NIS2, Does My Swiss Company Fall Under It? Self-Assessment

5 min readLast updated By Marc Grob

Introduction

EU Directive 2022/2555 (NIS2) entered into force in January 2023, had to be transposed into national law by 17 October 2024 and has since acted directly on companies in most Member States. Switzerland has no own NIS2 transposition, its functional equivalent is the ISG (Information Security Act) since 1 April 2024, with reporting duties for critical infrastructure operators. NIS2 nevertheless hits Swiss companies directly when they have EU establishments or get pulled in via supply chains as suppliers ("pull-through").

This self-assessment answers the question "Does my Swiss company fall under NIS2?" in five steps:

  • Do I have an EU establishment? Where? In which legal form?
  • Does this establishment fall into a NIS2 sector (Annex I or II)?
  • Is the size sufficient for applicability (mid-cap threshold 50 FTE / EUR 10 million)?
  • Am I a supplier to a NIS2-obligated entity and pulled in indirectly?
  • Which obligations apply specifically, essential or important entity?

Important: the Swiss ISG with its reporting duties is not identical to NIS2. Anyone in both regimes must master both reporting paths. Dual reporting is not yet harmonised in 2026, the BACS in Bern and ENISA/CSIRT network in the EU operate in parallel.

Step 1, EU establishment

NIS2 applies under Art. 2(1) to entities providing services or carrying out activities in the Union that fall within scope. An "entity" can be a subsidiary, branch, agency or representative office. A Swiss parent group without an EU subsidiary is not directly NIS2-obligated, but as soon as there is a German GmbH, French SAS, Irish Limited or Luxembourg S.à r.l., that entity is assessed.

For providers of certain services, cloud computing, online marketplaces, search engines, domain-name services, trust services, DNS, IXP, data centre, an extended scope applies under Art. 26(1)(b): NIS2 catches providers offering services in the EU even without an EU establishment, with an obligation to designate an EU representative (Art. 26(3), analogous to Art. 27 GDPR). A Swiss cloud provider with EU customers and no EU establishment falls directly under NIS2 and needs an EU representative.

Step 2, sector match

Annex I (sectors of high criticality, Art. 2(1)(a)) covers: energy (electricity, district heating, oil, gas, hydrogen); transport (air, rail, water, road); banking; financial market infrastructure; health; drinking water; waste water; digital infrastructure (IXP, DNS providers, TLD registries, cloud providers, data centres, CDN, trust service providers, public electronic communications networks and services); ICT service management (managed service providers, MSSP); public administration; space.

Annex II (other critical sectors) covers: postal and courier services; waste management; manufacture, production and distribution of chemicals; food production, processing and distribution; manufacture of medical devices, in-vitro diagnostics, computer/electronic/optical products, electrical equipment, machinery, motor vehicles/trailers, other transport equipment; digital providers (online marketplaces, search engines, social networks); research organisations. For Swiss industrial SMEs with an EU establishment, Annex II hits more often, particularly medtech, pharma, specialty chemicals, machinery. Anyone doing "manufacturing" must check whether their products fall under Annex II.

Step 3, size threshold

NIS2 applies in principle to medium and large enterprises per EU Recommendation 2003/361/EC: employing 50 or more persons or annual turnover and balance sheet total exceeding EUR 10 million. Important: both thresholds are checked on a group-consolidated basis. A Swiss parent with 500 employees and an EU subsidiary with 30 employees is typically assessed as "linked", the subsidiary exceeds the threshold because of group membership.

Classification by threshold: Large enterprises (250+ FTE or EUR 50+ million turnover and EUR 43+ million balance sheet total) in Annex I sectors = Essential Entity (highest obligations, proactive supervision). Medium enterprises (50–249 FTE / EUR 10–50 million turnover) in Annex I sectors = Important Entity (same security obligations, reactive supervision). Annex II sectors = generally Important Entity, unless large enterprise with special criticality (then Essential). Certain actors (TLD registries, DNS providers, critical administration, trust service providers) are Essential regardless of size, the size cap-out does not apply.

Step 4, supply chain pull-through

Art. 21(2)(d) NIS2 requires obligated entities to manage supply chain risk, in particular assessment of the cybersecurity of their suppliers and service providers, contractual security requirements, audit rights, incident information duties. In practice this means: a German energy utility (Essential Entity) will contractually bind its Swiss switchgear supplier to NIS2-equivalent controls. A French hospital will want to audit its Swiss ICT service provider. A Dutch bank will pull its Swiss treasury platform under its TPRM supervision.

Swiss suppliers are therefore de facto affected by NIS2 even without direct applicability. The control expectations correspond to Art. 21(2) NIS2: risk analysis, incident handling, business continuity, supply chain security, acquisition/development security, effectiveness assessment, cyber hygiene practices, cryptography policies, access control, asset management, personnel security/awareness, multi-factor authentication. Swiss companies that already have these controls from an ISO 27001 heritage can close the mapping table with manageable additional effort, anyone without an ISMS sees 18 months of build-up ahead.

Step 5, obligations by status

Essential Entities and Important Entities have the same material security and reporting obligations, they differ primarily in supervisory intensity and sanction range. Obligations: cybersecurity risk management with Art. 21(2) measures; incident reporting with three deadlines (early warning 24h, incident report 72h, final report 1 month); registration with the competent authority; supplier security management; management responsibility with personal liability of the executive board (Art. 20).

Sanction range: Essential Entities up to EUR 10 million or 2 percent of global turnover (Art. 34(4)); Important Entities up to EUR 7 million or 1.4 percent (paragraph 5). In addition, the national authority can temporarily remove the executive board from their function or suspend the conformity certification (Art. 32(5)). The latter sanction is existential for regulated markets (energy, banking). Supervision is national: BfDI/BSI in Germany, ANSSI/CNIL in France, NCSC in the Netherlands, Garante/AgID in Italy. Swiss EU subsidiaries must know which authority is competent for them.

ISG vs NIS2, the Swiss duplication

The Swiss ISG obliges critical-infrastructure operators to report "significant cyberattacks" to the BACS within 24 hours of becoming aware (Art. 74e ISG read with Art. 1 ISV-NCSC, in force since 1 April 2024). The critical-infrastructure catalogue in the Annex to ISV-NCSC covers, among others, energy, finance, health, drinking water, transport, ICT, administration, substantively close but not identical to NIS2 Annex I. A Swiss critical-infrastructure entity with a German subsidiary that falls under NIS2 may need to report a cyber incident both to the BACS (for Swiss operations) and to the German authority (for German operations).

Practical consequence: an integrated incident response plan that captures the triggers and addressees of both regimes is mandatory. During an incident, there must be no 30 minutes of deliberation about whether ISG or NIS2 applies, both reporting paths must be prepared with the right templates, contacts and escalation paths. A shared crisis console is the minimum; a played-through tabletop exercise with both authorities in scenario is the maturity level an internationalised Swiss group should reach.

How SIDD supports you

SIDD runs NIS2 self-assessments for Swiss groups with EU exposure: group map, establishment analysis, sector match, size classification, supply-chain pull-through. We deliver a documented decision per entity and, where an obligation applies, an implementation plan that integrates NIS2 security duties into the existing ISMS (ISO 27001 mapping). For supplier pull-through, we build the contractual control packages that EU customers expect.

More on our services at ISMS & ISO 27001 and for ongoing CISO support at External CISO / ISB. For penetration tests expected under NIS2 Art. 21(2), see Penetration testing and vulnerability scanning. Further reading: NIS2 Directive for Swiss groups and NIS2 vs ISO 27001 mapping. To request a concrete self-assessment, use our quote form or reach us via the contact form.

Need help putting this into practice? SIDD operates the matching service.
See service →

NIS2, Does My Swiss Company Fall Under It? Self-Assessment

INSIGHT

InfoSec
24 May 2026
Marc Grob
Is my Swiss company covered by NIS2? A five-step self-check: EU establishment, sector, size, supply chain and obligations by status.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.