You may have received an email from a German or French client. It mentions NIS2, asks you to fill in a questionnaire, announces an amendment to the contract. Or perhaps you read an alarmist article and are wondering whether your company has been in breach for months.
Let’s start with the answer, because it is simple and rarely given clearly: NIS2 does not apply directly to your Swiss SME. This does not mean it will leave you alone.
What is NIS2, in three sentences?
NIS2 is the common name for directive (EU) 2022/2555. It aims to raise the level of cybersecurity in the European Union by imposing obligations on certain organisations considered critical to the economy and society.
These organisations are divided into two categories: “essential” entities and “important” entities. The classification depends on two combined factors, the sector of activity and the size of the company. The text relies for this on the European definition of medium-sized companies, with exceptions allowing smaller structures to be included when they play a key role for a given sector.
The entities concerned must put in place risk management measures, notify their incidents to the national authority, and hold their management accountable on these matters. The lists of sectors, the precise thresholds and the sanctions appear in the text itself and in each national transposition law. We do not reproduce them here: they vary from one country to another, and that is not what concerns you.
Why isn’t Switzerland directly concerned?
The legal point rests on a distinction that many articles skip over.
A European directive is not a text directly applicable to companies. It is addressed to the member states of the Union. Each must then transpose it, meaning adopt or amend its own national law to achieve the result set. It is this national law that creates concrete obligations, in Germany, in France, in Italy.
Switzerland is not a member of the European Union. No transposition obligation applies to it, and NIS2 has not been transposed into Swiss law. There is therefore no Swiss authority tasked with enforcing it, no Swiss sanction based on it, no register for you to register with.
"NIS2 does not apply to you" does not mean "NIS2 does not concern you". The text obliges you to nothing. Your European clients, however, can oblige you to a great deal. And a signed contractual commitment is just as binding as a law, with faster consequences: loss of the contract, penalties, non-renewal.
The real mechanism: the supply chain
Here is how a directive that does not target you ends up on your desk.
NIS2 requires the entities concerned to secure their supply chain. The text asks them to assess the quality and resilience of the products and services they purchase, the security measures built into them, and the cybersecurity practices of their suppliers and service providers. It explicitly encourages them to include security requirements in their contracts with their direct suppliers.
You are that direct supplier. If you machine parts for a Bavarian equipment manufacturer, if you develop software for a French operator, if you manage the IT maintenance of an industrial site in Alsace, your client must be able to demonstrate that they have assessed your security.
They cannot impose German or French law on you. They can, however, impose a contract on you. That is exactly what happens, and it takes four usual forms: a security questionnaire to fill in, clauses added to the contract, a right of audit or visit, and a commitment to report any incident affecting you without delay.
This mechanism is nothing theoretical. It stems from the fact that attackers increasingly target the most accessible link in a business relationship, as explained in supply chain attacks.
| What does not apply to your Swiss SME | What actually applies to you |
|---|---|
| NIS2’s legal obligations as such | The security clauses you sign in a contract |
| Classification as an “essential” or “important” entity | The supplier questionnaires from your European clients |
| The sanctions set out in national transposition laws | Losing a contract if you fail to answer credibly |
| Incident notification to European authorities | Incident notification to your client, if the contract requires it |
| The Swiss ISA’s reporting obligation (critical infrastructure) | Your actual Swiss obligations, notably your obligations under the FADP |
Do not confuse NIS2 with the Swiss ISA
The confusion is common, and it is fuelled by the fact that both texts deal with cybersecurity and incident reporting.
The Swiss Information Security Act (ISA) has imposed, since 1 April 2025, an obligation to report cyberattacks for operators of Swiss critical infrastructure. The sanctions linked to this failure have applied since 1 October 2025. This concerns energy, water, transport, health, administrations, telecommunications.
This Swiss obligation does not concern ordinary SMEs. If you are an eight-person trust company, an architecture firm, a garage or a mechanical workshop, you are not a critical infrastructure operator and this reporting obligation does not target you.
What remains true, however, is that you can voluntarily report an incident to the National Cyber Security Centre. Many do: the NCSC received 64,733 voluntary reports in 2025, against 62,954 in 2024 (NCSC, half-yearly report 2025/II, 30 March 2026). The details of which texts apply depending on your activity are covered in our article on obligations by sector.
What should you do when a European client sends you a questionnaire?
This is the concrete situation. Here is the approach that works best.
1. Do not treat it as an administrative formality. This document is used to decide whether you remain a supplier. It deserves the same care as a commercial proposal.
2. Read it fully before answering. Identify what is required as mandatory, what is desired, and what will become a contractual clause. The three do not carry the same weight.
3. Never lie. A false answer discovered after an incident turns into a contractual breach, sometimes into deception. Answering “no, but here is our plan and our deadline” is almost always received better than an unverifiable “yes”.
4. Negotiate what is disproportionate. An on-site audit right at a three-person provider, a two-hour incident notification available around the clock, a heavy certification for a modest contract: these requirements can be discussed. Propose an equivalent alternative rather than a flat refusal.
5. Capitalise on it. Gather your answers in a reusable file: security policy, technical measures, incident procedure, list of your subcontractors and their hosting countries, contact details for a security contact. The second questionnaire will then take an hour instead of three days. We detail the approach, the wording that works and the pitfalls to avoid in our article on responding to a client security questionnaire.
The questions asked by European procurement teams are very similar: two-factor authentication, tested backups, access management, patching, an incident response plan, staff awareness. These are the basic measures. Putting them in place before you are asked turns an imposed exercise into a commercial argument. The cyber check-up covers the essentials of these points in a few minutes.
What this changes for your roadmap
The risk, with a topic like NIS2, is to swing into one of two extremes. Panicking and seeking a compliance that does not exist for you. Or shrugging it off because “it does not apply”, and getting dropped from a tender six months later.
The reasonable position lies in between. You have no NIS2 compliance to obtain. You have a level of security to reach and to know how to demonstrate, because your clients will increasingly ask for it, and because it protects you first and foremost.
One signal deserves to be noted along the way: 42% of Swiss SMEs consider their protection sufficient, against 55% a year earlier (SME Cybersecurity 2025 study). Confidence is declining. That is rather healthy, provided the clear-sightedness turns into measures.
Two developments deserve your attention going forward. The European Cyber Resilience Act, which will affect manufacturers of products with digital elements exported to the Union, is covered separately in our article on the CRA. And your actual Swiss obligations are grouped in the Regulations pillar.
One last word of caution. This article explains a general mechanism and does not constitute legal advice. If a European contract commits you to security requirements, or if your group has an entity in a member state, have the situation reviewed by a qualified lawyer in the country concerned before signing.