---
titel: "IT and information security for energy utilities · SACOSI"
url: https://sacosi.ch/en/industries/energy
seite: /en/industries/energy
stand: 2026-09-24
beschreibung: "IT strategy for energy companies in Switzerland and the EU: ICT minimum standard under StromVV, reporting obligation under ISG and NIS2, documented for audit."
---

> Knowledge version of the page https://sacosi.ch/en/industries/energy. It contains the full text, including what is shortened or collapsible on the page itself. Publisher: SACOSI, Situational Awareness Consulting by Ivo Schönberner, Zürich.

# IT in energy supply.

**Short answer:** In energy supply, IT is part of critical infrastructure. In Switzerland, the ICT minimum standard under the Electricity Supply Ordinance (StromVV) has been mandatory since 1 July 2024, and cyberattacks must be reported to BACS within 24 hours since 1 April 2025. Companies with a branch or customers in the EU must also assess NIS2. I map these obligations to the company's situation and build the evidence so that ElCom, auditors and investors can review it.

## Why is IT critical in energy supply?

- Security of supply depends on control systems and networks that must not fail.
- Operational technology (OT) and office IT are converging, under different rules.
- Growth in renewables, storage and new market roles brings new obligations.

## Which rules typically need to be checked?

Whether a given rule applies in an individual case depends on size, markets, customers and products. The situation picture clarifies this.

### [ICT minimum standard under StromVV](https://sacosi.ch/en/regulation#stromvv)

**Switzerland:** Mandatory since 1 July 2024. **EU:** Does not apply.

### [Reporting obligation for cyberattacks (ISG)](https://sacosi.ch/en/regulation#isg)

**Switzerland:** Applies since 1 April 2025 to operators of critical infrastructure. **EU:** Does not apply.

### [NIS2 Directive](https://sacosi.ch/en/regulation#nis2)

**Switzerland:** Not directly. Indirectly via EU subsidiaries, EU customers in the supply chain and for certain digital services. **EU:** Transposed into national law, in Germany since 6 December 2025.

### [ISO/IEC 27001](https://sacosi.ch/en/regulation#iso27001)

**Switzerland:** Voluntary, often required contractually. **EU:** Voluntary, often required contractually.

### [Swiss Federal Act on Data Protection (FADP)](https://sacosi.ch/en/regulation#revdsg)

**Switzerland:** Applies since 1 September 2023. **EU:** Does not apply directly.

## How can I help?

### [Situation picture for investments](https://sacosi.ch/en/investors)

IT due diligence before the investment, or the situation picture in the first weeks afterwards: risks, costs, dependencies and obligations of the investment on a single page, with measures ranked by impact and effort.

### [Fractional CTO for a defined period](https://sacosi.ch/en/fractional-cto)

Technical leadership for a defined period: architecture, team, security, due-diligence readiness. The goal is a handover to a permanent CTO or the company's own team.

### [Compliance roadmap](https://sacosi.ch/en/regulation)

Which standards and laws apply to your business, in what order to address them, and how the evidence is built up in an auditable system, for example for ISO 27001, ISO 9001 or TISAX.

### [Scaling architecture](https://sacosi.ch/en/it-architecture)

A target architecture without legacy baggage that supports the planned growth: identity, workplace, cloud, local AI, costs in proportion to budget.

Back to the [industry overview](https://sacosi.ch/en/industries) or the [overview of all rules](https://sacosi.ch/en/regulation).

## What is the situation in your company?

Thirty minutes, no presentation. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile.

CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English
