Compliance

NIS2

NIS2 is a European Union directive setting minimum cybersecurity requirements for important and essential entities.

NIS2 is an EU directive that sets minimum cybersecurity requirements for essential and important entities. Member states had to transpose it into national law by October 2024, and it significantly expands the previous NIS directive.

How it works

NIS2 affects organisations in 18 sectors. These include energy, transport, health, digital infrastructure, and parts of the manufacturing industry. Typically, medium and large companies are affected.

They must conduct risk management, handle incidents, secure supply chains, and train employees. Significant incidents must be reported with an early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report after one month. Management must approve the measures, monitor their implementation and can be held liable for violations.

For example, a Swiss engineering company has a subsidiary in Germany. This subsidiary is classified as an important entity under the directive. Germany's national implementation rules for NIS2 apply to this subsidiary. The parent company must prove that incidents can be detected and reported on time. Without round-the-clock monitoring, meeting the 24-hour deadline is very difficult.

What to look out for

  • Clarify if any of your subsidiaries in the EU are subject to NIS2.
  • Check if EU customers require you to meet NIS2 standards as a supplier.
  • Establish a reporting process that works at night and at weekends.
  • Document your risk management and security measures in an auditable way.

Switzerland and regulation

NIS2 does not apply directly in Switzerland. Swiss companies are affected if they operate in the EU or supply EU entities. In Switzerland, the reporting obligation under the Information Security Act (ISG) has applied to operators of critical infrastructure since April 2025. The reporting deadline under the ISG is also 24 hours.

Typical mistakes

Many Swiss companies assume that NIS2 does not affect them. The requirements can then appear through contracts with EU customers. Another mistake is having a reporting process that only works during office hours.

How we implement it

Our SOC detects incidents around the clock and provides the information for timely reporting. The formal notification to the authorities remains your responsibility, while we prepare the evidence.

How ANOMAL implements this