NIS2 IN FOCUS: 18 INDUSTRIES, CLEAR CRITERIA AND HIDDEN OBLIGATIONS 

18 critical sectors, stricter cybersecurity requirements and severe penalties: the new EU NIS2 Directive affects more than just companies in the European Union. Swiss SMEs may also fall within its scope, either directly or indirectly – often without even knowing it. It is high time to check whether you are affected.

With penalties of up to €10 million or 2% of global annual turnover, the EU is sending a clear message with NIS2: cybersecurity is no longer a nice-to-have. The new regulatory framework has been in force in all EU member states since October 2024 – with far-reaching consequences for Swiss companies too. What is particularly controversial is that it is not only large corporations and critical infrastructures that are affected. The directive specifically targets medium-sized companies with 50 or more employees. Even suppliers working with EU companies will find it difficult to avoid the new requirements. For many Swiss SMEs, the question is therefore not whether, but how they must implement the NIS2 requirements.

NIS2: First cybersecurity directive with liability for executives

In addition to corporate penalties, as have been in place since the GDPR (2015), executives are now also personally liable for proven misconduct. They are obliged to approve risk management measures, monitor their implementation and report security incidents to the authorities and affected partners, suppliers and customers.

To fulfil these obligations, executives must regularly attend training courses to enable them to assess cyber risks and measures. Violations of this duty of care are punishable by personal penalties, the amount and type of which are determined by the member states – however, they must be ‘effective, proportionate and dissuasive’. In extreme cases, management may even be relieved of their duties until the identified deficiencies have been remedied.

Direct scope of application: core criteria at a glance

The impact of NIS2 on Swiss companies can be clearly defined: anyone who operates a branch in the EU or offers IT services there falls directly under the directive. This applies to companies that generate annual revenues of more than €10 million in the EU in 2024 or employ more than 50 people there. The consequences are far-reaching: affected companies must introduce systematic risk management, carry out regular security audits and report security incidents within 24 hours. The focus is particularly on IT service providers, cloud providers and companies in the 18 critical sectors.

Focus on the supply chain: recognising indirect NIS2 obligations

The scope of NIS2 extends far beyond directly regulated companies. As suppliers to EU companies, Swiss SMEs are increasingly confronted with NIS2 requirements – even without a formal obligation. Large EU corporations must ensure the cybersecurity of their entire supply chain. In concrete terms, this means that Swiss suppliers, for example in the automotive or mechanical engineering industries, must meet the increased security standards. From complete documentation to regular penetration tests – this evidence is already required as standard in EU tenders.

NIS2 check: Analyse your EU business relationships 

Systematically reviewing your own EU activities is the first important step in clarifying whether you are affected by NIS2. This involves taking a close look at various aspects of your business.

  • Do you have an EU branch?
  • Do you sell directly to the EU?
  • Is your annual turnover in the EU > EUR 10 million?
  • Do you have > 50 employees in the EU?
  • Supplier for critical EU industries?
  • Part of an EU supply chain?
  • Participation in EU tenders?
  • Cloud services for EU customers?

→ If the answer is ‘yes’, you should have your NIS2 obligations reviewed in detail.

Swiss ISG and NIS2: Exploiting synergies 

For Swiss SMEs, the domestic Information Security Act (ISG) provides a good starting point for NIS2. Both sets of regulations require reporting obligations for cyber incidents and structured risk management. However, NIS2 goes further: it requires specific technical measures and an active role for senior management. Take advantage of the overlaps to create an integrated compliance programme – this saves resources and creates clarity.

Your roadmap for NIS2 implementation: How to proceed systematically 

Particular attention should be paid to establishing robust risk management and effective incident response. Documenting the measures taken and providing regular staff training are also key success factors.

The second step focuses on technical and organisational measures. The key here is to establish robust security incident management: implement clear processes for 24-hour reporting of security incidents. Establish systematic risk management that takes into account the specific NIS2 requirements. Don't forget the supply chain: your suppliers must also be involved.

The third step concerns the governance structure. NIS2 requires management to play an active role – from approving security measures to regularly reviewing their effectiveness. Define clear responsibilities and escalation paths. It is particularly important to document all decisions and measures in full.

Finally, you need to get your employees on board. Regular training is not only a NIS2 requirement, but also the key to success. Develop an awareness programme that clearly communicates the new requirements and anchors them in everyday work.

SET THE COURSE FOR NIS2 COMPLIANCE NOW 

The NIS2 Directive presents Swiss SMEs with new challenges – but also offers opportunities. Those who take a systematic approach now will not only be able to implement the requirements efficiently, but also raise their cybersecurity to a new level. MTF Solutions supports you with a proven three-step process:

  • NIS2 QuickCheck: In an initial consultation, we analyse your specific situation. Are you directly or indirectly affected by NIS2? Which requirements are relevant to you? Where do you stand today?
  • Gap analysis and roadmap: Our experts systematically identify the gaps between the current and target situations. You receive a tailor-made roadmap with concrete recommendations for action, priorities and time frames.
  • Implementation support: On request, we can assist you with the actual implementation – from technical implementation and process design to employee training.
     

NIS2: Time to act – also for Swiss SMEs

The EU NIS2 Directive affects more Swiss companies than is apparent at first glance. Not only SMEs with direct EU activities need to take action; suppliers and business partners of EU companies are also increasingly required to meet the stricter cybersecurity standards. It is clear that NIS2 is more than just a regulatory obligation. The directive offers the opportunity to systematically raise your own IT security to a new level and thus gain a competitive advantage.

The most important findings at a glance:

  • The impact extends far beyond the formal scope of application.
  • Swiss SMEs in EU supply chains must prepare themselves.
  • Implementation requires a systematic approach.
  • Synergies with the Swiss ISG can be exploited.
  • Early action brings advantages.
     

Take the first step towards NIS2 compliance

Let us analyse your NIS2 impact together. Our experts will support you with practical experience and proven solutions – from the initial analysis to successful implementation. Arrange a free initial consultation now!

FAQs 

  1. As a purely Swiss SME with no EU branch, do we fall under NIS2?
    Formally, not directly. But as soon as you are a supplier or partner of an EU company that itself falls under NIS2, you are indirectly affected. Many EU customers already require proof of IT security from Swiss SMEs.
     
  2. Which Swiss industries are particularly affected by NIS2?
    SMEs working with critical EU sectors are particularly affected: energy, transport, health, IT services, mechanical engineering, automotive suppliers and cloud services. Swiss companies without a direct EU presence may also fall within the scope of the directive via the supply chain.
     
  3. What criteria determine whether my Swiss SME is directly affected by NIS2?
    The directive applies to companies with 50 or more employees or an annual turnover of more than EUR 10 million in the EU – provided that they operate in or provide services to one of the 18 critical sectors.
     
  4. What does ‘indirectly affected’ mean for Swiss SMEs?
    Many Swiss SMEs supply EU companies. These companies must prove that their entire supply chain is secure – and pass on the NIS2 requirements to their partners. This creates a de facto obligation, even without direct regulation.
     
  5. What penalties do Swiss SMEs face in serious cases?
    If your SME operates directly in the EU, penalties of up to EUR 10 million or 2% of global annual turnover may be imposed. Managers are also personally liable. Indirectly affected SMEs risk losing orders if they do not meet NIS2 requirements.
     
  6. What responsibility does the management of Swiss SMEs have?
    Company management must approve security measures, monitor them, report incidents and regularly participate in cybersecurity training. NIS2 therefore requires active engagement – including from Swiss executives with EU business. In the event of breaches of due diligence, they are personally liable – up to and including fines or temporary removal from office.
     
  7. Isn't the Swiss ISG (Information Security Act) sufficient?
    The ISG provides a good basis, as it also stipulates reporting obligations and risk management. However, NIS2 goes further: it requires more detailed technical measures, greater involvement of senior management and takes the entire supply chain into account.
     
  8. How should Swiss SMEs get started with NIS2 – and what opportunities does it offer?
    First, carry out a quick check of your EU relationships: do you have customers, branches or supply chains in the EU? Next, we recommend a gap analysis with clear action steps – from risk management to employee training. Working in compliance with NIS2 increases your cyber resilience, signals reliability to EU partners and improves your chances in EU tenders.

Do you have Questions ?

Ümit Celebi
Key Account Manager