On 31 December 2026 a deadline expires that many management teams first learn about through a customer questionnaire. By then the Information Security Act requires every organisation subject to it to have a working ISMS, meaning a management system that runs in operations, not a binder of policies. Four months before the cut-off date, the ISG ISMS obligation therefore raises two questions that are landing on management tables in Swiss SMEs right now: are we affected at all? And if so, is there still enough time?
Both questions can be answered soberly. The answer to the first surprises most people, the answer to the second is more uncomfortable than vendors of compliance packages like to tell it.
The ISMS obligation under the ISG applies by 31.12.2026 only to directly subject organisations, above all operators of critical infrastructure. Most SMEs are still reached by it, just on a different route: through the contracts and supplier audits of their customers. Companies that start with focus now build a credible foundation by year end. Companies that buy tools or produce paper in deadline panic spend money without getting safer.
Who is affected by the ISG ISMS obligation?
Directly affected are federal authorities, organisations with federal tasks, and operators of critical infrastructure across nine sectors, among them energy, drinking water, transport, and cantonal and municipal administrations. A typical Swiss SME with 50 to 500 employees is normally not directly subject to the ISG. It is affected indirectly anyway, as soon as it supplies such organisations.
The ISG has come into force in stages. Since 1 April 2025 the obligation to report cyber attacks to the Federal Office for Cybersecurity applies: operators of critical infrastructure report attacks within 24 hours of discovery. Since 1 October 2025 fines of up to CHF 100'000 are possible when a BACS order is ignored. And by 31 December 2026 subject organisations must have built their ISMS.
The legislator did not invent the ISMS and then set a deadline. It established that critical infrastructure without systematic security management is a risk to the country, and is now catching up with what well-run organisations do anyway. The deadline is the end of a transition period, not the start of an idea.
The deadline belongs to the regulator. The risk sits in sales.
For an SME not subject to the ISG, a BACS fine is irrelevant. Something else is relevant. Critical infrastructure operators are not allowed to let their duties end at their own company boundary, so they pass the requirements on to their suppliers by contract. Your customer's deadline thereby becomes your deadline, only without a legal text and without a transition rule.
Here is how that looks in practice. A supplier with around 120 employees, a vendor to an energy utility for years, receives a security questionnaire as part of the contract renewal. One of the questions essentially asks whether an ISMS is operated and how it can be evidenced. IT answers the questionnaire to the best of its knowledge, the customer's procurement team rates the answers as insufficient, and suddenly a long-standing contract hangs on a topic that never had internal priority. No auditor called, no authority issued an order. It was sales that felt the problem first.
In our experience that is the normal case, not the exception. Regulation rarely reaches SMEs directly. It reaches them through their customers' procurement departments, and those know no transition periods, only award criteria. Fail there and you do not get an order from an authority, you simply do not get the contract. Anyone sitting in the supplier portfolio of two or three large customers should therefore take the ISG deadline seriously, even when their own company appears nowhere in the law.
For the board a second level comes on top. Whether the ISG applies directly or not, the duty of careful oversight always applies, and a board that knows its most important customer expects an ISMS can hardly dismiss the topic as an IT detail. The uncomfortable question in the room is not whether the law bites, but whether you can document that you assessed the risk deliberately.
What does the ISG concretely require from an ISMS?
A working ISMS, not a certificate. The law requires an organisation to lead its information security systematically: know and assess risks, settle accountability, implement controls and review their effectiveness. In practice most organisations orient themselves on ISO 27001, because the standard describes exactly this leadership logic and is understood by customers and auditors alike.
The difference between an ISMS and a binder full of policies is not the volume, it is the question it answers. A policy binder answers the question of what has been regulated. An ISMS answers the question of which risks the company carries, which it treats and who decided that. A consultancy can deliver the first. Only the organisation itself can deliver the second, because the decisions belong to it. Which systems are critical for the business? Which outage would be survivable, which not? How much residual risk does management accept, and does it know? No service provider can answer these questions for you. They can ask them, put the answers in context and cast them into a system that holds in daily work, but the decisions stay in the house.
That is why the shortcut attempt fails so reliably. Buy an ISMS as a document package and afterwards you have documents, but no answers. In the customer audit at the latest, when somebody asks when the risk register was last discussed with the management team, paper separates from operation. How the ISG, the nDSG and customer requirements can be brought together into a single system instead of maintaining three parallel paper worlds is described in our article on IT compliance in Switzerland.
Are four months still enough for an ISMS?
For a lived ISMS from zero it gets tight, for a credible foundation the time is enough. A focused build with a clear scope, asset and risk registers, settled responsibilities and the first implemented measures is doable as a 90-day programme. What will not appear by year end is the maturity a system only has after several cycles of risk assessment, measures and review. That comes in 2027, if the start succeeds in 2026. A system that starts in autumn and has implemented its first measures by December is further along at year end than one delivered in November as a finished document package.
That is not bad news once you understand how examiners and customers look at deadlines. In our experience procurement departments and auditors distinguish quite reliably between three states: nothing, paper without operation, and a system under construction with a visible course. The third state opens doors the second does not, even though it looks like more. A risk register with ten honestly assessed risks and a management team that can speak to them convinces more than eighty pages of policies nobody can speak to.

The decision due in the coming weeks is therefore a leadership decision: who carries the topic? With what mandate, what budget, what reporting line to management and the board? What the build realistically costs in effort and money we worked through for ISO 27001 in an SME. The numbers apply by analogy to an ISMS under the ISG, because the leadership work is the same.
The most expensive ISMS is the one nobody lives
Deadlines are high season for sellers. Four months before the cut-off, compliance packages, ISMS tools and all-in offers appear that tell security as a purchasing decision: buy the licence, deadline met. Let us be honest, if a management system were purchasable, the legislator would not have needed a multi-year transition period.
The direction of thinking that works is the reverse. First clarify what has to be protected and what is already there, then decide what is missing. Most SMEs we see do not have a gap problem, they have a sizing problem: too many tools, too little overview, too much cost for too little real protection. An ISMS build is the best moment to correct that, because every system, every contract and every responsibility comes onto the table anyway. Being consistent about it, you come out with more protection and fewer tools, not rarely with lower running costs too. The deadline then turns from a cost driver into an occasion to tidy up.
That an honest stocktake stands at the beginning and not a product catalogue is also why we start every mandate with a stocktake. How that entry works is described in the process on the homepage.
Frequently asked questions
Does the 24-hour reporting duty apply to SMEs not subject to the ISG?
No. The reporting duty under the ISG applies to operators of critical infrastructure. An SME not subject to it reports to BACS voluntarily, which can well be sensible. Contractually, however, a reporting deadline of your own can exist: many customers require suppliers to report security-relevant incidents within defined deadlines. Here the contract replaces the law.
Do we need an ISO 27001 certificate to meet the ISG requirement?
No. The ISG requires a working ISMS, not a certificate. ISO 27001 is the most widespread framework for it and makes the evidence easier towards customers. Whether certification pays off is a separate decision, depending mainly on how often you have to produce the evidence externally and how much effort answering questionnaires eats today.
What happens if the deadline at the end of 2026 is missed?
Subject organisations face supervisory consequences, while fines require an ignored BACS order. For everyone else the risk is commercial: customer audits that end badly, and tenders where the evidence is missing. These consequences know no cut-off date, they arrive with the next questionnaire.
Whether the ISG binds you directly or only your largest customer's questionnaire does: the work behind it is the same, and it starts with a sober stocktake rather than a tool purchase.
