital service providers: certain online services must appoint a representative in the EU, similar to Art. 27 GDPR. Swiss providers offering such services in the EU are caught.
In practice: scope for Switzerland is primarily determined by contract, not by geography.
The ten minimum measures under Art. 21(2)
Art. 21(2) NIS2 names ten measure fields that must be covered. They are deliberately technology-neutral and broadly mirror the top-level categories of modern security standards:
- Risk analysis and information security policies
- Incident handling
- Business continuity (BCM, backups, crisis management)
- Supply-chain security
- Security in procurement, development and maintenance of ICT systems including vulnerability management
- Policies and procedures to assess the effectiveness of the security measures
- Basic cyber hygiene practices and cybersecurity training
- Policies and procedures on cryptography and encryption
- Human resources security, access control policies and asset management
- Multi-factor authentication, continuous authentication, secure voice, video and text communications, secure emergency communications
Anyone running an ISO/IEC 27001:2022 certified ISMS can document these ten fields without a fundamental rebuild, the additional work consists of the mapping (see below) and a focused supplier security and incident reporting track.
Incident reporting, 24 / 72 / 30
The second operational core requirement is the staggered incident reporting under Art. 23 NIS2:
- 24 hours from awareness of a significant incident: early warning to the competent national CSIRT/NIS2 authority indicating whether the incident is suspected of being malicious.
- 72 hours from awareness: incident notification updating the early warning, with a first assessment of impact, severity and indicators of compromise.
- 1 month after the incident notification: final report with detailed description, root cause, measures taken and cross-border impact.
What counts as a significant incident is defined in Art. 23(3): severe operational disruption, financial damage or considerable material or non-material damage to third parties. In practice this is a low threshold. For Swiss groups with EU subsidiaries, the group incident response must therefore handle EU notification paths in parallel, with a ‘single point of notification’ per country, prepared templates, language coverage and an escalation matrix that delivers inside the 24-hour clock.
Supply chain and contractual pull-through
Art. 21(2)(d) and (3) NIS2 require essential and important entities to assess the cybersecurity practices of their direct suppliers and service providers and derive measures, including ‘specific vulnerabilities of each direct supplier’ and ‘the overall quality of products and cybersecurity practices of its suppliers’. What you will concretely experience as a Swiss vendor:
- Questionnaires that are markedly deeper than the previous standard vendor risk assessment
- A contractual undertaking to meet the NIS2 minimum measures ‘appropriately’, often with ISO 27001 as the target evidence
- Right-to-audit, right-to-test (penetration testing on customer-purchased services)
- Sub-contractor governance with consent reservation
- Pre-contractual sub-processor mapping
- Incident reporting to the EU customer within a contractually agreed deadline (typically 24 hours)
- SBOM requirements (software bill of materials) for product suppliers
Swiss vendors who cannot satisfy these contractual pull-through requirements will visibly lose tenders in 2026. Those who can show a certified ISMS, a documented vendor risk programme and a rehearsed incident response workflow win group customers.
ISO 27001 ↔ NIS2 mapping
The ten NIS2 minimum measures map almost one-to-one to ISO/IEC 27001:2022 Annex A. A compact overview:
- Risk analysis and ISMS policy → clauses 4.2, 6.1, A.5.1, A.5.2
- Incident handling → A.5.24–A.5.27
- Business continuity → A.5.29, A.5.30, A.8.13, A.8.14
- Supply-chain security → A.5.19–A.5.23
- Security in development/procurement → A.5.37, A.8.25–A.8.31, A.5.20
- Effectiveness assessment → clauses 9.1, 9.2, 9.3
- Awareness and training → A.6.3, A.6.4
- Cryptography → A.8.24
- HR security, IAM, asset management → A.5.9–A.5.18, A.6.1, A.6.2, A.6.5–A.6.8, A.7.x
- MFA and secure communications → A.5.17, A.8.5, A.8.20–A.8.23, A.5.14
Where NIS2 explicitly goes beyond ISO 27001: the staggered 24/72/30 reporting (Art. 23) and personal liability of management (Art. 20). Neither is contained in ISO 27001 expressis verbis. Anyone running a certified ISMS should therefore maintain a dedicated NIS2 annex bridging the two: which ISO clause covers which NIS2 requirement, where the delta sits and which workflow closes it.
How SIDD supports you
SIDD sets up the NIS2 programme for Swiss groups with EU subsidiaries or EU customers, pragmatic, ISO 27001 compatible and with clear interfaces to GDPR and DSG. Our ISO 27001 service is the methodological foundation; the staggered incident reporting and the vendor risk programme are placed on top as a modular extension. Where needed we provide an external CISO / information security officer who runs the NIS2 steering and reports to management and EU supervisors.
For technical evidence we combine the programme with penetration tests and vulnerability scans; for awareness with IT security workshops; and for supplier clauses and EU customer contracts with our legally grounded data protection and compliance advisory. A first NIS2 baseline runs via the contact form; a fixed-price implementation proposal comes within five working days via the offer.
