NIS2 Supply-Chain Obligations, What Awaits Swiss Suppliers

7 min readLast updated By Oliver Stutz

Introduction

The NIS2 Directive (Directive EU 2022/2555) has materially expanded the geographic reach of European cybersecurity regulation. Swiss companies are affected too, not as directly regulated essential or important entities, but as links in the supply chains of European customers. Software vendors, cloud providers, managed-service providers and hardware manufacturers selling into NIS2-regulated supply chains have experienced tangible new demands since the 17 October 2024 transposition deadline: tougher RFP questionnaires, harder contract clauses, deeper supplier audits.

This article covers:

  • The obligations Art. 21(2)(d) NIS2 imposes on the supply chain.
  • The contractual flow-down clause patterns European customers typically demand.
  • What evidence auditors actually want, from SBOM to incident-notification SLA.
  • How Swiss suppliers should prepare organisationally and technically.
  • How NIS2 interacts with the Federal Act on Data Protection (DSG), ISO/IEC 27001:2022 and DORA.

The legal anchors are Art. 21 (cybersecurity risk-management measures), Art. 23 (reporting obligations) and Art. 24 NIS2 (European cybersecurity certification schemes), with national transposition acts on top, Germany's NIS2UmsuCG, Austria's NISG 2024, Italy's D.Lgs. 138/2024. In Switzerland, the Information Security Act (ISG, in force since 1 January 2024) and the BACS/NCSC reporting obligations under Art. 74a–74f ISG provide the parallel domestic framework.

Which suppliers are in scope

NIS2 directly regulates entities in 18 sectors (Annexes I and II), including energy, transport, banking, financial market infrastructure, healthcare, drinking water, digital infrastructure, ICT service management, public administration, postal services, waste management, chemicals, food, manufacture of critical products, and digital service providers. Swiss companies without an EU establishment are not in scope as such, unless they provide certain digital services in the EU (cloud computing, online marketplaces, search engines, social networks, data centres, CDNs) for which Art. 26(1) NIS2 creates an extraterritorial hook. In that case, Art. 26(3) NIS2 requires the appointment of a representative in the EU.

The typical Swiss supplier, however, is not directly regulated but is pulled in through the customer's supply chain. Art. 21(2)(d) NIS2 obliges regulated entities to ensure "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers." That obligation cascades contractually: the customer transfers its own duties, to the extent legally feasible, to the supplier.

In practice, the Swiss suppliers most exposed are software and SaaS vendors with DACH customers, IT service providers (managed services, helpdesk, hosting), specialist OT/ICS integrators, cybersecurity consultancies, IIoT hardware vendors, and audit firms that hold productive-system access at their clients.

What Art. 21 NIS2 concretely requires

Art. 21(2) NIS2 lists ten minimum measures every regulated entity must implement. The ones most relevant to the supply chain are:

  • (a) Risk analyses and information system security policies.
  • (b) Incident handling.
  • (d) Supply chain security, including supplier and service-provider relationships.
  • (e) Security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure.
  • (f) Policies and procedures to assess the effectiveness of cybersecurity risk-management measures.
  • (h) Policies and procedures regarding cryptography and encryption.
  • (i) Human resources security, access control policies and asset management.
  • (j) Multi-factor authentication, continuous authentication and secure voice, video and text communications.

Art. 21(3) NIS2 adds that entities must take into account "relevant best practices and, where applicable, relevant European and international standards." Customers therefore systematically cite ISO/IEC 27001:2022 (especially Annex A.5.19–A.5.23 on supplier management), ISO/IEC 27036, BSI IT-Grundschutz module OPS.2.3 and NIST SP 800-161 Rev. 1 (Cybersecurity Supply Chain Risk Management Practices).

In June 2024 ENISA released a draft NIS2 Technical Implementation Guidance describing minimum practices for supplier governance, documented supplier risk assessment, incident-notification clauses, right-to-audit, sub-outsourcing approval.

Contractual flow-down clauses

Since early 2025, Swiss suppliers have been systematically receiving sharpened clauses in DACH contracts. The most recurrent building blocks:

  • Security requirements: reference to ISO/IEC 27001 or equivalent, obligation to maintain an Information Security Management System with annual re-certification or at least a documented internal audit.
  • Incident notification: within 24 hours of knowledge, often expressly mirroring the staged regime of Art. 23(4) NIS2 (24h early warning, 72h incident notification, 30-day final report).
  • Right to audit: pre-notice (typically 30 days), on-site under NDA, right to instruct independent third parties.
  • Sub-outsourcing control: prior written approval, obligation to flow the same clauses down to sub-contractors, maintenance of a current sub-supplier list.
  • Vulnerability management: patch SLA (typically 24h critical, 7d high, 30d medium), CVE tracking, coordinated disclosure per ISO/IEC 29147.
  • Software bill of materials: SBOM in CycloneDX or SPDX format, refreshed at every major release.
  • Background checks: criminal-record extract, identity verification, sometimes enhanced clearance for personnel with productive-system access.
  • Exit clauses: return and secure deletion of all data within defined deadlines, migration support, retention periods.

Accepting clauses unchanged is economically risky. A clause playbook with standard positions and negotiated fallbacks calibrated to contract value pays for itself within the first three deals.

What auditors actually want to see

Supplier audits by customers or third-party assessment firms have professionalised sharply in DACH markets through 2025. Typical checkpoints and expected evidence:

  • Governance: information-security policy signed off by top management, annual review evidenced, defined roles (CISO or ISO, supplier-management owner).
  • Risk management: methodology (e.g. ISO/IEC 27005), current risk register with semi-annual update, risk treatment plan.
  • Asset inventory: complete CMDB, protection-need classification, lifecycle tracking.
  • Vulnerability management: SLA performance via ticket metrics (Mean Time to Patch), monthly vulnerability-scan report.
  • Incident response: documented IR plan, at least annual exercise (tabletop or live), escalation matrix.
  • Business continuity: BCP/DRP documentation, RTO/RPO defined, annual recovery test.
  • Awareness: training plan, training completion rate > 95%, phishing simulations.
  • Sub-suppliers: list of sub-contractors, their security assessments, contract documentation.

Auditors generally accept ISO/IEC 27001:2022 certificates, SOC 2 Type II reports or C5 attestations as presumption of conformity. Pure self-declarations (filled-out vendor security questionnaires without external verification) are increasingly accepted only for non-critical suppliers.

Reporting obligations and 24-hour logic

Art. 23 NIS2 establishes the multi-stage reporting regime that is increasingly flowed down to suppliers contractually. On a significant incident, the regulated customer must send an early warning to the competent national authority (Germany: BSI; Austria: BMI/GovCERT) within 24 hours, a full incident notification within 72 hours, and a final report within one month. For the customer to meet these windows, the supplier typically has to notify within 12 to 24 hours.

Swiss suppliers must also bear in mind Art. 74a–74f ISG: since 1 April 2025, operators of critical infrastructure in Switzerland face their own 24-hour reporting duty to the Federal Office for Cyber Security (BACS / NCSC). If a Swiss supplier serves a Swiss customer that itself passes NIS2 cascade obligations to EU end customers, reporting paths can overlap.

Recommendation: a single "one-notification policy" with a clear escalation matrix, named contacts (security officer and deputy, 24/7 reachable), pre-built templates per customer and a central incident-logging platform reduces complexity sharply. Equally important is a contractual clause that defines significant incident precisely, otherwise every minor event triggers a notification cascade.

Intersections with DSG, ISO 27001 and DORA

NIS2 supply-chain duties do not exist in isolation; they overlap with other regimes. The key intersections:

  • DSG: Where personal data is processed, Art. 9 DSG (processor agreements), Art. 24 DSG (notification to the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) "as soon as possible") and Art. 8 DSG (data security) apply in parallel. A NIS2 supplier contract is not automatically a valid Art. 9 DSG processor agreement; both must be modelled separately.
  • GDPR: For EU customers, Art. 28 GDPR adds, together with Art. 32 (technical and organisational measures) and Art. 33 (notification to supervisory authority within 72h).
  • ISO/IEC 27001:2022: Annex A.5.19 (information security in supplier relationships), A.5.20 (addressing information security within supplier agreements), A.5.21 (managing information security in the ICT supply chain), A.5.22 (monitoring, review and change management of supplier services) and A.5.23 (information security for use of cloud services) cover most NIS2 supply-chain expectations.
  • DORA: For ICT third parties to regulated financial entities, Art. 28 ff. of Regulation EU 2022/2554 add a separate Register of Information, concentration-risk assessment and tougher contractual standards.
  • Cyber Resilience Act: from December 2027 products with digital elements must demonstrate CRA conformity, relevant for hardware suppliers.

Swiss suppliers benefit strongly from running an integrated compliance architecture rather than treating each regime in isolation. Our ISO 27001 consulting follows this integrated approach.

How SIDD supports you

SIDD helps Swiss suppliers build a NIS2-ready security organisation. We start with a supplier-clause analysis of your top 10 contracts, identify gaps to Art. 21 NIS2, and design a realistic 90/180/365-day programme. Typical work packages are the implementation of an ISMS per ISO/IEC 27001:2022 as a multi-purpose vehicle (see ISMS & ISO 27001), establishment of a CISO mandate for operational governance (see external CISO/ISO), hardening of your supplier-clause library including a negotiation playbook, and the build-out of an incident-response process with 24/7 on-call and pre-built notification templates for the most common DACH customers.

We combine legal depth (Art. 21 ff. NIS2, ISG, DSG, GDPR, DORA) with technical implementation, including technical audits, penetration tests and vulnerability scans that double as customer-facing evidence. Where relevant, we also assess whether you need an EU representative under Art. 26 NIS2 or whether a Swiss regime (FINMA, BACS / NCSC) applies in parallel.

Reach us via /kontakt for a non-binding first conversation or request a tailored proposal at /offerte. For pure budget indications, you receive a written quote with fixed-price options for clearly scoped modules within a few working days of a 30-minute scoping call.

Need help putting this into practice? SIDD operates the matching service.
See service →

NIS2 Supply-Chain Obligations, What Awaits Swiss Suppliers

INSIGHT

InfoSec
24 May 2026
Oliver Stutz
NIS2 in the supply chain: which requirements EU customers pass on to Swiss suppliers, contract clauses, audits and reporting channels.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.