Skip to content
NIS2Supply ChainEU RegulationSuppliers

What NIS2 Now Demands from Swiss Suppliers

2 October 2026|8 min read

Since 1 October 2026, NIS2 also applies in Austria, and in Germany since December 2025. Swiss companies are not directly affected, but their EU customers are. Those customers pass the obligations on to their suppliers through contracts and questionnaires.

On 1 October 2026, Austria's NISG 2026 entered into force, the national transposition of the EU's NIS2 Directive. Since that day, the entities it covers must meet its requirements, and they must register with the authority by the end of the year. In Germany, the implementing act has applied since 6 December 2025.

As an EU directive, NIS2 does not apply in Switzerland. It still reaches Swiss SMEs, through their customers. According to the Federal Department of Foreign Affairs (FDFA), Germany is Switzerland's most important trading partner, with trade above 100 billion francs every year since 2021. Anyone supplying customers in Germany or Austria should therefore expect a security questionnaire or a contract addendum. If you have your evidence ready, you can answer quickly. If you first have to gather it, you lose time and in the worst case the order.

Why an EU Law Reaches Swiss SMEs

Article 21 of the directive requires the entities it covers to ensure supply chain security, including their relationships with direct suppliers and service providers. In doing so, they must take into account the vulnerabilities specific to each supplier and its cybersecurity practices. In Germany this duty sits in Section 30 of the BSIG, in Austria in Section 32 of the NISG 2026. In its FAQ, Germany's Federal Office for Information Security (BSI) states explicitly that through business relationships the provisions of the BSIG can indirectly affect companies that are not covered by NIS2 themselves.

The management bodies of covered entities must approve the measures, oversee their implementation and can be held liable for infringements. For essential entities, the directive requires maximum fines of at least 10 million euros or 2 percent of worldwide annual turnover, whichever is higher. With a supplier in Switzerland, the customer can only enforce its requirements through the contract. That is why they arrive as a clause and a questionnaire.

The group of covered companies is large. NIS2 applies to medium-sized and large companies in the sectors listed in Annexes I and II, including manufacturers of medical devices, electronics, electrical equipment, machinery and vehicles. According to the BSI, the number of supervised entities in Germany grows from about 4,500 to around 29,500. In its semi-annual report 2025/2, the BACS (Federal Office for Cybersecurity) notes that cyberattacks travel along digital dependencies and cross organisational, sector and national borders.

What the Questionnaires and Contracts Contain

The questions derive from the customer's own obligations. Article 21(2) lists ten measures, including risk analysis, incident handling, backups and disaster recovery, vulnerability handling, training, encryption, access control and multi-factor authentication. According to the BSI, the explanatory notes to the German act give contractual agreements with suppliers on risk management, incident handling and patch management as an example.

The Austrian Economic Chambers (WKO) list what such contracts should contain. This includes security requirements for the supplier, requirements for the awareness, qualification and training of its staff, background checks, prompt notification of security incidents, a right to audit or to receive audit reports, an obligation to remediate vulnerabilities, rules for subcontracting and obligations at the end of the contract.

The notification duty follows from your customer's own deadlines. Your customer must submit an early warning within 24 hours of a significant incident and a full notification within 72 hours. If the incident starts with you, the customer needs to hear about it much earlier.

NIS2 does not require suppliers to hold a certificate. The directive only requires relevant European and international standards to be taken into account. According to the WKO, whether an ISO 27001 certificate is sufficient evidence depends on the risk assessment in each individual case.

Who Gets Asked First

Not every supplier is affected. The WKO writes that not all suppliers are covered as a matter of principle, but that limiting the scope to IT service providers would be too narrow. All participants in the supply chain that relate to the network and information systems supporting the entity's services must be included. As an example, the WKO names the air conditioning for the server room.

How closely a customer checks follows from its risk assessment, because Article 21 requires appropriate and proportionate measures. A supplier that accesses the customer's systems through remote maintenance, VPN or an administrator account, or that processes confidential data such as design drawings, poses a higher risk than one that only delivers goods. A machine builder in the Rhine Valley that maintains its customers' equipment remotely should therefore expect detailed questions, such as who connects when, whether multi-factor authentication applies and whether access is logged.

Swiss providers offering cloud, data centre or managed services in the EU are a special case. They can fall under NIS2 themselves even without an establishment in the EU, and must then designate a representative in the EU under Article 26. A subsidiary in Germany or Austria is assessed under local law in any case.

What You Already Have from the nDSG and ISG

Few SMEs start from zero. Article 8 of the nDSG requires data security appropriate to the risk, through suitable technical and organisational measures. Article 3 of the Data Protection Ordinance specifies this, among other things with access control, rapid recovery after an incident and software kept at the latest security level.

Operators of critical infrastructure have been reporting cyberattacks to the BACS within 24 hours under the ISG since 1 April 2025 and know how a report works. The federal ICT Minimum Standard is mandatory for electricity and gas suppliers and recommended for all other organisations. It is based on the NIST Cybersecurity Framework, which also covers incident response and recovery.

The gaps lie elsewhere. In the study "KMU Cybersicherheit 2025" by FHNW and HES-SO Valais-Wallis, only 30 percent of the SMEs surveyed have an emergency plan or a business continuity concept. Regular staff training takes place in 31 percent of the companies, and 20 percent carry out a security audit. NIS2 explicitly requires all of these. Article 21 calls for business continuity and crisis management, training, and procedures to assess whether the measures are effective. A penetration test is one way to demonstrate that effectiveness.

How to Answer the Questionnaire

Treat the questionnaire like a contractual declaration. The supervisory authority can ask your customer for documented policies and evidence of implementation, and your answers are part of that evidence. If the customer has agreed a right to audit, it can check every statement. So do not answer any question from memory, and file evidence for every answer, such as a policy, a screenshot of the configuration or a test report. An honest "partially" with a remediation plan and a date will hold up in an audit. A flattering yes will not.

Turn the first questionnaire into an evidence package you can reuse. It should contain a security policy, the remote access concept, the log of the last restore test, the summary of the last penetration test, a list of your subcontractors and a contact point for security incidents. Because all customers must cover the same measures from Article 21, the questions repeat.

Finally, read the contract clauses carefully. The WKO list provides for prompt notification of security incidents and a right to audit. Clauses that go further, such as notification on mere suspicion, audits at your expense or unlimited liability, should be reviewed by a lawyer. Only commit technically to what you can actually deliver.

How MilesGuard Helps

MilesGuard prepares Swiss suppliers for NIS2 requests from their EU customers. We assess your position against the ten measures in Article 21, prioritise the gaps and put together the evidence package you can reuse with every customer. Where remote maintenance or customer data are involved, a penetration test provides solid evidence of effectiveness. If such requests arrive regularly, we handle them as part of CISO as a Service. The first questionnaire takes effort. Every one after that is quick once the evidence is ready.

Share:LinkedIn

More Posts

Related Services