NIS2 is an EU directive. Switzerland is not in the EU. For many management teams the topic is settled before it started. Until a paragraph appears in the framework agreement of a large German customer demanding reports within 24 hours, granting audit rights and requiring evidence on information security. The first sentence is still true. It has just become irrelevant, because the requirement does not arrive through law, it arrives through procurement.
NIS2 does not bind Swiss SMEs directly. It reaches you through the contract: affected EU customers have to co-manage the security of their direct suppliers, and their management is personally liable for it. So they pass the requirements on. What lands with you are clauses with short reporting deadlines and evidence duties. The work on it largely pays into what the Swiss ISG demands anyway.
Does NIS2 apply to Swiss companies?
Directly, no. NIS2 is EU Directive 2022/2555, which member states had to transpose into national law by 17 October 2024. A Swiss company without an establishment in the EU does not fall under it.
Two routes lead in anyway. One is obvious: anyone with a subsidiary in the EU operating in one of the sectors is captured there directly. The other is the more common one, and the one almost nobody has on the radar. It runs through the customer relationship.
Whether a customer is affected can usually be estimated roughly. The directive captures medium and large companies in eighteen sectors, among them energy, transport, health, banking, drinking water and waste water, digital infrastructure, postal and courier services, waste management, the manufacture of critical products, and public administration. Micro enterprises normally stay outside. An industrial customer in Germany with 400 employees in one of these sectors is a very likely candidate, a small trading house rather not.
That implementation across Europe is only now picking up speed does not make the situation calmer. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for still not having fully transposed the directive, including a request for financial penalties. For you that means pressure at your EU customers is rising exactly where it was missing so far.
Why your EU customer passes the requirements on to you
Because otherwise they answer for it themselves. Article 21(2)(d) of the directive explicitly requires affected companies to take measures on supply chain security, including the relationships with their direct suppliers and service providers. So your customer has to evidence not only their own security but also that they have yours under control.
On top comes the part that speeds things up in procurement. Article 20 makes management personally responsible: they must approve the risk measures, oversee their implementation, and can be held liable for breaches. The fine range for essential entities is up to 10 million euros or 2 percent of global annual turnover, whichever is higher. For important entities it is 7 million euros or 1.4 percent.
A management team that is personally liable negotiates supplier clauses differently. They would rather write the requirement into the contract too strictly than too loosely, because that is the cheaper direction of error for them. Which is exactly why Swiss suppliers regularly receive deadlines and duties that are harder than what the directive demands of the customer itself.
What the reporting deadlines mean in operations
Under Article 23 your customer has to issue an early warning within 24 hours, a notification within 72 hours and a final report at the latest one month after the notification. Those are their deadlines. Yours are whatever the contract says, and they are usually shorter, because they need your information before their own clock runs out.
That turns a regulatory question into an operational one. Twenty-four hours does not mean a tool is missing. It means that on a Friday evening somebody has to be reachable who can judge whether an incident is reportable, and who is allowed to make that call. In the companies we see it almost never fails on the technology. It fails because nobody is named and IT waits, in case of doubt, until somebody from management is reachable on Monday.
Twenty-four hours is shorter than most holiday absences. A reporting duty that only works when one particular person is in the building is not reporting capability, it is a coincidence with a good reputation.
Audit rights and evidence duties sit in the same contract and are missing from the preparation just as often. A customer who has to prove they steer their suppliers will eventually want to see proof. Whoever can then show policies, a risk register and minutes has a short meeting. Whoever starts searching then has a project.
An example, condensed from situations we meet again and again, details altered: a Swiss manufacturer with around 200 employees learned about NIS2 not from the press but from a questionnaire. A German customer, a good fifth of revenue, wanted the reporting process and the person accountable for information security documented. On checking, it turned out the corresponding clause had been in the framework agreement for fourteen months. Sales had signed it, nobody from IT had read it. The technical starting point was decent, there were backups, monitoring and a clean access model. What was missing was the answer to a single question: who decides on a Saturday whether an incident gets reported to this customer. That gap cost no investment, it cost three meetings and one named responsibility.
What else arrives from the EU through the supply chain
NIS2 is the broadest channel, but not the only one. Two further rulebooks hit Swiss SMEs on the same route, and both are already in force.
DORA has applied to EU financial entities since 17 January 2025. Anyone working as an IT or service provider for an EU bank, an insurer or a payment service provider gets the requirements written into the contract through Article 30, which sets out the mandatory content of such contracts. That also hits small Swiss software and operations providers hanging in that chain.
The EU AI Act does not attach to where you are based but to how the output is used. It captures providers and deployers from third countries when the output of the AI system is used in the EU. Anyone delivering AI features to EU customers is therefore in scope, even without an EU presence. How to organise that internally is in our article on AI governance in an SME.
On data protection many Swiss companies are under both regimes at once anyway: the revised Swiss Data Protection Act and the GDPR, as soon as personal data from the EU is processed. None of that is new. But it belongs in the same overview, because in the customer questionnaire all these points sit on the same sheet.
How much of this overlaps with the Swiss ISG?
Most of it. The Information Security Act requires organisations subject to it to have a working management system for information security by 31 December 2026, and since 1 April 2025 it provides for a reporting duty within 24 hours to BACS. The same 24-hour logic, the same question about responsibilities, the same evidence.
That is the good news in this story. A company that works through the requirements from the EU contract properly builds, for the most part, what it needs for the ISG anyway, and the other way round. Setting both up as separate projects means paying twice for the same management system. We consider separate treatment the most expensive mistake an SME can make on this topic, and it happens regularly, because regulation gets sorted by origin instead of by effect. What is coming with the ISG deadline is described in our article on the ISG ISMS obligation by the end of 2026.
What an SME has to be able to answer now
Not everything at once. Three questions decide whether NIS2 stays a contract risk for your company or becomes a managed requirement, and none of them is technical.
Which of your contracts already carry the clause? This is the question most management teams have to pass on. The clauses come in through framework agreements and purchasing terms and get signed in sales, not read in IT. In our experience the first review of existing customer contracts is the moment the topic stops being abstract.
Who decides within 24 hours? Not who reports. Who judges whether it gets reported, and who carries that decision by name, including during holidays.
Where is the evidence? An audit right is only as unpleasant as the search for the documents. If the documents sit together in one place, such a customer meeting takes two hours instead of two weeks.
What all three questions have in common is that they need a person who is allowed to answer them. As long as information security in an SME belongs to nobody by name, every one of these requirements wanders between sales, IT and management until a customer asks. How a mandate covers that role is in our article on what a fractional CISO is, and what a start looks like is under process.
Frequently asked questions
We only supply Swiss customers. Does NIS2 still concern us?
Possibly, one step further along. If your Swiss customer in turn supplies into the EU and falls under NIS2 there, they have to steer their own supply chain. Then the requirement comes from them instead of directly from Europe. So the question is not where your customers sit, it is where their customers sit.
Is an ISO 27001 certification enough for NIS2?
It covers a large part and is the strongest argument an SME can have in a customer conversation. But a certificate alone fulfils no reporting duty. What NIS2 clauses additionally require is the reporting process with clear deadlines and named accountability. Both can be hooked into an existing management system.
Do we have to hire somebody new for this?
In the rarest of cases. The work consists of contract review, a reporting process and regular maintenance, and in a company with 50 to 500 employees that fills no position. What it needs is somebody who carries the accountability and decides when it counts. Whether somebody internal takes that on or it runs on a mandate is a question of available time and experience, not of company size.
