Home · Blog
GRC

IT compliance in Switzerland: deliver it, do not just get it advised

August 17, 2026 · 8 min read · ODCUS
A leader at a desk brings a pile of scattered reports and binders together into one ordered folder, as an image for IT compliance run as a system instead of many consulting projects

The folder is called "compliance", and it keeps growing. A data protection concept from 2023, the report from the last IT compliance consultancy, two quotes for the next one, a half-completed questionnaire from the largest customer. What does not grow is the delivery. This state is common in Swiss SMEs, and it has one cause: IT compliance gets bought as a consulting project instead of being organised as an operation.

That is no accusation against the companies doing it that way. The market is built like that. Search for IT compliance consulting in Switzerland and you mostly find analyses, expert opinions and recommendations, and all of it ends in a document. But the audit asks about lived practice: who decides, who delivers, where is the evidence. A document answers none of those questions.

TLDR

For Swiss SMEs, IT compliance means the nDSG for practically everyone, the ISG for critical infrastructure and its suppliers, NIS2 and DORA through contracts with EU customers, plus customer audits as the strictest examiner. Another consulting report solves none of that. What holds up: one system with one owner, one risk register and one set of evidence that serves every requirement at once.

Which compliance requirements actually apply to Swiss SMEs?

Four legal levels, plus a fifth that is written in no law. The revised Data Protection Act (nDSG) applies to every company processing personal data, so practically all of them. The Information Security Act (ISG) binds operators of critical infrastructure, and through their contracts their suppliers too. EU rules such as NIS2 and DORA reach Swiss SMEs through the supply chain. On top come sector regulators, for instance the FINMA circulars for supervised firms and their service providers.

With the ISG it is worth looking at the calendar. Since 1 April 2025 operators of critical infrastructure must report cyber attacks within 24 hours, and the reporting duty at the Federal Office for Cybersecurity (BACS) describes the details. Since 1 October 2025 fines of up to CHF 100'000 are possible when a BACS order is ignored. And by the end of 2026 organisations subject to the ISG need a working ISMS. Anyone who supplies a critical infrastructure operator is currently getting these duties passed down by contract, often without anybody in the SME having expected it.

The nDSG in turn does not only concern companies with customer databases. If you employ people, you process personal data, and the basic duties apply: know which data sits where, protect it appropriately, be able to answer access requests, and have data breaches under control. None of that is exotic. But all of it assumes somebody knows their own data landscape, and that is exactly where things most often fall down in practice.

The fifth level appears in no law and is still often the most effective: your customer. Customer questionnaires and supplier audits now help decide whether an order arrives. A law gives you transition periods and room for judgement. A customer gives you two weeks for the questionnaire, and your competitor has already answered.

Why another consulting report changes nothing

Because IT compliance in an SME is rarely a knowledge problem. The requirements of the nDSG are in the law, the ISO 27001 controls can be read by anyone, and the customer questionnaire tells you word for word what the customer wants to see. What is missing is almost always the same: a person who is accountable, and an operation that carries the requirements.

Classic compliance consulting ends where the actual work begins. The report describes the gaps, recommends measures and gets filed. IT has no time, the management team has no translation, and in six months the report is out of date. At the next audit the game starts over, with a new consultancy and a thicker folder.

"Operation" sounds unspectacular, but it is the point where compliance is decided. What it means is everyday routine: risks get reviewed on a fixed rhythm instead of once inside a consulting project. Access gets revoked when somebody leaves, not when the audit is due. Evidence appears as a by-product because the processes produce it, instead of being reconstructed before the audit. A report can describe what that should look like. It cannot produce it.

Most SMEs do not have a compliance knowledge problem, they have a sizing problem: too many reports, tools and parallel attempts, too little accountability and operation. The route through the audit does not run through more of that, it runs through less, with one owner and one system behind it. More protection, fewer tools, lower cost.

External knowledge has its place in this. It only evaporates when nobody owns the delivery. So ask every provider not only "what do you recommend?" but also "who delivers it, and who stands next to us in the audit next year?"

What does IT compliance cost in an SME?

Three cost blocks: the one-off build (stocktake, policies, risk register), the ongoing operation (maintenance, evidence, audits) and the hidden cost of duplicated work. In our experience the third block is the most expensive, because it appears in no budget: one separate project per regulation, one firefighting exercise per customer questionnaire, one new document round per auditor.

This duplication happens because without a system every requirement starts from zero. Yet the requirements overlap heavily. The nDSG asks for appropriate technical and organisational measures, the ISG for an ISMS, the customer questionnaire asks about both. All three point at the same basic questions: which data and systems do you have, which risks exist, who is accountable, what are you doing about it, and how do you evidence it.

Five tangled ribbons run together into one ordered ribbon with a seal of approval, as an image for many compliance requirements served by a single system
Many requirements, one system: nDSG, ISG and customer audits point at the same basic questions.

An SME that answers those basic questions cleanly once and keeps them current serves every regulation at the same time. What building such a system realistically means in effort and money is broken down in our article on ISO 27001 in an SME: effort, duration and cost. The most expensive variant is, in our experience, the most common one: five half attempts in parallel, each with its own consultant, its own tool and its own folder.

For the management team the reverse holds: IT compliance becomes budgetable as soon as it is organised as an operation. A defined build, a predictable monthly effort, done. What is not budgetable is the tender lost over an unanswered questionnaire and the fourth consultancy that starts from zero again. So if you want to cut compliance cost, you do not buy cheaper reports, you end the duplicated work.

One system instead of five projects: how that looks in practice

An anonymised example: an industrial supplier, around 120 employees, three compliance consultancies in four years, three reports in the folder. Then the largest customer wrote an information security audit into the framework agreement. In the audit none of the reports counted. Other things were asked: who is accountable for information security here? Show us your risk register. When did you last test restoring your backups?

What changed afterwards was less work than the folder suggested. An owner was named, with a time budget rather than just a title. The existing documentation was halved: what nobody reads and nobody lives went out. The three reports turned into one risk register with the ten most important topics, prioritised by business risk, not by framework chapter. And every measure had a date and a piece of evidence. The audit the following year was unspectacular. That is exactly what audits should be.

The side effect was the more interesting one: the next customer questionnaire was answered in two days instead of three weeks, with references to the same registers and evidence. A compulsory exercise turned into a sales argument, because the company could show in its next proposal how it handles customer data. Many management teams underestimate this effect: in many tenders the security organisation helps decide whether the order arrives.

The principle behind it is the same as with consolidating security tools: tidy up instead of stacking. One backbone, usually oriented on ISO 27001 even without a certificate, onto which the nDSG, the ISG and customer requirements are mapped. New requirements are then no longer new projects but deltas: what does the new customer ask for on top of what already stands and is lived? Usually surprisingly little.

When is external support worth it, and in what form?

When accountability is settled but capacity and routine are missing. An IT lead with a full day job does not build a compliance system on the side, and for a full-time position the topic is too small in an SME. The right form depends on the starting point: a stocktake when it is unclear where you stand; sparring when an IT or security lead exists and needs a second opinion; a mandate with delivery accountability when the system has to be built and run.

One thing is the same in all three forms: accountability does not end with the report. What such an entry looks like in practice, from stocktake to full operation, is shown in the course of a mandate on the homepage. And an honest answer belongs to it: sometimes the right recommendation is to buy nothing yet and settle the accountability question internally first. Without that, even the best system does not hold.

Frequently asked questions

Does NIS2 apply to Swiss SMEs too?

Not directly. NIS2 is an EU directive and is not law in Switzerland. It reaches Swiss SMEs anyway: EU customers who fall under NIS2 themselves must secure their supply chain and pass the requirements on by contract. Anyone working for EU companies should check their framework agreements for such clauses before the first audit request arrives.

Do we need an ISO 27001 certificate for IT compliance?

No. No Swiss law requires a certificate. The nDSG requires appropriate measures, the ISG a working ISMS, and both can be evidenced without certification. The certificate pays off when several customers explicitly ask for it or when it makes the difference in sales. Using the ISO 27001 structure as a backbone, by contrast, pays off almost always, even without an audit by a certification body.

Can we outsource IT compliance completely?

The work yes, the accountability no. Build, operation and audit support can be taken on by an external partner. Legal responsibility stays with the management team and the board. Serious providers say so openly and therefore build internal accountability along the way, instead of delivering a black box that does not work without them.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call