NIS2 · Compliance Consulting

NIS2 Consulting for Swiss Companies

The EU NIS2 Directive does not only bind large corporations in the EU. Swiss companies are pulled into its scope through the supply chains of their EU customers: anyone supplying a German or Austrian client will find NIS2 security clauses in almost every new contract from 2025. And management is personally liable for implementation. SIDD makes you NIS2-ready with a gap analysis, an ISO 27001 ISMS and ready-to-use incident-reporting processes.

from CHF 500/month Lead Auditor ISO 27001 Active since 2017
NIS2 consulting for Swiss companies: gap analysis, ISMS and incident reporting
Mandate under Art. 321 SCC Professional secrecy

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide
Philipp Staiger

Responsible for this mandate

Philipp Staiger

M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)

Guides ISO 27001 certification projects from the scope workshop through to Stage 2 audit support. Interface to executive management, IT, data protection and the external certification body.

LinkedIn profile

Why NIS2 affects Swiss companies too

In brief

NIS2 is the EU cybersecurity directive that has been transposed into national law across the member states since October 2024. It requires companies in 18 sectors to run risk-based security management, to report incidents and to hold management personally accountable.

Swiss companies are directly affected if they offer certain digital services in the EU or have an EU establishment. Far more common is indirect exposure: EU clients pass the NIS2 requirements on to their suppliers by contract. Anyone supplying a German energy provider or an Austrian bank has to demonstrate the required security, or the contract is at risk.

Managing directors are personally liable

NIS2 makes cybersecurity a board-level responsibility, with consequences reaching personal liability.

Article 20 NIS2 obliges management bodies to approve the security measures, oversee their implementation and undergo regular training themselves. Violations risk not only fines of up to EUR 10 million or 2 percent of worldwide annual turnover, but also the personal accountability of management. Some national transpositions even provide for a temporary ban from holding management functions.

We put the necessary evidence in place in documented form: management approvals, traceable board-level training and clear reporting to top management. That way you meet the Article 20 duties demonstrably, not just on paper.

Are you affected by NIS2? The 5-point check

Answer the following questions. Even a single yes means NIS2 is relevant to you, directly or through your EU customers.

1

Do you supply customers in the EU, for example as a supplier, IT service provider or SaaS vendor?

2

Do your EU clients impose contractual requirements on your cybersecurity or on the security of your supply chain?

3

Do you operate a branch or subsidiary in an EU member state?

4

Do you belong to a NIS2 sector such as energy, health, transport, manufacturing or digital infrastructure?

5

Do you provide digital services in the EU, such as cloud, data centre, online marketplace or search engine?

We confirm whether NIS2 applies to you in a binding initial consultation and scope it precisely before any effort is incurred.

NIS2 and the Swiss ISA: two separate regimes

We deliberately keep the two regimes apart.

NIS2 is EU law and reaches Swiss firms through EU contracts and EU establishments. The Swiss Information Security Act (ISA), with its reporting duty to the NCSC (BACS), is a separate national regime for operators of critical infrastructure. The two overlap heavily in substance, but they are legally independent and are enforced by different authorities.

Where you have to satisfy both, we set up a management system that covers the duties under NIS2 and the ISA with a single investment, instead of running two parallel programmes.

Our methodology: NIS2 readiness in five steps

Five steps from baseline assessment to demonstrable NIS2 evidence. No vague quick wins, but a traceable methodology with clear deliverables.

Applicability and scoping

We establish whether and through which contracts NIS2 applies to you, and scope it precisely.

Gap analysis against Art. 21(2)

Comparison of your existing measures with the ten NIS2 minimum measures and the Annex A controls of ISO 27001.

Measures and ISMS

Building or extending an ISO 27001 management system as a robust foundation for the NIS2 requirements.

Reporting and incident playbooks

Ready-to-use processes for the NIS2 deadlines: 24-hour early warning, 72-hour incident notification and 30-day final report.

Evidence and audit support

Board training, supplier documentation and support through to demonstrable evidence for clients and authorities.

What SIDD's NIS2 consulting covers

  • Binding applicability analysis and scoping along your EU contracts
  • Gap analysis against Art. 21(2) NIS2 mapped to ISO/IEC 27001:2022 Annex A
  • Building or adapting the ISMS including policies, risk register and Statement of Applicability
  • Reporting processes and incident playbooks for the NIS2 deadlines of 24, 72 and 30 days
  • Documented management training under Art. 20 NIS2
  • Supplier and security documentation for audits by your EU clients

For individual sectors we cover the NIS2 requirements in more depth separately:

NIS2 consulting: packages and pricing

Transparent pricing, no hidden effort. Ongoing support starts at CHF 500 per month.

Gap analysis · project

Fixed fee on request

One-off NIS2-vs-ISO-27001 gap analysis with a prioritised roadmap.

  • Applicability and scoping analysis
  • Mapping of Art. 21(2) to Annex A
  • Management report with risk heat map
  • Roadmap over 90, 180 and 365 days

Why SIDD?

NIS2 is a question of liability and evidence, not of buying a tool. Four reasons why companies entrust the mandate to SIDD.

Law and technology from a single team

We combine the legal assessment of the NIS2 duties with the technical ISMS build, instead of outsourcing the two to separate providers.

Led by a lead auditor

The gap analysis and ISMS build are led by a BSI-trained ISO 27001 lead auditor, with an eye on later certification.

Independent and bound by confidentiality

As an independent Swiss company with no foreign parent, we run the mandate under professional confidentiality pursuant to Art. 321 of the Swiss Criminal Code.

ISA and NIS2 kept cleanly apart

We keep the Swiss ISA and NCSC regime and the EU NIS2 directive clearly apart, and cover both where you have to satisfy both.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

Concretely for your NIS2 consulting: LexCommand places the ten minimum measures of Art. 21(2) NIS2 next to the Annex A controls of ISO 27001 and produces a traceable gap table with citations, so that every measure remains traceable back to the underlying legal provision.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions about NIS2 consulting

Does NIS2 apply to Swiss companies at all?

Directly only if you offer certain digital services in the EU or have an EU establishment. In practice, however, NIS2 affects most exporting Swiss SMEs indirectly, because their EU clients pass the requirements down the supply chain by contract.

Is an ISO 27001 certificate enough for NIS2?

An ISO 27001:2022 ISMS covers around 75 to 80 percent of the NIS2 minimum measures and is therefore the most pragmatic vehicle. Beyond that, NIS2 requires reporting processes, management training and registration duties, which we add in a targeted way.

Is management really personally liable?

Yes. Article 20 NIS2 establishes the personal accountability of management bodies for approving and overseeing the measures. We put the necessary approval, training and reporting evidence in place in documented form.

How long does a NIS2 gap analysis take?

For a company with an existing ISMS we plan around four weeks to the management report with a prioritised roadmap. We fix the exact scope during scoping.

What does NIS2 consulting cost?

Ongoing support starts at CHF 500 per month. We offer a one-off gap analysis as a fixed-fee project whose scope depends on size and complexity.

Become NIS2-ready before the next EU contract demands it

Request a quote or book an initial consultation. Enquiries are subject to professional confidentiality under Art. 321 of the Swiss Criminal Code.