NIS2 is the nickname for European directive 2022/2555, a text designed to raise the level of cybersecurity across the European Union. Since a European directive is an act that each member state must transpose into its own legislation, NIS2 does not apply directly in Switzerland. Many executives conclude, a little too quickly, that it does not concern them. That is a mistake that could prove costly, and here is why.
Two ways of being affected
The first is direct. A Swiss company falls under NIS2 if it operates a branch in the EU or provides services there, in one of the eighteen sectors the directive considers critical (energy, health, transport, digital infrastructure, and so on). Size thresholds come into play, typically annual turnover above 10 million euros generated in the EU or more than 50 employees. This route therefore only affects a minority of SMEs.
The second way is indirect, and it is the one that will affect the largest number. NIS2 requires large European companies to guarantee the cybersecurity of their entire supply chain, meaning all the suppliers and service providers that contribute to their business. As a result, these major clients pass their requirements on to their partners, including Swiss ones. A mechanical engineering subcontractor, an automotive supplier, or a Swiss IT service provider working for a European client can be asked for stronger guarantees without being directly subject to the text itself.
What these requirements demand
In practice, a European client subject to NIS2 will expect its suppliers to demonstrate genuine cybersecurity maturity. This means structured risk management, documentation of security measures, regular audits, and sometimes penetration tests (simulated attacks designed to check how solid the defences are). On top of this comes the ability to report an incident quickly, since the directive requires affected entities to send an initial notification within 24 hours.
These demands will not arrive in the form of a fine from Brussels. They will come through a far more mundane channel: a contractual clause, a security questionnaire to fill in before renewing a contract, or an entry condition in a call for tenders. For an SME, being unable to answer it simply means losing a market.
A sanctions regime that sets the tone
To gauge how seriously major clients will enforce these requirements, look at what they themselves risk. The directive provides for fines of up to 10 million euros or 2% of worldwide annual turnover. Notably, NIS2 also introduces personal liability for management in cases of proven negligence. A European executive who knows their own liability is at stake will show no leniency towards a weak link in their supplier chain.
Putting it in perspective for a Swiss SME
It would be tempting to see NIS2 as a constraint purely imposed from outside. It is also, and perhaps above all, an opportunity. An SME able to demonstrate a good level of cybersecurity gains a competitive advantage: it reassures its European clients, sets itself apart from less-prepared competitors, and secures its own markets.
Note that Switzerland already has its own framework, notably the Information Security Act, which shares certain principles with NIS2, such as incident reporting and risk management. The efforts you make are therefore not wasted, they count on both fronts. You can start documenting your measures and structuring your processes today. But assessing precisely what your European clients will expect of you, and closing the gap with your current situation, requires knowing both the text and your own organisation. No generic template can answer the question for you: “am I affected, and to what extent?”
In conclusion
NIS2 illustrates a trend that is set to spread: cybersecurity is becoming a condition of market access, and it travels step by step down supply chains. National borders make no difference to this. Anticipating this requirement rather than enduring it is a strategic choice within your reach. To determine your real exposure and build a credible response for your clients, a targeted assessment of your situation remains the most worthwhile investment.