NIS2 for Swiss subsidiaries: when the EU directive lands in Switzerland

The EU NIS2 directive (transposition deadline was 17 Oct 2024, implemented nationally by member states) does not apply directly in Switzerland. It bites through two channels: first, EU subsidiaries of Swiss groups fall directly under national NIS2 implementations. Second, Swiss providers of essential services to regulated EU customers inherit obligations contractually. A SOC is the operational building block for detection, notification and evidence in both cases.

All

How this compares to neighbouring topics

This page frames NIS2 from a Swiss angle. For the domestic reporting duty, see SOC & ISG 24h reporting. For financial institutions, see SOC & FINMA requirements. For data protection, see revFADP and SOC. For operations, see SOC as a Service Switzerland.

Which parts of a Swiss group are in scope?

  • EU subsidiaries of Swiss parents fall within scope in the following sectors. These include energy, transport, banking, financial markets, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. They also include post, waste, chemicals, food, manufacturing, digital providers and research.
  • Essential entities (large enterprises, from 250 employees or EUR 50 million turnover) and important entities (medium enterprises). Micro-enterprises are broadly exempt, unless captured by a sector-specific rule.
  • Representative obligations and sector classifications can bring Swiss entities without an EU registered office into scope if they provide services in the EU.
  • Contractual reach-through: Swiss suppliers of critical services to EU-regulated customers inherit NIS2 obligations via contracts and audit rights.
Important

NIS2 is a directive, not a regulation. The national transposition in the member state where the subsidiary or customer is based determines the applicable requirements. Deadlines, fine ranges and sector boundaries can diverge.

What NIS2 requires operationally

  • Ten minimum risk-management measures cover risk analysis, incident handling, business continuity, supply chain and secure operations. They also cover effectiveness testing, cryptography, HR security, access and asset management, MFA and communications.
  • The notification process requires an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. Notifications go to the competent national authority and, where applicable, recipients.
  • Personal responsibility of management with a documented training obligation.
  • Supply-chain obligations: critical suppliers must be in scope of detection and response and be contractually bound.
  • Essential entities face fines up to EUR 10 million or 2 per cent of worldwide annual turnover. Important entities face fines up to EUR 7 million or 1.4 per cent of worldwide annual turnover.

What the SOC concretely delivers in the NIS2 context

  • 24/7 detection provides the operational basis for the 24-hour early warning. Continuous detection and assessment ensure that discovery, assessment and reporting follow each other closely.
  • Playbooks with an explicit NIS2 notification threshold and templates for the early warning, 72-hour notification and final report.
  • Ticket and evidence trail with timestamps to evidence discovery, response and impact.
  • Supplier lens: detection and reporting extend to critical suppliers and their access, in step with contractual duties.
  • Reporting to executive management and the board with MTTD, MTTR, notifications and training records to support personal accountability.
Bottom line

Whether NIS2 applies directly or through contract, the operational demands on detection and reporting are practically identical. A single, unified SOC is therefore the cheapest way to serve several regimes at once.

Practice: what to do first

  1. Scope assessment per EU subsidiary: which member state, which sector, which size class.
  2. Reverse supplier analysis: which parts of the Swiss group supply critically to EU-regulated customers.
  3. Gap assessment against the ten NIS2 minimum measures, consolidated across the group rather than duplicated country by country.
  4. Align detection and reporting with the 24/72/30 timeline. Put templates and escalation chains in writing.
  5. Training and reporting plan for executive management and the board, documented and repeatable.

For the economics, see SOC cost Switzerland. For the 24/7 rationale, see SOC 24/7 operations. On the make-or-buy question, see Managed SOC vs. in-house.

Legal basis and sources

Frequently asked questions

Does the Swiss parent have to implement NIS2 directly?

NIS2 as such does not apply in Switzerland. Every EU subsidiary falls under the national transposition of the country where it has its registered office. The group retains consolidated responsibility for governance and evidence.

How is this different from ISG in Switzerland?

ISG governs reporting for operators of critical infrastructure in Switzerland with a 24-hour deadline to the National Cyber Security Centre (NCSC). NIS2 governs risk management and reporting across the EU, with deadlines of 24 hours, 72 hours and one month. A single incident can trigger both regimes.

Does DORA already count as NIS2?

DORA is the sector-specific lex specialis for the EU financial sector and largely takes precedence over NIS2. Non-financial subsidiaries remain under NIS2. See [DORA requirements for the SOC](/en/soc/dora-soc-requirements).

Do Swiss groups need an EU representative under NIS2?

Certain digital providers without an EU registered office need an EU representative. In most cases the obligation runs through the EU subsidiary itself. Providers without an EU subsidiary may need to appoint a representative if they offer the service in the EU.

Can we combine NIS2 and ISG reporting processes?

You can combine the processes if you handle the deadlines and recipients separately. In practice a SOC uses the same playbook with different recipients, templates and deadline calculations.

Continue reading in this cluster
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
How a 24/7 SOC works in practice
A 24/7 SOC runs in overlapping analyst shifts with clear tiers, playbooks and an escalation matrix up to executive level. Alerts flow from EDR, identity, cloud and network into a central SIEM or XDR. They are triaged on L1, investigated on L2/L3 and never parked outside the customer tenant. Targets for critical cases: MTTR up to 60 minutes, MTTC between 1 and 4 hours.
SOC and cyber insurance: what Swiss insurers require
Cyber insurers in Switzerland and the EU increasingly require applicants to evidence security controls. MFA, EDR, segregated backups, a documented incident response plan and a patch process appear on nearly every proposal form. Missing 24/7 detection via a managed SOC or MDR is rarely a formal exclusion. It is a strong premium driver and, in many policies, the only realistic way to meet short policy notification deadlines.