{"id":"en/ch_ki_regulierung#kurzantwort","norm":"ch_ki_regulierung","norm_name":"Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"Switzerland does not yet have an AI-specific act. On 12 February 2025, the Federal Council discussed a stocktaking report on possible regulatory approaches to artificial intelligence and instructed the Federal Office of Justice (FOJ) to draft a consultation bill by the end of 2026, implementing in particular the Council of Europe's Framework Convention on Artificial Intelligence. Until this process is concluded, there is no horizontal, AI-specific legal obligation in Switzerland; existing obligations, for instance under the FADP, already apply today regardless.","quellen":[{"titel":"Künstliche Intelligenz - Regulierung","url":"https://www.bk.admin.ch/de/regulierung","herausgeber":"Bundeskanzlei (BK) / Bundesamt für Justiz (BJ)","abgerufen":"2026-09-24"},{"titel":"Künstliche Intelligenz","url":"https://www.bk.admin.ch/de/ki","herausgeber":"Bundeskanzlei (BK)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ch_ki_regulierung","sprache":"en"}
{"id":"en/ch_ki_regulierung#wann_gilt","norm":"ch_ki_regulierung","norm_name":"Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence)","abschnitt":"wann_gilt","ueberschrift":"When does CH AI Regulation apply to you?","text":"- Activity: Using AI (Recommend individual review): You use AI systems - a horizontal Swiss AI obligation does not yet exist today (as of 24.9.2026), but the consultation bill planned for the end of 2026 could bring transparency, data protection and oversight requirements for you in future. Nothing is currently binding; monitor the development.\n- Activity: AI provider (own AI products) (Recommend individual review): You provide AI systems - the same recommendation to monitor developments applies to you as a provider. According to the Federal Council, the planned regulation is to combine legally binding measures with voluntary elements such as industry solutions and self-commitments; their specific content has not yet been determined.\n- Activity: Public-sector clients (Recommend individual review): You supply public-sector clients - internal requirements for the use of AI within the federal administration itself already exist outside this consultation bill; whether and how these have knock-on effects on you as a supplier needs to be checked case by case.","quellen":[{"titel":"Künstliche Intelligenz - Regulierung","url":"https://www.bk.admin.ch/de/regulierung","herausgeber":"Bundeskanzlei (BK) / Bundesamt für Justiz (BJ)","abgerufen":"2026-09-24"},{"titel":"Künstliche Intelligenz","url":"https://www.bk.admin.ch/de/ki","herausgeber":"Bundeskanzlei (BK)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ch_ki_regulierung","sprache":"en"}
{"id":"en/ch_ki_regulierung#ausnahmen","norm":"ch_ki_regulierung","norm_name":"Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- There is currently (as of 24.9.2026) no Swiss AI act and no AI ordinance; the regulation described here is a consultation bill still under preparation, with no legal force.\n- Sector-specific rules - for instance the FADP for automated individual decisions and profiling, or medical device law for AI in medical devices - remain unaffected by this process and already apply today regardless.","quellen":[{"titel":"Künstliche Intelligenz - Regulierung","url":"https://www.bk.admin.ch/de/regulierung","herausgeber":"Bundeskanzlei (BK) / Bundesamt für Justiz (BJ)","abgerufen":"2026-09-24"},{"titel":"Künstliche Intelligenz","url":"https://www.bk.admin.ch/de/ki","herausgeber":"Bundeskanzlei (BK)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ch_ki_regulierung","sprache":"en"}
{"id":"en/ch_ki_regulierung#pflichten","norm":"ch_ki_regulierung","norm_name":"Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- No statutory obligations arise from this bill as long as it has not been passed and brought into force.\n- Voluntarily possible: monitoring the consultation process and participating in industry solutions or self-commitment declarations, which the Federal Council is providing for alongside the legally binding bill.","quellen":[{"titel":"Künstliche Intelligenz - Regulierung","url":"https://www.bk.admin.ch/de/regulierung","herausgeber":"Bundeskanzlei (BK) / Bundesamt für Justiz (BJ)","abgerufen":"2026-09-24"},{"titel":"Künstliche Intelligenz","url":"https://www.bk.admin.ch/de/ki","herausgeber":"Bundeskanzlei (BK)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ch_ki_regulierung","sprache":"en"}
{"id":"en/ch_ki_regulierung#nachweise","norm":"ch_ki_regulierung","norm_name":"Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Not applicable, as long as no applicable law exists.","quellen":[{"titel":"Künstliche Intelligenz - Regulierung","url":"https://www.bk.admin.ch/de/regulierung","herausgeber":"Bundeskanzlei (BK) / Bundesamt für Justiz (BJ)","abgerufen":"2026-09-24"},{"titel":"Künstliche Intelligenz","url":"https://www.bk.admin.ch/de/ki","herausgeber":"Bundeskanzlei (BK)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ch_ki_regulierung","sprache":"en"}
{"id":"en/ch_ki_regulierung#fristen","norm":"ch_ki_regulierung","norm_name":"Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 12 February 2025: The Federal Council discusses a stocktaking report on possible AI regulatory approaches and instructs several offices, including the Federal Office of Justice, to develop regulatory measures.\n- 31 December 2026: Target date: by this point, the Federal Office of Justice is to submit a consultation bill for legally binding measures as well as an implementation plan for non-binding measures. This is a milestone for the bill, not the entry-into-force date of an act.","quellen":[{"titel":"Künstliche Intelligenz - Regulierung","url":"https://www.bk.admin.ch/de/regulierung","herausgeber":"Bundeskanzlei (BK) / Bundesamt für Justiz (BJ)","abgerufen":"2026-09-24"},{"titel":"Künstliche Intelligenz","url":"https://www.bk.admin.ch/de/ki","herausgeber":"Bundeskanzlei (BK)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ch_ki_regulierung","sprache":"en"}
{"id":"en/ch_ki_regulierung#sanktionen","norm":"ch_ki_regulierung","norm_name":"Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"None. No applicable act yet exists from which penalties could be derived.","quellen":[{"titel":"Künstliche Intelligenz - Regulierung","url":"https://www.bk.admin.ch/de/regulierung","herausgeber":"Bundeskanzlei (BK) / Bundesamt für Justiz (BJ)","abgerufen":"2026-09-24"},{"titel":"Künstliche Intelligenz","url":"https://www.bk.admin.ch/de/ki","herausgeber":"Bundeskanzlei (BK)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ch_ki_regulierung","sprache":"en"}
{"id":"en/ch_ki_regulierung#fragen","norm":"ch_ki_regulierung","norm_name":"Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Do I already have to comply with a Swiss AI regulation today?**\nNo. No AI-specific Swiss act exists yet. On 12 February 2025, the Federal Council merely issued the mandate to develop a consultation bill by the end of 2026 - that is an early stage of lawmaking, not a current obligation.\n\n**What is the planned bill based on?**\nOn implementing the Council of Europe's Framework Convention on Artificial Intelligence: the consultation bill is to set out the legal measures needed in the areas of transparency, data protection, non-discrimination and oversight, combined with non-binding measures such as industry solutions or self-commitment declarations.\n\n**Which office is responsible?**\nThe Federal Office of Justice (FOJ) coordinates the work, together with the Federal Office of Communications (OFCOM), the Directorate of International Law and other affected federal bodies.","quellen":[{"titel":"Künstliche Intelligenz - Regulierung","url":"https://www.bk.admin.ch/de/regulierung","herausgeber":"Bundeskanzlei (BK) / Bundesamt für Justiz (BJ)","abgerufen":"2026-09-24"},{"titel":"Künstliche Intelligenz","url":"https://www.bk.admin.ch/de/ki","herausgeber":"Bundeskanzlei (BK)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ch_ki_regulierung","sprache":"en"}
{"id":"en/ch_ki_regulierung#unsicher","norm":"ch_ki_regulierung","norm_name":"Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The exact substantive content of the future consultation bill (specific obligations, scope, addressees, thresholds) has not yet been determined and could accordingly not be researched.\n- Whether and when the consultation bill will actually become applicable law, and with what entry-into-force date, is open. No such deadline was found and none was invented.\n- Whether, alongside the horizontal bill, sector-specific AI requirements with their own legal character already exist (e.g. for AI in medical devices or in the financial sector) was not examined in this research.","quellen":[{"titel":"Künstliche Intelligenz - Regulierung","url":"https://www.bk.admin.ch/de/regulierung","herausgeber":"Bundeskanzlei (BK) / Bundesamt für Justiz (BJ)","abgerufen":"2026-09-24"},{"titel":"Künstliche Intelligenz","url":"https://www.bk.admin.ch/de/ki","herausgeber":"Bundeskanzlei (BK)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ch_ki_regulierung","sprache":"en"}
{"id":"en/cra#kurzantwort","norm":"cra","norm_name":"Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"The Cyber Resilience Act (Regulation (EU) 2024/2847) sets EU-wide, uniform cybersecurity requirements for hardware and software products with digital elements across their entire life cycle. Manufacturers must report actively exploited vulnerabilities and severe security incidents in stages - the reporting obligations have applied since 11 September 2026, with the regulation's full application from 11 December 2027. For Swiss manufacturers, the CRA applies as soon as they place products with digital elements on the EU market.","quellen":[{"titel":"Cyber Resilience Act – Reporting obligations","url":"https://digital-strategy.ec.europa.eu/en/policies/cra-reporting","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"Cyber Resilience Act – Übersicht","url":"https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"Wichtigste Fragen & Antworten zum Cyber Resilience Act","url":"https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/","herausgeber":"cyber-regulierung.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/cra","sprache":"en"}
{"id":"en/cra#wann_gilt","norm":"cra","norm_name":"Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act)","abschnitt":"wann_gilt","ueberschrift":"When does CRA apply to you?","text":"- Activity: Products with software (Likely applies): You state that you manufacture or distribute products with software or digital elements - the CRA requires cybersecurity by design and by default for such products across their entire product life cycle, as soon as they are placed on the EU market.\n- Role towards customers: Manufacturer (applies if additionally: Activity: Products with software) (Recommend individual review): As a manufacturer of products with digital elements, you bear the main responsibility under the CRA for conformity assessment, reporting obligations and security updates - distributors and importers have lighter-touch obligations. For manufacturers without digital product components, the CRA does not apply.\n- Markets: EU (applies if additionally: Activity: Products with software) (Recommend individual review): The CRA is triggered by placing a product on the EU market, not by the manufacturer's registered seat - if you offer your connectable products with digital elements in the EU, the CRA can apply regardless of your registered seat in Switzerland. Without digital product components, the EU market alone does not trigger the CRA.\n- Activity: Medical devices (Recommend individual review): For medical devices, the CRA generally does not apply; instead, the more specific cybersecurity requirements of the Medical Device Regulation (MDR) apply - check case by case whether your product falls under this CRA exemption.","quellen":[{"titel":"Cyber Resilience Act – Reporting obligations","url":"https://digital-strategy.ec.europa.eu/en/policies/cra-reporting","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"Cyber Resilience Act – Übersicht","url":"https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"Wichtigste Fragen & Antworten zum Cyber Resilience Act","url":"https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/","herausgeber":"cyber-regulierung.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/cra","sprache":"en"}
{"id":"en/cra#ausnahmen","norm":"cra","norm_name":"Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Medical devices and in-vitro diagnostics already subject to Regulation (EU) 2017/745 or (EU) 2017/746.\n- Motor vehicles and vehicle parts with their own sector-specific type approval.\n- Aviation and marine equipment with their own sector-specific cybersecurity requirements.\n- Products developed exclusively for national security or military purposes.\n- Non-commercial open-source software developed and made available by volunteers without direct commercial intent - as soon as paid support or commercial integration into products sold is added, the exemption no longer applies.\n- Identical spare parts for products already placed on the market.","quellen":[{"titel":"Cyber Resilience Act – Reporting obligations","url":"https://digital-strategy.ec.europa.eu/en/policies/cra-reporting","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"Cyber Resilience Act – Übersicht","url":"https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"Wichtigste Fragen & Antworten zum Cyber Resilience Act","url":"https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/","herausgeber":"cyber-regulierung.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/cra","sprache":"en"}
{"id":"en/cra#pflichten","norm":"cra","norm_name":"Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Secure-by-design and secure-by-default: consider cybersecurity from the start of development.\n- Draw up a declaration of conformity and apply CE marking for products with digital elements.\n- Report actively exploited vulnerabilities and severe security incidents via the central reporting platform (Single Reporting Platform) to the responsible CSIRT - early warning within 24 hours, detailed notification within 72 hours, final report within 14 days of remediation measures becoming available, or within one month for severe incidents.\n- Provide free security updates for at least 5 years or the expected product usage period.\n- Clearly indicate the end of the support period to customers.","quellen":[{"titel":"Cyber Resilience Act – Reporting obligations","url":"https://digital-strategy.ec.europa.eu/en/policies/cra-reporting","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"Cyber Resilience Act – Übersicht","url":"https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"Wichtigste Fragen & Antworten zum Cyber Resilience Act","url":"https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/","herausgeber":"cyber-regulierung.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/cra","sprache":"en"}
{"id":"en/cra#nachweise","norm":"cra","norm_name":"Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Technical documentation and declaration of conformity.\n- Evidence of the vulnerability management process.\n- Reporting logs via the CRA Single Reporting Platform or to ENISA.\n- Documented update and support period.","quellen":[{"titel":"Cyber Resilience Act – Reporting obligations","url":"https://digital-strategy.ec.europa.eu/en/policies/cra-reporting","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"Cyber Resilience Act – Übersicht","url":"https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"Wichtigste Fragen & Antworten zum Cyber Resilience Act","url":"https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/","herausgeber":"cyber-regulierung.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/cra","sprache":"en"}
{"id":"en/cra#fristen","norm":"cra","norm_name":"Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 11 June 2026: Notifying authorities must have established the procedures for conformity assessment bodies.\n- 11 September 2026: Reporting obligations for manufacturers (actively exploited vulnerabilities, severe incidents) become applicable.\n- 11 December 2027: The Cyber Resilience Act applies in full, including conformity assessment obligations for all affected products.","quellen":[{"titel":"Cyber Resilience Act – Reporting obligations","url":"https://digital-strategy.ec.europa.eu/en/policies/cra-reporting","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"Cyber Resilience Act – Übersicht","url":"https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"Wichtigste Fragen & Antworten zum Cyber Resilience Act","url":"https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/","herausgeber":"cyber-regulierung.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/cra","sprache":"en"}
{"id":"en/cra#sanktionen","norm":"cra","norm_name":"Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"According to secondary sources, breaches of the essential cybersecurity requirements can be penalised with fines of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher; the exact scale of fines by type of breach was not verified against the regulation's text itself in this session.","quellen":[{"titel":"Cyber Resilience Act – Reporting obligations","url":"https://digital-strategy.ec.europa.eu/en/policies/cra-reporting","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"Cyber Resilience Act – Übersicht","url":"https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"Wichtigste Fragen & Antworten zum Cyber Resilience Act","url":"https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/","herausgeber":"cyber-regulierung.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/cra","sprache":"en"}
{"id":"en/cra#fragen","norm":"cra","norm_name":"Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Does a Swiss software house without a physical product fall under the CRA?**\nYes, potentially: the CRA covers not only hardware but also standalone software with digital elements that is placed on the EU market - for example apps or backend software that connects to devices or networks. What matters is placing it on the market in the EU, not the registered seat.\n\n**Is open-source software generally exempt from the CRA?**\nOnly non-commercial open-source software developed and made available by volunteers without a profit motive. As soon as paid support, commercial distribution or integration into a product sold is added, the CRA applies as normal - open-source steward organisations have their own, lighter-touch obligations from December 2027.\n\n**How does the CRA relate to the EU Machinery Regulation?**\nBoth frameworks require cybersecurity for connected products but cover different product categories: the CRA regulates products with digital elements in general, while the Machinery Regulation (EU) 2023/1230 specifically regulates machinery and its safety functions. For machinery with digital elements, it must be checked case by case which framework - or whether both - applies; see the separate norm file maschinenverordnung_2023_1230.","quellen":[{"titel":"Cyber Resilience Act – Reporting obligations","url":"https://digital-strategy.ec.europa.eu/en/policies/cra-reporting","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"Cyber Resilience Act – Übersicht","url":"https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"Wichtigste Fragen & Antworten zum Cyber Resilience Act","url":"https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/","herausgeber":"cyber-regulierung.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/cra","sprache":"en"}
{"id":"en/cra#unsicher","norm":"cra","norm_name":"Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The EUR-Lex primary text of Regulation (EU) 2024/2847 (eur-lex.europa.eu/eli/reg/2024/2847/oj) could not be retrieved in this session (empty response); content evidenced via the EU Commission page digital-strategy.ec.europa.eu and the BSI, not via the regulation's text itself.\n- The exact date of entry into force of the regulation was not verified in this session and is therefore not listed.\n- The exact scale of fines by type of breach is evidenced only via a secondary source, not verified against the regulation's text.\n- Whether and how the open-source exemption exactly hinges on article text or a recital was not checked against the primary text.","quellen":[{"titel":"Cyber Resilience Act – Reporting obligations","url":"https://digital-strategy.ec.europa.eu/en/policies/cra-reporting","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"Cyber Resilience Act – Übersicht","url":"https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"Wichtigste Fragen & Antworten zum Cyber Resilience Act","url":"https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/","herausgeber":"cyber-regulierung.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/cra","sprache":"en"}
{"id":"en/dora#kurzantwort","norm":"dora","norm_name":"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"DORA obliges EU financial entities - banks, insurers, investment firms, payment service providers and others - to comply with uniform requirements for ICT risk management, incident reporting, resilience testing and the management of ICT third-party providers. The regulation has applied directly in the EU since 17 January 2025. For Swiss companies this is, per the client's assessment, a candidate not yet conclusively examined: relevant above all are Swiss financial institutions with an EU establishment, as well as Swiss ICT providers who supply financial entities in the EU/EEA.","quellen":[{"titel":"Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel","url":"https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"},{"titel":"DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen","url":"https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/","herausgeber":"LEXcellence (Anwaltskanzlei, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU","url":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","herausgeber":"Amt für Veröffentlichungen der Europäischen Union (EUR-Lex)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dora","sprache":"en"}
{"id":"en/dora#wann_gilt","norm":"dora","norm_name":"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","abschnitt":"wann_gilt","ueberschrift":"When does DORA apply to you?","text":"- Industry: Financial services (Recommend individual review): As a financial entity with an establishment, subsidiary or branch in the EU/EEA, that entity is directly subject to DORA's requirements on digital operational resilience.\n- Activity: Payment transactions (Recommend individual review): If you process payment transactions for or with EU financial institutions, DORA may affect you indirectly - for example as an ICT third-party provider under the oversight framework for critical providers. This needs to be checked case by case.\n- Markets: EU (applies if additionally: Industry: Financial services) (Recommend individual review): If you provide services as a Swiss financial entity in the EU/EEA market, DORA can reach you via your customers' contractual requirements or via an EU establishment, even though not every detail of this was verified in the regulation's text itself in this research.\n- Markets: EU (applies if additionally: Activity: Payment transactions) (Recommend individual review): If you provide services as a Swiss ICT or payment service provider (e.g. cloud, software, network, payment processing) for financial entities headquartered in the EU/EEA, DORA can reach you via your customers' contractual requirements, even without your own EU establishment.","quellen":[{"titel":"Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel","url":"https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"},{"titel":"DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen","url":"https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/","herausgeber":"LEXcellence (Anwaltskanzlei, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU","url":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","herausgeber":"Amt für Veröffentlichungen der Europäischen Union (EUR-Lex)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dora","sprache":"en"}
{"id":"en/dora#ausnahmen","norm":"dora","norm_name":"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- According to the secondary sources examined, DORA is triggered by the financial entity's seat in the EU/EEA, not by the customer's seat - a Swiss financial entity without any EU establishment is accordingly not directly within scope.\n- A Swiss bank or insurer without a subsidiary, branch or licensed establishment in an EEA member state is, on this understanding, not directly covered; the finer points were not checked in the regulation's text itself (Art. 2), only via secondary sources.","quellen":[{"titel":"Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel","url":"https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"},{"titel":"DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen","url":"https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/","herausgeber":"LEXcellence (Anwaltskanzlei, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU","url":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","herausgeber":"Amt für Veröffentlichungen der Europäischen Union (EUR-Lex)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dora","sprache":"en"}
{"id":"en/dora#pflichten","norm":"dora","norm_name":"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Establish an ICT risk management framework (per secondary sources, including governance, identification, protection, detection, response and recovery).\n- Report major ICT-related incidents to the competent supervisory authority.\n- Conduct regular digital operational resilience testing, for significant institutions including threat-led penetration testing (TLPT).\n- Manage ICT third-party risk, including contractual minimum requirements towards ICT providers.\n- For ICT third-party providers from third countries (such as Switzerland) classified as 'critical': per a secondary source, EU financial entities may only use their services if the provider has established a subsidiary in the EU/EEA within twelve months of classification - this statement was not verified against the regulation's text (Art. 31) itself.","quellen":[{"titel":"Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel","url":"https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"},{"titel":"DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen","url":"https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/","herausgeber":"LEXcellence (Anwaltskanzlei, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU","url":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","herausgeber":"Amt für Veröffentlichungen der Europäischen Union (EUR-Lex)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dora","sprache":"en"}
{"id":"en/dora#nachweise","norm":"dora","norm_name":"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Documented ICT risk management framework.\n- Register of contracts with ICT third-party providers (per secondary sources part of DORA, not itself checked in the regulation's text).\n- Evidence of resilience tests carried out.\n- Reporting process for major ICT incidents.","quellen":[{"titel":"Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel","url":"https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"},{"titel":"DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen","url":"https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/","herausgeber":"LEXcellence (Anwaltskanzlei, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU","url":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","herausgeber":"Amt für Veröffentlichungen der Europäischen Union (EUR-Lex)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dora","sprache":"en"}
{"id":"en/dora#fristen","norm":"dora","norm_name":"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 17 January 2025: DORA becomes binding and applicable in the EU/EEA (regulation in force since 17 January 2023, applicable from 17 January 2025 per the secondary sources examined).","quellen":[{"titel":"Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel","url":"https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"},{"titel":"DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen","url":"https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/","herausgeber":"LEXcellence (Anwaltskanzlei, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU","url":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","herausgeber":"Amt für Veröffentlichungen der Europäischen Union (EUR-Lex)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dora","sprache":"en"}
{"id":"en/dora#sanktionen","norm":"dora","norm_name":"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"The regulation's text itself (including Art. 50 on administrative sanctions) was not examined in full text in this research, as the EUR-Lex full text was not technically retrievable. Per secondary sources, national supervisory authorities can impose measures and sanctions on financial entities within the EU scope. For Swiss companies without their own EU scope, DORA, per the sources examined, does not act as directly enforceable, but primarily via EU customers' contractual requirements.","quellen":[{"titel":"Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel","url":"https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"},{"titel":"DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen","url":"https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/","herausgeber":"LEXcellence (Anwaltskanzlei, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU","url":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","herausgeber":"Amt für Veröffentlichungen der Europäischen Union (EUR-Lex)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dora","sprache":"en"}
{"id":"en/dora#fragen","norm":"dora","norm_name":"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Are we, as a Swiss fintech without an EU establishment, automatically exempt from DORA?**\nBased on the source status examined here, yes, as long as you have no EU/EEA establishment and are not classified as a critical ICT third-party provider for EU financial entities. A conclusive case-by-case review against the regulation's text (Art. 2 and Art. 31 DORA) was not carried out in this research.\n\n**Why is there no separate 'Finance' industry on the website yet?**\nThat is a deliberate, still open decision by the client (see the architecture document, item 13). This norm file has been researched and evidenced; the decision to show DORA and the FINMA circular on the website as a separate industry is a separate, outstanding matter.","quellen":[{"titel":"Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel","url":"https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"},{"titel":"DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen","url":"https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/","herausgeber":"LEXcellence (Anwaltskanzlei, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU","url":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","herausgeber":"Amt für Veröffentlichungen der Europäischen Union (EUR-Lex)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dora","sprache":"en"}
{"id":"en/dora#unsicher","norm":"dora","norm_name":"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- CANDIDATE STATUS: per the client's architecture decision, DORA has not yet been adopted into the website. No 'Finance' industry page exists yet; whether and how DORA applies to Swiss companies case by case has not yet been conclusively clarified (see ARCHITEKTUR-UND-CONTENT.md, item 13 and section 7.10).\n- The EUR-Lex full text of the regulation (in particular Art. 2 scope and Art. 31 oversight framework for critical ICT third-party providers) could not be technically retrieved in this research (JavaScript requirement of the EUR-Lex page). The statements on scope, third-country rules and sanctions come from secondary sources and are marked 'pruefen' accordingly.\n- The exact list of financial entity categories covered by DORA was taken not directly from the regulation's text but from secondary sources.\n- Whether and how FINMA-supervised institutions are additionally affected by DORA on top of existing FINMA requirements was not examined.","quellen":[{"titel":"Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel","url":"https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"},{"titel":"DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen","url":"https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/","herausgeber":"LEXcellence (Anwaltskanzlei, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU","url":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","herausgeber":"Amt für Veröffentlichungen der Europäischen Union (EUR-Lex)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dora","sprache":"en"}
{"id":"en/eu_ai_act#kurzantwort","norm":"eu_ai_act","norm_name":"Regulation laying down harmonised rules on artificial intelligence (EU AI Act)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"The EU AI Act (Regulation (EU) 2024/1689) regulates AI systems in stages by risk class and applies to providers and deployers whose AI systems are placed on the market in the EU or whose output is used there - regardless of registered seat. Bans on certain practices have applied since February 2025, rules for general-purpose AI models since August 2025, and transparency obligations since August 2026. The amending regulation (EU) 2026/1744 ('Digital Omnibus', published on 24 July 2026) has postponed the obligations for high-risk systems under Annex III to December 2027 and for AI in regulated products under Annex I to August 2028.","quellen":[{"titel":"Regulatory framework proposal on artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde","url":"https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde","herausgeber":"Flick Gocke Schaumburg (Kanzlei)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/eu_ai_act","sprache":"en"}
{"id":"en/eu_ai_act#wann_gilt","norm":"eu_ai_act","norm_name":"Regulation laying down harmonised rules on artificial intelligence (EU AI Act)","abschnitt":"wann_gilt","ueberschrift":"When does EU AI Act apply to you?","text":"- Activity: AI provider (own AI products) (Likely applies): As the provider of an AI system placed on the market in the EU, you bear the most far-reaching obligations under the EU AI Act - from bans on certain practices to conformity assessment and transparency obligations, depending on your system's risk class.\n- Activity: Using AI (Recommend individual review): Even as a deployer - not only as a provider - of an AI system, you have obligations under the EU AI Act, in particular on transparency towards users and, for high-risk systems, on oversight and documentation.\n- Markets: EU (applies if additionally: Activity: Using AI, AI provider (own AI products)) (Recommend individual review): The EU AI Act is triggered by placing on the market or use in the EU, not by the registered seat - if you use AI systems whose output is used in the EU, the regulation can apply regardless of your seat in Switzerland. Without any use or provision of AI, the EU market alone does not trigger the regulation.","quellen":[{"titel":"Regulatory framework proposal on artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde","url":"https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde","herausgeber":"Flick Gocke Schaumburg (Kanzlei)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/eu_ai_act","sprache":"en"}
{"id":"en/eu_ai_act#ausnahmen","norm":"eu_ai_act","norm_name":"Regulation laying down harmonised rules on artificial intelligence (EU AI Act)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- AI systems developed or used exclusively for military, defence or national security purposes.\n- Purely private, non-professional use of AI systems by natural persons.\n- Scientific research and development prior to market introduction.\n- Systems that, per the Digital Omnibus amendment (Regulation (EU) 2026/1744), serve exclusively user support, performance optimisation, automation or non-safety-relevant quality control no longer automatically fall under the high-risk classification.","quellen":[{"titel":"Regulatory framework proposal on artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde","url":"https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde","herausgeber":"Flick Gocke Schaumburg (Kanzlei)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/eu_ai_act","sprache":"en"}
{"id":"en/eu_ai_act#pflichten","norm":"eu_ai_act","norm_name":"Regulation laying down harmonised rules on artificial intelligence (EU AI Act)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Refrain from prohibited AI practices (including manipulative systems, social scoring, certain real-time remote biometric identification) since 2 February 2025; two further bans (including on non-consensual intimate content and abuse material) have applied since 2 December 2026.\n- For providers of general-purpose AI (GPAI) models: transparency and copyright obligations, plus additional risk assessments where there is systemic risk, since 2 August 2025.\n- Transparency obligations under Art. 50: labelling of AI-generated content, disclosure of interaction with an AI system, labelling of deepfakes and AI-generated text on matters of public interest - since 2 August 2026, with a four-month transition period for systems already on the market until 2 December 2026.\n- For high-risk AI systems under Annex III (including biometrics, critical infrastructure, education, employment, migration/asylum/border control): conformity assessment, risk management system, documentation, human oversight - applicable from 2 December 2027.\n- For high-risk AI as a safety component in regulated products under Annex I (e.g. lifts, toys): corresponding obligations from 2 August 2028.","quellen":[{"titel":"Regulatory framework proposal on artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde","url":"https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde","herausgeber":"Flick Gocke Schaumburg (Kanzlei)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/eu_ai_act","sprache":"en"}
{"id":"en/eu_ai_act#nachweise","norm":"eu_ai_act","norm_name":"Regulation laying down harmonised rules on artificial intelligence (EU AI Act)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Risk classification of the AI system (prohibited/high/limited/minimal) with justification.\n- Technical documentation and declaration of conformity for high-risk systems.\n- Labelling or disclosure under Art. 50 where transparency obligations apply.\n- Documentation of human oversight for high-risk use.","quellen":[{"titel":"Regulatory framework proposal on artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde","url":"https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde","herausgeber":"Flick Gocke Schaumburg (Kanzlei)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/eu_ai_act","sprache":"en"}
{"id":"en/eu_ai_act#fristen","norm":"eu_ai_act","norm_name":"Regulation laying down harmonised rules on artificial intelligence (EU AI Act)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 2 February 2025: Bans on certain AI practices and the obligation on AI literacy become applicable.\n- 2 August 2025: Rules for general-purpose AI (GPAI) models become applicable.\n- 24 July 2026: The amending regulation (EU) 2026/1744 ('Digital Omnibus') is published in the Official Journal.\n- 2 August 2026: Transparency obligations under Art. 50 become applicable.\n- 2 December 2026: The transition period for transparency obligations for systems already on the market ends; two further bans under Art. 5 enter into force.\n- 2 December 2027: Obligations for high-risk AI systems under Annex III become applicable (postponed from originally August 2026).\n- 2 August 2028: Obligations for high-risk AI as a safety component in regulated products under Annex I become applicable (postponed from originally August 2027).","quellen":[{"titel":"Regulatory framework proposal on artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde","url":"https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde","herausgeber":"Flick Gocke Schaumburg (Kanzlei)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/eu_ai_act","sprache":"en"}
{"id":"en/eu_ai_act#sanktionen","norm":"eu_ai_act","norm_name":"Regulation laying down harmonised rules on artificial intelligence (EU AI Act)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"Breaches of prohibited AI practices (Art. 5) can be penalised with fines of up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Breaches of transparency obligations under Art. 50 can be penalised with up to EUR 15 million or 3% of worldwide annual turnover.","quellen":[{"titel":"Regulatory framework proposal on artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde","url":"https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde","herausgeber":"Flick Gocke Schaumburg (Kanzlei)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/eu_ai_act","sprache":"en"}
{"id":"en/eu_ai_act#fragen","norm":"eu_ai_act","norm_name":"Regulation laying down harmonised rules on artificial intelligence (EU AI Act)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**What changed under Regulation (EU) 2026/1744 ('Digital Omnibus')?**\nThe amending regulation, published on 24 July 2026, mainly postponed the deadlines for high-risk AI systems - to December 2027 for standalone high-risk systems (Annex III) and to August 2028 for AI in regulated products (Annex I). It also narrowed the definition of safety-relevant components and added two new bans.\n\n**Does the EU AI Act also apply to a Swiss company that only uses its own AI tool internally?**\nIf the tool is used exclusively internally and without any EU connection, the AI Act generally does not apply. As soon as the system's output affects people in the EU or the system is placed on the market there, the provider or deployer obligations need to be checked.\n\n**From when must a high-risk AI system meet the full requirements?**\nFor most high-risk applications under Annex III (e.g. personnel selection, creditworthiness assessment, biometric systems), the obligation applies, following the postponement by the Omnibus amendment, from 2 December 2027; for AI as a safety component in products already regulated (Annex I), from 2 August 2028.","quellen":[{"titel":"Regulatory framework proposal on artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde","url":"https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde","herausgeber":"Flick Gocke Schaumburg (Kanzlei)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/eu_ai_act","sprache":"en"}
{"id":"en/eu_ai_act#unsicher","norm":"eu_ai_act","norm_name":"Regulation laying down harmonised rules on artificial intelligence (EU AI Act)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The EUR-Lex primary text of Regulation (EU) 2024/1689 and the amending regulation (EU) 2026/1744 could not be retrieved in this session (empty response, per prior findings HTTP 202/bot block); deadlines evidenced via the EU Commission page and a law-firm source, not via the regulation's text itself.\n- The exact entry-into-force date of Regulation (EU) 2026/1744 is given in a secondary source as '27 July 2026' (publication per prior findings on 24.7.2026) - not checked against the Official Journal itself.\n- The exact new wording of 'safety-relevant components' after the Omnibus amendment was not checked in full text.","quellen":[{"titel":"Regulatory framework proposal on artificial intelligence","url":"https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai","herausgeber":"Europäische Kommission (Generaldirektion CNECT)","abgerufen":"2026-09-24"},{"titel":"EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde","url":"https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde","herausgeber":"Flick Gocke Schaumburg (Kanzlei)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/eu_ai_act","sprache":"en"}
{"id":"en/mdr#kurzantwort","norm":"mdr","norm_name":"Regulation (EU) 2017/745 on medical devices","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"The EU Medical Device Regulation (MDR, Regulation (EU) 2017/745) governs conformity assessment, CE marking, technical documentation and market surveillance for medical devices in the EU; it has applied since 26 May 2021. Since that date, Switzerland has been a third country for the EU, because the mutual recognition agreement (MRA) was not updated - Swiss manufacturers therefore need an authorised representative in the EU for the EU market. Software can itself be a medical device, and the MDR sets its own requirements on IT security for it in Annex I.","quellen":[{"titel":"Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)","url":"https://eur-lex.europa.eu/eli/reg/2017/745/oj","herausgeber":"Europäisches Parlament und Rat der Europäischen Union / EUR-Lex","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Medical devices – new regulations","url":"https://health.ec.europa.eu/medical-devices-sector/new-regulations_en","herausgeber":"Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mdr","sprache":"en"}
{"id":"en/mdr#wann_gilt","norm":"mdr","norm_name":"Regulation (EU) 2017/745 on medical devices","abschnitt":"wann_gilt","ueberschrift":"When does EU MDR apply to you?","text":"- Activity: Medical devices (Applies): You manufacture, import or distribute a medical device - the MDR sets out how you must assess conformity, document and CE-mark it as soon as the product enters the market in the EU.\n- Industry: MedTech (Likely applies): As a MedTech company, you are highly likely to develop or distribute products that fall under the MDR's definition of a 'medical device' - check the classification based on your specific intended purpose.\n- Markets: EU, Germany (applies if additionally: Activity: Medical devices) (Recommend individual review): You are active on the EU market (or in Germany) and manufacture or distribute medical devices - even as a Swiss company, this makes you subject to the MDR. As a Swiss manufacturer, you additionally need an authorised representative in the EU since 26.5.2021.\n- Role towards customers: Manufacturer (applies if additionally: Activity: Medical devices) (Recommend individual review): As the manufacturer of a medical device, you bear the main responsibility under the MDR for conformity assessment, technical documentation, post-market surveillance and - if you are based in Switzerland and supply the EU - appointing an EU authorised representative. For manufacturers of other products, the MDR does not apply.","quellen":[{"titel":"Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)","url":"https://eur-lex.europa.eu/eli/reg/2017/745/oj","herausgeber":"Europäisches Parlament und Rat der Europäischen Union / EUR-Lex","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Medical devices – new regulations","url":"https://health.ec.europa.eu/medical-devices-sector/new-regulations_en","herausgeber":"Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mdr","sprache":"en"}
{"id":"en/mdr#ausnahmen","norm":"mdr","norm_name":"Regulation (EU) 2017/745 on medical devices","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Custom-made devices (products individually made for a specific patient) are subject to adapted, reduced requirements instead of the full conformity assessment.\n- Pure in-vitro diagnostics do not fall under the MDR but under the separate IVDR (Regulation (EU) 2017/746).\n- For in-house manufacture and use of products within a health institution without supply to third parties, relief from certain MDR obligations applies under narrow conditions.\n- The exact article and paragraph numbers of these exemptions were not verified in this session via full-text retrieval from EUR-Lex (see 'unsicher').","quellen":[{"titel":"Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)","url":"https://eur-lex.europa.eu/eli/reg/2017/745/oj","herausgeber":"Europäisches Parlament und Rat der Europäischen Union / EUR-Lex","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Medical devices – new regulations","url":"https://health.ec.europa.eu/medical-devices-sector/new-regulations_en","herausgeber":"Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mdr","sprache":"en"}
{"id":"en/mdr#pflichten","norm":"mdr","norm_name":"Regulation (EU) 2017/745 on medical devices","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Carry out a conformity assessment procedure matching the product's risk class (Class I to III), including involving a notified body for higher classes.\n- Draw up and keep current technical documentation evidencing the product's design, manufacture and safety.\n- For software that is itself a medical device or embedded in one: meet the Annex I requirements on the design and manufacture of electronic programmable systems, including IT security measures and protection against unauthorised access, aligned with the state of the art.\n- Apply CE marking only after successful conformity assessment.\n- Operate post-market surveillance and a vigilance system (reporting of serious incidents).\n- As a Swiss manufacturer: appoint an authorised representative established in the EU before the product is placed on the market there.\n- Register the manufacturer, authorised representative and product in the EU database EUDAMED, to the extent the respective modules are already mandatory.","quellen":[{"titel":"Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)","url":"https://eur-lex.europa.eu/eli/reg/2017/745/oj","herausgeber":"Europäisches Parlament und Rat der Europäischen Union / EUR-Lex","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Medical devices – new regulations","url":"https://health.ec.europa.eu/medical-devices-sector/new-regulations_en","herausgeber":"Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mdr","sprache":"en"}
{"id":"en/mdr#nachweise","norm":"mdr","norm_name":"Regulation (EU) 2017/745 on medical devices","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Technical documentation under Annex II/III of the MDR.\n- EU declaration of conformity.\n- CE marking with the notified body's identification number (where required).\n- Certificate from the notified body (for Class IIa, IIb, III and certain Class I products).\n- Evidence of an appointed EU authorised representative where based outside the EU, including the mandate document under Annex II of the MDR.","quellen":[{"titel":"Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)","url":"https://eur-lex.europa.eu/eli/reg/2017/745/oj","herausgeber":"Europäisches Parlament und Rat der Europäischen Union / EUR-Lex","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Medical devices – new regulations","url":"https://health.ec.europa.eu/medical-devices-sector/new-regulations_en","herausgeber":"Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mdr","sprache":"en"}
{"id":"en/mdr#fristen","norm":"mdr","norm_name":"Regulation (EU) 2017/745 on medical devices","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 26 May 2021: The MDR (Regulation (EU) 2017/745) becomes applicable; from this date, Switzerland is treated as a third country by the EU in medical device law, because the MRA was not updated.","quellen":[{"titel":"Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)","url":"https://eur-lex.europa.eu/eli/reg/2017/745/oj","herausgeber":"Europäisches Parlament und Rat der Europäischen Union / EUR-Lex","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Medical devices – new regulations","url":"https://health.ec.europa.eu/medical-devices-sector/new-regulations_en","herausgeber":"Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mdr","sprache":"en"}
{"id":"en/mdr#sanktionen","norm":"mdr","norm_name":"Regulation (EU) 2017/745 on medical devices","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"The MDR itself does not prescribe uniform fines; EU member states set effective, proportionate and dissuasive sanctions for breaches in their national law. Market surveillance authorities can additionally order sales bans, recalls and withdrawal of CE marking. The exact enabling provision in the MDR was not verified via full-text retrieval in this session (see 'unsicher').","quellen":[{"titel":"Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)","url":"https://eur-lex.europa.eu/eli/reg/2017/745/oj","herausgeber":"Europäisches Parlament und Rat der Europäischen Union / EUR-Lex","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Medical devices – new regulations","url":"https://health.ec.europa.eu/medical-devices-sector/new-regulations_en","herausgeber":"Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mdr","sprache":"en"}
{"id":"en/mdr#fragen","norm":"mdr","norm_name":"Regulation (EU) 2017/745 on medical devices","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**We are a Swiss manufacturer and sell only in Switzerland - does the MDR affect us?**\nNot directly, as long as you operate exclusively on the Swiss market; there, the MedDO applies. As soon as you place a product on the market in the EU, the MDR applies and you need an authorised representative in the EU.\n\n**Is our software automatically a medical device?**\nNo, that depends on the intended purpose. Software used for medical purposes such as diagnosis, monitoring or treatment support can itself qualify as a medical device and must then meet the MDR's requirements, even if it is not a hardware component.\n\n**What does Switzerland's third-country status specifically mean for us as a manufacturer?**\nSince 26.5.2021 you need an authorised representative established in the EU to represent your products there, and you no longer have direct access to the EU database EUDAMED or to the information exchange of European authorities. At the same time, EU manufacturers supplying Switzerland must appoint a Swiss authorised representative.","quellen":[{"titel":"Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)","url":"https://eur-lex.europa.eu/eli/reg/2017/745/oj","herausgeber":"Europäisches Parlament und Rat der Europäischen Union / EUR-Lex","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Medical devices – new regulations","url":"https://health.ec.europa.eu/medical-devices-sector/new-regulations_en","herausgeber":"Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mdr","sprache":"en"}
{"id":"en/mdr#unsicher","norm":"mdr","norm_name":"Regulation (EU) 2017/745 on medical devices","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The exact wording of Annex I section 17 of the MDR (subsections on IT security) could not be verified via full-text retrieval from EUR-Lex in this session - EUR-Lex blocked automated access (WebFetch and curl repeatedly returned empty responses with HTTP 202/404). The description rests on the website's existing content and established professional knowledge, not on a primary text read in this session.\n- The exact article number of the MDR's enabling provision for sanctions (presumably Art. 113) was not verified via full text.\n- The exact article/paragraph numbers of the exemptions named (custom-made devices, IVDR demarcation, in-house manufacture) were not verified via full-text retrieval.\n- The exact title and content of the 'Notice to Stakeholders' on the Switzerland-EU MRA status, mentioned by the European Commission, could not be retrieved directly (404 at the presumed URL); its existence is evidenced via the health.ec.europa.eu page, not its wording.","quellen":[{"titel":"Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)","url":"https://eur-lex.europa.eu/eli/reg/2017/745/oj","herausgeber":"Europäisches Parlament und Rat der Europäischen Union / EUR-Lex","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Medical devices – new regulations","url":"https://health.ec.europa.eu/medical-devices-sector/new-regulations_en","herausgeber":"Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mdr","sprache":"en"}
{"id":"en/revdsg#kurzantwort","norm":"revdsg","norm_name":"Federal Act on Data Protection (Data Protection Act, FADP)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"The revised Federal Act on Data Protection (FADP, SR 235.1) has, since 1 September 2023, governed the processing of personal data of natural persons by private companies and federal bodies in Switzerland. It obliges controllers, among other things, to data protection by design and by default (Art. 7 FADP), to keep a record of processing activities (Art. 12 FADP, with an exemption for most SMEs), and to notify data security breaches to the Federal Data Protection and Information Commissioner (FDPIC, Art. 24 FADP).","quellen":[{"titel":"Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/491/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/568/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"EDÖB - Aufsichtsbehörde für Datenschutz","url":"https://www.edoeb.admin.ch/edoeb/de/home.html","herausgeber":"Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/revdsg","sprache":"en"}
{"id":"en/revdsg#wann_gilt","norm":"revdsg","norm_name":"Federal Act on Data Protection (Data Protection Act, FADP)","abschnitt":"wann_gilt","ueberschrift":"When does FADP apply to you?","text":"- Activity: Customers’ personal data (Applies): You process personal data of customers - this makes you subject to the basic obligations of the FADP as soon as the processing has an effect in Switzerland (Art. 2 f. FADP).\n- Activity: Special category personal data (Applies): You process special categories of personal data (e.g. health, biometric or religious data) - stricter requirements apply to this under Art. 5(c) and Art. 6(7) FADP, including on consent.\n- Markets: Switzerland (applies if additionally: Markets: Switzerland) (Applies): Your activity is (also) directed at the Swiss market - even simply as an employer, you process personal data of your employees (HR data), even without separate customer data processing. Under Art. 3 FADP, the act applies to every processing that has an effect in Switzerland, regardless of where your company is based.\n- Employees: from 250 (only together with industry or activity) (Applies): With 250 or more employees on 1 January of the year, the SME exemption from the record of processing activities under Art. 12(5) FADP and Art. 24 DPO does not apply to you - you must keep such a record.","quellen":[{"titel":"Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/491/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/568/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"EDÖB - Aufsichtsbehörde für Datenschutz","url":"https://www.edoeb.admin.ch/edoeb/de/home.html","herausgeber":"Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/revdsg","sprache":"en"}
{"id":"en/revdsg#ausnahmen","norm":"revdsg","norm_name":"Federal Act on Data Protection (Data Protection Act, FADP)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Purely private, exclusively personal processing of personal data does not fall under the act (Art. 2(2)(a) FADP).\n- Companies and other private-law organisations, as well as natural persons, employing fewer than 250 employees on 1 January of a year are exempt from the duty to keep a record of processing activities - unless special categories of personal data are processed on a large scale or high-risk profiling is carried out (Art. 12(5) FADP in conjunction with Art. 24 DPO).\n- The FADP protects only natural persons; the processing of data of legal entities does not fall under it (Art. 1 FADP).\n- The Federal Assembly, the Federal Council, the federal courts, as well as the Office of the Attorney General and adjudicating federal authorities, are exempt from FDPIC supervision for certain proceedings (Art. 4(2) FADP).","quellen":[{"titel":"Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/491/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/568/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"EDÖB - Aufsichtsbehörde für Datenschutz","url":"https://www.edoeb.admin.ch/edoeb/de/home.html","herausgeber":"Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/revdsg","sprache":"en"}
{"id":"en/revdsg#pflichten","norm":"revdsg","norm_name":"Federal Act on Data Protection (Data Protection Act, FADP)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Comply with processing principles: lawfulness, good faith, proportionality, purpose limitation (Art. 6 FADP).\n- Ensure data protection by design and by default, starting already at the planning stage (Art. 7 FADP).\n- Ensure adequate data security through suitable technical and organisational measures (Art. 8 FADP).\n- Keep a record of processing activities, unless an SME exemption applies (Art. 12 FADP, Art. 24 DPO).\n- Inform data subjects appropriately when collecting personal data (Art. 19 FADP).\n- For processing likely to result in a high risk to personality or fundamental rights, carry out a data protection impact assessment in advance (Art. 22 FADP).\n- Notify the FDPIC as quickly as possible of data security breaches likely to result in a high risk to the data subject, with the mandatory details under Art. 15 DPO (Art. 24 FADP).\n- Grant data subjects the right of access, generally within 30 days (Art. 25 FADP, Art. 18 DPO).","quellen":[{"titel":"Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/491/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/568/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"EDÖB - Aufsichtsbehörde für Datenschutz","url":"https://www.edoeb.admin.ch/edoeb/de/home.html","herausgeber":"Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/revdsg","sprache":"en"}
{"id":"en/revdsg#nachweise","norm":"revdsg","norm_name":"Federal Act on Data Protection (Data Protection Act, FADP)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Documented record of processing activities with the minimum details under Art. 12(2) FADP.\n- Documentation of data protection impact assessments carried out, to be retained for at least two years after completion of the processing (Art. 14 DPO).\n- Documentation of reported data security breaches with type, effects and measures, to be retained for at least two years from the report (Art. 15(4) DPO).\n- Evidence of the technical and organisational measures taken for data security (Art. 8 FADP).","quellen":[{"titel":"Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/491/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/568/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"EDÖB - Aufsichtsbehörde für Datenschutz","url":"https://www.edoeb.admin.ch/edoeb/de/home.html","herausgeber":"Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/revdsg","sprache":"en"}
{"id":"en/revdsg#fristen","norm":"revdsg","norm_name":"Federal Act on Data Protection (Data Protection Act, FADP)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 1 September 2023: The revised FADP and the Data Protection Ordinance (DPO) enter into force (Art. 74(2) FADP in conjunction with the Federal Council decision of 31 August 2022).","quellen":[{"titel":"Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/491/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/568/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"EDÖB - Aufsichtsbehörde für Datenschutz","url":"https://www.edoeb.admin.ch/edoeb/de/home.html","herausgeber":"Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/revdsg","sprache":"en"}
{"id":"en/revdsg#sanktionen","norm":"revdsg","norm_name":"Federal Act on Data Protection (Data Protection Act, FADP)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"Fines of up to CHF 250,000 for private individuals for wilful breach of information, access and cooperation obligations (Art. 60 FADP) or of due-diligence obligations such as unlawful disclosure of personal data abroad, faulty transfer to a processor, or non-compliance with the Federal Council's minimum data security requirements (Art. 61 FADP). Breach of professional confidentiality (Art. 62 FADP) and disregard of FDPIC rulings (Art. 63 FADP) also carry fines of up to CHF 250,000. Administrative criminal law applies to violations within business operations (Art. 64 FADP); prosecution and adjudication fall to the cantons (Art. 65 FADP), and the limitation period for prosecution is five years (Art. 66 FADP). A breach of the notification duty for data security breaches (Art. 24 FADP) is not listed as a separate offence in the penal provisions (Art. 60-64 FADP).","quellen":[{"titel":"Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/491/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/568/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"EDÖB - Aufsichtsbehörde für Datenschutz","url":"https://www.edoeb.admin.ch/edoeb/de/home.html","herausgeber":"Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/revdsg","sprache":"en"}
{"id":"en/revdsg#fragen","norm":"revdsg","norm_name":"Federal Act on Data Protection (Data Protection Act, FADP)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Does every company have to keep a record of processing activities?**\nNo. Under Art. 24 DPO, companies and other private-law organisations, as well as natural persons, employing fewer than 250 employees on 1 January of a year are exempt from this duty - unless they process special categories of personal data on a large scale or carry out high-risk profiling. Both elements (size and type of processing) must be checked together.\n\n**From when does the FADP apply?**\nSince 1 September 2023.\n\n**Who supervises compliance?**\nThe Federal Data Protection and Information Commissioner (FDPIC, Art. 4 FADP), with the exception of the Federal Assembly, the Federal Council, the federal courts, and certain proceedings of the Office of the Attorney General and adjudicating federal authorities.\n\n**What must a notification to the FDPIC of a data security breach contain?**\nUnder Art. 15 DPO, at minimum: the type of breach, where possible its time and duration, the categories and approximate number of persons or personal data affected, the consequences including any risks, measures taken or planned, and the contact details of a contact person. Missing details can be submitted later.","quellen":[{"titel":"Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/491/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/568/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"EDÖB - Aufsichtsbehörde für Datenschutz","url":"https://www.edoeb.admin.ch/edoeb/de/home.html","herausgeber":"Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/revdsg","sprache":"en"}
{"id":"en/revdsg#unsicher","norm":"revdsg","norm_name":"Federal Act on Data Protection (Data Protection Act, FADP)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The Data Protection Ordinance (DPO, SR 235.11) was not read in full text; only Art. 1 and Art. 11-34 (including Art. 15 notification, Art. 24 SME exemption) were read; the remaining approximately 10 articles of the roughly 20 pages were not examined.\n- The FDPIC's exact investigative and ruling powers (Art. 49-51 FADP) were not checked in full wording; only the context from Art. 52 FADP (procedure) is available.\n- Note on naming: the name 'VDSG' used in the brief refers to the old 1993 ordinance to the DSG; the current ordinance cited here is correctly called the 'Data Protection Ordinance (DPO)', SR 235.11.","quellen":[{"titel":"Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/491/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023","url":"https://www.fedlex.admin.ch/eli/cc/2022/568/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"EDÖB - Aufsichtsbehörde für Datenschutz","url":"https://www.edoeb.admin.ch/edoeb/de/home.html","herausgeber":"Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/revdsg","sprache":"en"}
{"id":"en/finma_rundschreiben#kurzantwort","norm":"finma_rundschreiben","norm_name":"FINMA Circular 2023/1 \"Operational risks and resilience – banks\"","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"FINMA Circular 2023/1 sets out in detail, for Swiss banks under the Banking Act, how operational risks are to be managed - including ICT risk management, cyber risk management and business continuity management. It replaced the earlier Circular 2008/21. IMPORTANT: the title and content of this file come from secondary sources, not from a document examined in full text on finma.ch - the FINMA website could not be technically read in full text in this research. Before external use, the exact wording should be verified on finma.ch.","quellen":[{"titel":"FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)","url":"https://www.sidd.swiss/einblicke/finma-dora-leitfaden/","herausgeber":"SIDD Swiss (Beratungsunternehmen, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)","url":"https://www.finma.ch/de/dokumentation/rundschreiben/","herausgeber":"Eidgenössische Finanzmarktaufsicht (FINMA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/finma_rundschreiben","sprache":"en"}
{"id":"en/finma_rundschreiben#wann_gilt","norm":"finma_rundschreiben","norm_name":"FINMA Circular 2023/1 \"Operational risks and resilience – banks\"","abschnitt":"wann_gilt","ueberschrift":"When does FINMA Circular 2023/1 apply to you?","text":"- Industry: Financial services (Recommend individual review): If you are a bank or securities firm under the Swiss Banking Act, the FINMA circular on operational risks and resilience applies to you. For other financial institutions (insurers, asset managers), separate circulars exist that were not examined here.\n- Markets: Switzerland (applies if additionally: Industry: Financial services) (Recommend individual review): As a FINMA-supervised institution operating in Switzerland, this circular may be relevant to you.","quellen":[{"titel":"FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)","url":"https://www.sidd.swiss/einblicke/finma-dora-leitfaden/","herausgeber":"SIDD Swiss (Beratungsunternehmen, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)","url":"https://www.finma.ch/de/dokumentation/rundschreiben/","herausgeber":"Eidgenössische Finanzmarktaufsicht (FINMA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/finma_rundschreiben","sprache":"en"}
{"id":"en/finma_rundschreiben#ausnahmen","norm":"finma_rundschreiben","norm_name":"FINMA Circular 2023/1 \"Operational risks and resilience – banks\"","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Per a secondary source, the primary addressees are banks under the Banking Act (BankA); for insurers, analogous requirements are said, per the same source, to apply under a separate circular (Circular 2017/02). Both statements were not verified on finma.ch itself.\n- Smaller institutions benefit, per a secondary source, from a simplified application differentiated by supervisory category; the exact design was not examined.","quellen":[{"titel":"FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)","url":"https://www.sidd.swiss/einblicke/finma-dora-leitfaden/","herausgeber":"SIDD Swiss (Beratungsunternehmen, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)","url":"https://www.finma.ch/de/dokumentation/rundschreiben/","herausgeber":"Eidgenössische Finanzmarktaufsicht (FINMA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/finma_rundschreiben","sprache":"en"}
{"id":"en/finma_rundschreiben#pflichten","norm":"finma_rundschreiben","norm_name":"FINMA Circular 2023/1 \"Operational risks and resilience – banks\"","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Establish an integrated operational risk management framework.\n- Own ICT risk management with an inventory of critical data and processes.\n- Cyber risk management with threat intelligence and monitoring.\n- Business continuity management (BCM) including cyber resilience.\n- Definition and management of critical functions and critical data ('Critical Data').","quellen":[{"titel":"FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)","url":"https://www.sidd.swiss/einblicke/finma-dora-leitfaden/","herausgeber":"SIDD Swiss (Beratungsunternehmen, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)","url":"https://www.finma.ch/de/dokumentation/rundschreiben/","herausgeber":"Eidgenössische Finanzmarktaufsicht (FINMA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/finma_rundschreiben","sprache":"en"}
{"id":"en/finma_rundschreiben#nachweise","norm":"finma_rundschreiben","norm_name":"FINMA Circular 2023/1 \"Operational risks and resilience – banks\"","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Documented operational risk framework.\n- ICT and cyber risk inventory.\n- BCM concept including cyber resilience measures.\n- Evidence of the management of critical functions towards FINMA as part of ongoing supervision.","quellen":[{"titel":"FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)","url":"https://www.sidd.swiss/einblicke/finma-dora-leitfaden/","herausgeber":"SIDD Swiss (Beratungsunternehmen, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)","url":"https://www.finma.ch/de/dokumentation/rundschreiben/","herausgeber":"Eidgenössische Finanzmarktaufsicht (FINMA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/finma_rundschreiben","sprache":"en"}
{"id":"en/finma_rundschreiben#fristen","norm":"finma_rundschreiben","norm_name":"FINMA Circular 2023/1 \"Operational risks and resilience – banks\"","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 1 January 2024: FINMA Circular 2023/1 entered into force per a secondary source (replacing Circular 2008/21); not verified on finma.ch itself.","quellen":[{"titel":"FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)","url":"https://www.sidd.swiss/einblicke/finma-dora-leitfaden/","herausgeber":"SIDD Swiss (Beratungsunternehmen, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)","url":"https://www.finma.ch/de/dokumentation/rundschreiben/","herausgeber":"Eidgenössische Finanzmarktaufsicht (FINMA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/finma_rundschreiben","sprache":"en"}
{"id":"en/finma_rundschreiben#sanktionen","norm":"finma_rundschreiben","norm_name":"FINMA Circular 2023/1 \"Operational risks and resilience – banks\"","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"The circular itself contains no penalty provisions of its own - per FINMA's own description of its supervisory practice (Art. 7(1)(b) FINMASA), FINMA circulars set out in detail the application of financial market legislation and bind FINMA in its application of the law. Breaches of the obligations set out in it can be addressed through FINMA's general supervisory instruments (rulings, measures); the exact instruments were not examined article by article in this research.","quellen":[{"titel":"FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)","url":"https://www.sidd.swiss/einblicke/finma-dora-leitfaden/","herausgeber":"SIDD Swiss (Beratungsunternehmen, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)","url":"https://www.finma.ch/de/dokumentation/rundschreiben/","herausgeber":"Eidgenössische Finanzmarktaufsicht (FINMA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/finma_rundschreiben","sprache":"en"}
{"id":"en/finma_rundschreiben#fragen","norm":"finma_rundschreiben","norm_name":"FINMA Circular 2023/1 \"Operational risks and resilience – banks\"","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Is this circular already part of the public regulatory check on sacosi.ch?**\nNo. Per the client's architecture decision, it is a candidate: there is no separate 'Finance' industry on the website yet, and inclusion is an open decision (see ARCHITEKTUR-UND-CONTENT.md, item 13).\n\n**Why does the information come from secondary sources instead of directly from finma.ch?**\nThe FINMA website loads its circular overview dynamically via JavaScript/AJAX; direct full-text access was not technically possible with the tools available in this research. Before any external publication of this file, the exact wording should be checked on finma.ch.","quellen":[{"titel":"FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)","url":"https://www.sidd.swiss/einblicke/finma-dora-leitfaden/","herausgeber":"SIDD Swiss (Beratungsunternehmen, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)","url":"https://www.finma.ch/de/dokumentation/rundschreiben/","herausgeber":"Eidgenössische Finanzmarktaufsicht (FINMA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/finma_rundschreiben","sprache":"en"}
{"id":"en/finma_rundschreiben#unsicher","norm":"finma_rundschreiben","norm_name":"FINMA Circular 2023/1 \"Operational risks and resilience – banks\"","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- CANDIDATE STATUS: as with DORA, per the client's architecture decision this circular has not yet been adopted into the website; no 'Finance' industry page exists. Applicability to individual CH companies has not been conclusively clarified (ARCHITEKTUR-UND-CONTENT.md, item 13).\n- The exact title 'Operational risks and resilience – banks', the entry-into-force date (1 January 2024) and the substantive key points come from a single secondary source (a consultancy), not from the circular itself on finma.ch. The FINMA circular overview page (https://www.finma.ch/de/dokumentation/rundschreiben/) was reached and confirms the general system of circulars, but delivers the specific list of current circulars only via a dynamic programming interface not readable in this research.\n- The statement on an analogous circular for insurers (Circular 2017/02) was not verified.\n- Whether the wording given in the brief, 'Operating risks and resilience – banks', or the wording found here, 'Operational risks and resilience – banks', is the correct official title must be checked directly on finma.ch before publication.","quellen":[{"titel":"FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)","url":"https://www.sidd.swiss/einblicke/finma-dora-leitfaden/","herausgeber":"SIDD Swiss (Beratungsunternehmen, Sekundärquelle)","abgerufen":"2026-09-24"},{"titel":"Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)","url":"https://www.finma.ch/de/dokumentation/rundschreiben/","herausgeber":"Eidgenössische Finanzmarktaufsicht (FINMA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/finma_rundschreiben","sprache":"en"}
{"id":"en/dsgvo#kurzantwort","norm":"dsgvo","norm_name":"General Data Protection Regulation","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"The EU General Data Protection Regulation (Regulation (EU) 2016/679) has applied since 25 May 2018 and governs the processing of personal data in the EU. Under the market-location principle in Article 3(2), it also covers Swiss companies that offer goods or services to people in the EU or monitor their behaviour - regardless of their own registered seat. Anyone covered generally has to appoint a representative in the EU under Article 27.","quellen":[{"titel":"Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/27.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/3.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/83.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dsgvo","sprache":"en"}
{"id":"en/dsgvo#wann_gilt","norm":"dsgvo","norm_name":"General Data Protection Regulation","abschnitt":"wann_gilt","ueberschrift":"When does GDPR apply to you?","text":"- Markets: EU (only together with industry or activity) (Recommend individual review): You state that you are active in the EU market - under Art. 3 GDPR, either an EU establishment is sufficient (Art. 3(1)) or, without an EU establishment, that you specifically offer goods or services to people in the EU or monitor their behaviour (Art. 3(2)). Whether there is deliberate targeting of the market or an occasional one-off sale without any GDPR relevance cannot be conclusively assessed from the market information alone and needs to be checked case by case.\n- Activity: Customers’ personal data (applies if additionally: Markets: EU) (Recommend individual review): You process personal data of customers and are active in the EU market - if this includes people in the EU to whom you specifically offer goods or services, or whose behaviour you monitor, the GDPR applies in addition to the FADP (Art. 3(2)). Without any EU market relevance, only the FADP obligations remain.\n- Activity: Special category personal data (applies if additionally: Markets: EU) (Recommend individual review): You process special categories of personal data, for instance health data, and are active in the EU market - if this also concerns people in the EU, the GDPR's stricter requirements for precisely these data categories apply in addition to the FADP. Without any EU market relevance, only the FADP obligations remain.","quellen":[{"titel":"Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/27.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/3.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/83.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dsgvo","sprache":"en"}
{"id":"en/dsgvo#ausnahmen","norm":"dsgvo","norm_name":"General Data Protection Regulation","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- The obligation to appoint a representative under Art. 27 does not apply if the processing is only occasional, does not include special categories of data (Art. 9) or data relating to criminal convictions (Art. 10) to any significant extent, and, taking into account the nature, scope and purpose of the processing, is unlikely to result in a risk to the rights and freedoms of data subjects (Art. 27(2)(a) GDPR).\n- The obligation to appoint a representative does not apply to public authorities and bodies (Art. 27(2)(b) GDPR).\n- Purely B2B offerings with no connection to natural persons in the EU do not trigger Art. 3(2) GDPR, as long as no personal data of people in the EU is processed.","quellen":[{"titel":"Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/27.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/3.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/83.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dsgvo","sprache":"en"}
{"id":"en/dsgvo#pflichten","norm":"dsgvo","norm_name":"General Data Protection Regulation","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Be able to demonstrate a legal basis for every processing of personal data (Art. 6 GDPR).\n- Maintain a record of processing activities, unless an exemption applies (Art. 30 GDPR).\n- Be able to fulfil data subject rights: access, rectification, erasure, objection, data portability (Art. 12-22 GDPR).\n- Carry out a data protection impact assessment where processing is likely to result in a high risk (Art. 35 GDPR).\n- Report personal data breaches to the supervisory authority within 72 hours, and notify data subjects where required (Art. 33-34 GDPR).\n- Where Art. 3(2) applies: appoint in writing a representative in the EU, established in a member state where data subjects are located (Art. 27(1) and (3) GDPR).","quellen":[{"titel":"Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/27.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/3.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/83.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dsgvo","sprache":"en"}
{"id":"en/dsgvo#nachweise","norm":"dsgvo","norm_name":"General Data Protection Regulation","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Record of processing activities (Art. 30).\n- Documented legal bases and consents.\n- Data processing agreements with providers (Art. 28).\n- Evidence of the representative's appointment under Art. 27 (contact details, written appointment), where applicable.\n- Data protection impact assessments, where carried out.","quellen":[{"titel":"Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/27.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/3.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/83.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dsgvo","sprache":"en"}
{"id":"en/dsgvo#fristen","norm":"dsgvo","norm_name":"General Data Protection Regulation","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 25 May 2018: The GDPR becomes applicable across the entire EU.","quellen":[{"titel":"Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/27.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/3.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/83.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dsgvo","sprache":"en"}
{"id":"en/dsgvo#sanktionen","norm":"dsgvo","norm_name":"General Data Protection Regulation","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"Fines under Art. 83 GDPR: up to EUR 10 million or 2% of total worldwide annual turnover of the preceding financial year for breaches under Art. 83(4) (e.g. against obligations on data processing or representative appointment), and up to EUR 20 million or 4% of total worldwide annual turnover for more serious breaches under Art. 83(5) (e.g. against basic processing principles, data subject rights, international data transfers) - whichever amount is higher.","quellen":[{"titel":"Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/27.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/3.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/83.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dsgvo","sprache":"en"}
{"id":"en/dsgvo#fragen","norm":"dsgvo","norm_name":"General Data Protection Regulation","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Does a Swiss company without an EU establishment always need an EU representative?**\nNo. The obligation under Art. 27 GDPR does not apply if the processing concerned is only occasional, does not concern special categories of data to any significant extent, and is unlikely to result in a risk to the rights and freedoms of data subjects, or if it concerns a public authority (Art. 27(2) GDPR).\n\n**Does the GDPR apply to a Swiss company that only occasionally sells goods to Germany?**\nWhat matters is not the individual export sale, but whether you specifically offer goods or services to people in the EU or monitor their behaviour (Art. 3(2) GDPR). An occasional sale without deliberate market targeting generally does not suffice for this.\n\n**How does the GDPR differ from the revised Swiss Federal Act on Data Protection (FADP)?**\nBoth frameworks are structurally similar but differ in the level of fines, competent authorities and detailed requirements. Swiss companies with EU relevance under Art. 3(2) GDPR generally have to comply with both frameworks in parallel; see the separate norm file revdsg.","quellen":[{"titel":"Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/27.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/3.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/83.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dsgvo","sprache":"en"}
{"id":"en/dsgvo#unsicher","norm":"dsgvo","norm_name":"General Data Protection Regulation","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The EUR-Lex primary text (eur-lex.europa.eu/eli/reg/2016/679/oj, also in the form legal-content/DE/TXT/... and .../PDF/...) was not retrievable in this session (empty or blocked response); the article wording was instead verified via the mirror dejure.org, not via the EDPB or EUR-Lex itself.\n- Whether and under what conditions individual Swiss bodies count as a 'public authority' within the meaning of Art. 27(2)(b) GDPR was not examined in depth.","quellen":[{"titel":"Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/27.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/3.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"},{"titel":"Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)","url":"https://dejure.org/gesetze/DSGVO/83.html","herausgeber":"dejure.org","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/dsgvo","sprache":"en"}
{"id":"en/gebuev_or#kurzantwort","norm":"gebuev_or","norm_name":"Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"Anyone obliged to keep accounts under Art. 957 CO must retain business books, accounting records, the annual report and the auditor's report for ten years; the period begins at the end of the financial year (Art. 958f CO - checked in the wording). Retention on paper, electronically or in a comparable form is permitted, provided that conformity with the underlying business transactions is guaranteed and the records can be made legible again at any time. The details of keeping and retention are set out by the Federal Council, based on Art. 958f(4) CO, in the Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431).","quellen":[{"titel":"Bundesgesetz betreffend die Ergänzung des Schweizerischen Zivilgesetzbuches (Fünfter Teil: Obligationenrecht), SR 220 – konsolidierte Fassung, Art. 957, 957a, 958f","url":"https://www.fedlex.admin.ch/eli/cc/27/317_321_377/de","herausgeber":"Bundeskanzlei / Fedlex, Systematische Rechtssammlung des Bundes","abgerufen":"2026-09-24"},{"titel":"Geschäftsbücherverordnung (GeBüV) – Übersichtsartikel (SR-Nummer, Erlassdatum, Struktur der Verordnung)","url":"https://de.wikipedia.org/wiki/Gesch%C3%A4ftsb%C3%BCcherverordnung","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gebuev_or","sprache":"en"}
{"id":"en/gebuev_or#wann_gilt","norm":"gebuev_or","norm_name":"Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts)","abschnitt":"wann_gilt","ueberschrift":"When does GeBüV / CO accounting apply to you?","text":"- Markets: Switzerland (applies if additionally: Markets: Switzerland) (Applies): If you keep your business books in Switzerland, you are subject - provided you are obliged to keep accounts under Art. 957 CO - to the retention obligations under the CO and the GeBüV.","quellen":[{"titel":"Bundesgesetz betreffend die Ergänzung des Schweizerischen Zivilgesetzbuches (Fünfter Teil: Obligationenrecht), SR 220 – konsolidierte Fassung, Art. 957, 957a, 958f","url":"https://www.fedlex.admin.ch/eli/cc/27/317_321_377/de","herausgeber":"Bundeskanzlei / Fedlex, Systematische Rechtssammlung des Bundes","abgerufen":"2026-09-24"},{"titel":"Geschäftsbücherverordnung (GeBüV) – Übersichtsartikel (SR-Nummer, Erlassdatum, Struktur der Verordnung)","url":"https://de.wikipedia.org/wiki/Gesch%C3%A4ftsb%C3%BCcherverordnung","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gebuev_or","sprache":"en"}
{"id":"en/gebuev_or#ausnahmen","norm":"gebuev_or","norm_name":"Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Sole proprietorships and partnerships with revenue of less than CHF 500,000 in the last financial year only need to keep simplified accounts of income, expenses and assets ('milk-book accounting') under Art. 957(2) CO; the full accounting rules apply by analogy. This revenue threshold cannot be directly mapped with the regulatory check's 'groesse' input field (number of employees).\n- Associations and foundations not required to be entered in the commercial register, as well as foundations exempted from the audit requirement under Art. 83b(2) CC, are likewise subject only to the simplified accounting obligation under Art. 957(2) CO.","quellen":[{"titel":"Bundesgesetz betreffend die Ergänzung des Schweizerischen Zivilgesetzbuches (Fünfter Teil: Obligationenrecht), SR 220 – konsolidierte Fassung, Art. 957, 957a, 958f","url":"https://www.fedlex.admin.ch/eli/cc/27/317_321_377/de","herausgeber":"Bundeskanzlei / Fedlex, Systematische Rechtssammlung des Bundes","abgerufen":"2026-09-24"},{"titel":"Geschäftsbücherverordnung (GeBüV) – Übersichtsartikel (SR-Nummer, Erlassdatum, Struktur der Verordnung)","url":"https://de.wikipedia.org/wiki/Gesch%C3%A4ftsb%C3%BCcherverordnung","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gebuev_or","sprache":"en"}
{"id":"en/gebuev_or#pflichten","norm":"gebuev_or","norm_name":"Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Keep accounts in accordance with the principles of proper accounting: complete, accurate and systematic recording of business transactions, documentary evidence for every entry, clarity, appropriateness and verifiability (Art. 957a CO).\n- Retain business books, accounting records, the annual report and the auditor's report for ten years; the period begins at the end of the financial year (Art. 958f(1) CO).\n- The annual report and the auditor's report must be retained in writing and signed (Art. 958f(2) CO).\n- Business books and accounting records may be retained on paper, electronically or in a comparable manner, provided that conformity with the underlying business transactions and facts is guaranteed and the records can be made legible again at any time (Art. 958f(3) CO).\n- Any written record on paper, electronically or in a comparable form that is needed to trace the underlying business transaction counts as an accounting record (Art. 957a(3) CO).","quellen":[{"titel":"Bundesgesetz betreffend die Ergänzung des Schweizerischen Zivilgesetzbuches (Fünfter Teil: Obligationenrecht), SR 220 – konsolidierte Fassung, Art. 957, 957a, 958f","url":"https://www.fedlex.admin.ch/eli/cc/27/317_321_377/de","herausgeber":"Bundeskanzlei / Fedlex, Systematische Rechtssammlung des Bundes","abgerufen":"2026-09-24"},{"titel":"Geschäftsbücherverordnung (GeBüV) – Übersichtsartikel (SR-Nummer, Erlassdatum, Struktur der Verordnung)","url":"https://de.wikipedia.org/wiki/Gesch%C3%A4ftsb%C3%BCcherverordnung","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gebuev_or","sprache":"en"}
{"id":"en/gebuev_or#nachweise","norm":"gebuev_or","norm_name":"Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Complete documentary records with traceability of every entry.\n- Demonstrable retention over the full ten-year period from the end of the relevant financial year.\n- For electronic retention: evidence of conformity with the original transactions and the ability to make records legible at any time - the specific technical requirements (traceability, integrity, availability) are set out in the GeBüV; the GeBüV ordinance text itself could not be technically retrieved in full text in this research, so the principles are evidenced only via a secondary source (a Wikipedia summary) and noted under 'unsicher'.","quellen":[{"titel":"Bundesgesetz betreffend die Ergänzung des Schweizerischen Zivilgesetzbuches (Fünfter Teil: Obligationenrecht), SR 220 – konsolidierte Fassung, Art. 957, 957a, 958f","url":"https://www.fedlex.admin.ch/eli/cc/27/317_321_377/de","herausgeber":"Bundeskanzlei / Fedlex, Systematische Rechtssammlung des Bundes","abgerufen":"2026-09-24"},{"titel":"Geschäftsbücherverordnung (GeBüV) – Übersichtsartikel (SR-Nummer, Erlassdatum, Struktur der Verordnung)","url":"https://de.wikipedia.org/wiki/Gesch%C3%A4ftsb%C3%BCcherverordnung","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gebuev_or","sprache":"en"}
{"id":"en/gebuev_or#sanktionen","norm":"gebuev_or","norm_name":"Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"A breach of the duty to keep accounts or retain records can carry criminal consequences (e.g. in case of bankruptcy); the exact wording of the relevant penal provision was not examined in full text in this research and is therefore not cited with an article number. Under civil law, deficient accounting can also considerably worsen a company's evidentiary position (e.g. in disputes or a tax audit).","quellen":[{"titel":"Bundesgesetz betreffend die Ergänzung des Schweizerischen Zivilgesetzbuches (Fünfter Teil: Obligationenrecht), SR 220 – konsolidierte Fassung, Art. 957, 957a, 958f","url":"https://www.fedlex.admin.ch/eli/cc/27/317_321_377/de","herausgeber":"Bundeskanzlei / Fedlex, Systematische Rechtssammlung des Bundes","abgerufen":"2026-09-24"},{"titel":"Geschäftsbücherverordnung (GeBüV) – Übersichtsartikel (SR-Nummer, Erlassdatum, Struktur der Verordnung)","url":"https://de.wikipedia.org/wiki/Gesch%C3%A4ftsb%C3%BCcherverordnung","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gebuev_or","sprache":"en"}
{"id":"en/gebuev_or#fragen","norm":"gebuev_or","norm_name":"Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Is purely electronic retention sufficient, or do I also need paper?**\nBusiness books and accounting records may, per Art. 958f(3) CO, be retained on paper, electronically or in a comparable manner - there is no paper requirement for this. The annual report and the auditor's report, however, must be retained in writing and signed, per Art. 958f(2) CO.\n\n**From when does the ten-year period run?**\nThe retention period begins at the end of the financial year to which the records relate (Art. 958f(1) CO).\n\n**Where do I find the detailed technical requirements for electronic retention?**\nThese are set out by the Federal Council, based on Art. 958f(4) CO, in the Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431). The GeBüV text itself was not technically retrievable in full text in this research; it should be consulted directly before making a binding statement on specific requirements.","quellen":[{"titel":"Bundesgesetz betreffend die Ergänzung des Schweizerischen Zivilgesetzbuches (Fünfter Teil: Obligationenrecht), SR 220 – konsolidierte Fassung, Art. 957, 957a, 958f","url":"https://www.fedlex.admin.ch/eli/cc/27/317_321_377/de","herausgeber":"Bundeskanzlei / Fedlex, Systematische Rechtssammlung des Bundes","abgerufen":"2026-09-24"},{"titel":"Geschäftsbücherverordnung (GeBüV) – Übersichtsartikel (SR-Nummer, Erlassdatum, Struktur der Verordnung)","url":"https://de.wikipedia.org/wiki/Gesch%C3%A4ftsb%C3%BCcherverordnung","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gebuev_or","sprache":"en"}
{"id":"en/gebuev_or#unsicher","norm":"gebuev_or","norm_name":"Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The ordinance text of the Ordinance on the Keeping and Retention of Accounting Records itself (SR 221.431) could not be technically retrieved in full text from fedlex.admin.ch in this research (the page requires JavaScript; several direct document download paths were checked without success). All statements on the GeBüV's content come from a Wikipedia summary (SR number 221.431, enactment date 24 April 2002, entry into force 1 June 2002, last major amendment 1 January 2013) and are marked as secondary accordingly.\n- Specific GeBüV article numbers on the traceability, integrity and availability of electronic retention were NOT verified in the ordinance's text and are therefore deliberately not cited with an article number.\n- The revenue threshold of CHF 500,000 (Art. 957(2) CO) cannot be mapped in the regulatory check's vocabulary, since the 'groesse' field captures the number of employees, not revenue - a trigger based on the revenue threshold was therefore deliberately not formulated.\n- The exact criminal sanction provision for breach of the accounting duty was not examined in full text and is therefore described without an article number.","quellen":[{"titel":"Bundesgesetz betreffend die Ergänzung des Schweizerischen Zivilgesetzbuches (Fünfter Teil: Obligationenrecht), SR 220 – konsolidierte Fassung, Art. 957, 957a, 958f","url":"https://www.fedlex.admin.ch/eli/cc/27/317_321_377/de","herausgeber":"Bundeskanzlei / Fedlex, Systematische Rechtssammlung des Bundes","abgerufen":"2026-09-24"},{"titel":"Geschäftsbücherverordnung (GeBüV) – Übersichtsartikel (SR-Nummer, Erlassdatum, Struktur der Verordnung)","url":"https://de.wikipedia.org/wiki/Gesch%C3%A4ftsb%C3%BCcherverordnung","herausgeber":"Wikipedia (Sekundärquelle, nicht die Verordnung selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gebuev_or","sprache":"en"}
{"id":"en/gobd#kurzantwort","norm":"gobd","norm_name":"Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"The GoBD is an administrative circular of the German Federal Ministry of Finance (BMF) that sets out in detail how books, records and electronic documents are to be kept properly, recorded immutably and retained under the Fiscal Code (Sections 146 f. AO), together with requirements on procedural documentation and the tax authorities' data access. It is relevant to you if you are obliged to keep books or records in Germany - for example via a German subsidiary, permanent establishment or your own business activity in Germany. Retention periods under Section 147 AO were checked in full text: 10 years for books, records, inventories, annual financial statements and customs documents, 8 years for accounting records, 6 years for commercial and business correspondence.","quellen":[{"titel":"§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen","url":"https://www.gesetze-im-internet.de/ao_1977/__146.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen","url":"https://www.gesetze-im-internet.de/ao_1977/__147.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)","url":"https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff","herausgeber":"Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gobd","sprache":"en"}
{"id":"en/gobd#wann_gilt","norm":"gobd","norm_name":"Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD)","abschnitt":"wann_gilt","ueberschrift":"When does GoBD apply to you?","text":"- Markets: Germany (applies if additionally: Markets: Germany) (Likely applies): If you conduct business in Germany - for example through a German subsidiary or permanent establishment - you must align your electronic bookkeeping and retention with the GoBD and Sections 146 f. AO.","quellen":[{"titel":"§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen","url":"https://www.gesetze-im-internet.de/ao_1977/__146.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen","url":"https://www.gesetze-im-internet.de/ao_1977/__147.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)","url":"https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff","herausgeber":"Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gobd","sprache":"en"}
{"id":"en/gobd#ausnahmen","norm":"gobd","norm_name":"Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Per a secondary source, the GoBD is addressed to everyone obliged to keep books or records under German tax law - not only to companies obliged to keep accounts under commercial law in the classic sense. The exact scope of addressees was not examined in the BMF circular itself, only via a secondary source.\n- Whether and to what extent a Swiss company without a German permanent establishment or subsidiary can be affected (e.g. when registering for German VAT purposes) was not clarified in this research.","quellen":[{"titel":"§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen","url":"https://www.gesetze-im-internet.de/ao_1977/__146.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen","url":"https://www.gesetze-im-internet.de/ao_1977/__147.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)","url":"https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff","herausgeber":"Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gobd","sprache":"en"}
{"id":"en/gobd#pflichten","norm":"gobd","norm_name":"Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Individual, complete, accurate, timely and orderly recording of entries and other required records; for cash register systems, ongoing (typically daily) cash records are required (Section 146(1) AO, checked in full text).\n- Immutability: changes to entries or records may not be made in a way that the original content is no longer ascertainable; ambiguous changes in substance are also inadmissible (Section 146(4) AO, checked in full text).\n- For electronic storage: data must be available at all times during the entire retention period and be made legible without delay (Section 146(5) AO, checked in full text); under Section 147(2) AO, electronic documents subject to retention must additionally be machine-evaluable (checked in full text).\n- Relocating electronic bookkeeping abroad: permissible within the EU, provided the tax authority's data access is guaranteed; in third countries only with written approval of the tax authority under further conditions (Section 146(2a) f. AO, checked in full text).\n- Retention under Section 147(1) AO: books, records, inventories, annual financial statements and management reports as well as customs documents for 10 years; accounting records for 8 years; commercial or business correspondence received and sent, and other documents, for 6 years (checked in full text).\n- Start of the period under Section 147(4) AO: at the end of the calendar year in which the last entry was made in the book or record (checked in full text).\n- Maintain procedural documentation that makes the GoBD-compliant course of data processing traceable (per secondary sources, a core GoBD component; not examined in full text in the BMF circular itself).\n- Enable the tax authority's data access as part of a field audit, including machine evaluation or provision in evaluable formats (Section 147(6) AO, checked in full text).","quellen":[{"titel":"§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen","url":"https://www.gesetze-im-internet.de/ao_1977/__146.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen","url":"https://www.gesetze-im-internet.de/ao_1977/__147.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)","url":"https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff","herausgeber":"Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gobd","sprache":"en"}
{"id":"en/gobd#nachweise","norm":"gobd","norm_name":"Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Procedural documentation on the IT systems and processes used (content not examined in full text in the BMF circular).\n- Evidence of the immutability of electronic records (e.g. via audit-proof archiving systems).\n- Complete documentary records retained within the deadlines under Section 147(1) and (3) AO.\n- Readiness for the tax authority's data access (Z1 direct access, Z2 indirect access, Z3 provision of data carriers) - these types of access are generally known GoBD terminology but were not verified in the BMF circular itself in full text in this research and are therefore noted under 'unsicher'.","quellen":[{"titel":"§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen","url":"https://www.gesetze-im-internet.de/ao_1977/__146.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen","url":"https://www.gesetze-im-internet.de/ao_1977/__147.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)","url":"https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff","herausgeber":"Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gobd","sprache":"en"}
{"id":"en/gobd#fristen","norm":"gobd","norm_name":"Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 28 November 2019: Revised version of the GoBD circular (reference number per a secondary source IV A 4 - S 0316/19/10003), in force from 1 January 2020 - date verified not in the BMF circular itself but only via a secondary source (Wikipedia).\n- 11 March 2024: First known amendment of the GoBD circular (reference number per a secondary source IV D 2 - S 0316/21/10001:002) - not verified in the BMF circular itself.\n- 14 July 2025: Further amendment, per a secondary source with a focus on electronic invoices - not verified in the BMF circular itself.","quellen":[{"titel":"§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen","url":"https://www.gesetze-im-internet.de/ao_1977/__146.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen","url":"https://www.gesetze-im-internet.de/ao_1977/__147.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)","url":"https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff","herausgeber":"Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gobd","sprache":"en"}
{"id":"en/gobd#sanktionen","norm":"gobd","norm_name":"Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"Checked in full text is the sanction under Section 146(2c) AO: for breaches of the requirements on relocating electronic bookkeeping abroad, the tax authority can impose a delay penalty of EUR 2,500 to 250,000. Further consequences of improper bookkeeping (e.g. estimation of the tax base) are possible under the general understanding of German tax law, but were not verified in the statutory text (e.g. Section 162 AO) in this research and are therefore noted under 'unsicher'.","quellen":[{"titel":"§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen","url":"https://www.gesetze-im-internet.de/ao_1977/__146.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen","url":"https://www.gesetze-im-internet.de/ao_1977/__147.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)","url":"https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff","herausgeber":"Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gobd","sprache":"en"}
{"id":"en/gobd#fragen","norm":"gobd","norm_name":"Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Does the GoBD also apply to our Swiss parent company, or only to the German subsidiary?**\nThe GoBD is tied to the German duty to keep books and records under Sections 146 f. AO. For a purely Swiss parent company without a German permanent establishment or subsidiary, applicability was not clarified in this research; what generally matters is the tax liability of the respective German entity.\n\n**How long do I have to retain accounting records in Germany - 10 years as in Switzerland?**\nNo, not identical: under Section 147(1) AO, a period of 8 years applies to accounting records in Germany, while books and records themselves must be retained for 10 years. This differs from the Swiss rule under Art. 958f CO, where a uniform 10-year period applies to business books and accounting records (see the norm file gebuev_or).\n\n**Is electronic archiving sufficient if the accounting runs abroad?**\nWithin the EU, relocating electronic bookkeeping is permissible provided the German tax authority's data access remains guaranteed. For third countries such as Switzerland, prior written approval of the tax authority is required under Section 146(2a) AO, combined with further conditions.","quellen":[{"titel":"§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen","url":"https://www.gesetze-im-internet.de/ao_1977/__146.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen","url":"https://www.gesetze-im-internet.de/ao_1977/__147.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)","url":"https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff","herausgeber":"Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gobd","sprache":"en"}
{"id":"en/gobd#unsicher","norm":"gobd","norm_name":"Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The actual BMF circular on the GoBD (full text) could not be technically retrieved in this research: bundesfinanzministerium.de is protected by a bot-management system (Radware/perfdrive) that blocks automated access; archived Wayback Machine copies also returned only 404 error pages. All statements on procedural documentation, the types of data access (Z1/Z2/Z3) and the exact reference numbers/dates of the amendment circulars come from a single secondary source (Wikipedia) and are marked accordingly.\n- The existence and content of the data access types Z1 (direct access), Z2 (indirect access) and Z3 (provision of data carriers) are generally known GoBD terminology but were not verified in the BMF circular itself in this research.\n- Whether an even more current version exists beyond the three amendment circulars named (2019, 2024, 2025) was not examined.\n- Sanction consequences for improper bookkeeping beyond the Section 146(2c) AO provision checked in full text (e.g. the power of estimation under Section 162 AO) were not verified.","quellen":[{"titel":"§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen","url":"https://www.gesetze-im-internet.de/ao_1977/__146.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen","url":"https://www.gesetze-im-internet.de/ao_1977/__147.html","herausgeber":"Bundesministerium der Justiz / gesetze-im-internet.de","abgerufen":"2026-09-24"},{"titel":"GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)","url":"https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff","herausgeber":"Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/gobd","sprache":"en"}
{"id":"en/ikt_minimalstandard_stromvv#kurzantwort","norm":"ikt_minimalstandard_stromvv","norm_name":"ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"Since 1 July 2024, the recommendations of the Minimum Standard for Improving ICT Resilience (ICT Minimum Standard, May 2023 edition) have been binding, per the respective protection level under Annex 1a, under Art. 5a of the Electricity Supply Ordinance (StromVV, SR 734.71) for grid operators, for generators and storage operators with a total of 100 MW or more of controllable capacity via a single system, and for service providers able to permanently remote-control such installations. The Swiss Federal Electricity Commission (ElCom) can demand proof of the protection level being reached at any time.","quellen":[{"titel":"Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)","url":"https://www.fedlex.admin.ch/eli/oc/2024/282/de","herausgeber":"Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71)","abgerufen":"2026-09-24"},{"titel":"IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario","url":"https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv","herausgeber":"InfoGuard AG (Fachartikel)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ikt_minimalstandard_stromvv","sprache":"en"}
{"id":"en/ikt_minimalstandard_stromvv#wann_gilt","norm":"ikt_minimalstandard_stromvv","norm_name":"ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a)","abschnitt":"wann_gilt","ueberschrift":"When does ICT Minimum Standard (StromVV) apply to you?","text":"- Industry: Energy (Likely applies): As a company in the energy industry, you are in principle a candidate as a grid operator, generator or storage operator under Art. 5a StromVV - whether you are specifically covered depends on your role and, for generation or storage, on the 100 MW threshold of controllable installed capacity.\n- Activity: Critical infrastructure (applies if additionally: Industry: Energy) (Likely applies): As an energy company, you count among critical infrastructure - in the energy sector, Art. 5a StromVV precisely narrows the circle of those obliged to grid operators, larger generators/storage operators of 100 MW or more, and their remote-control service providers; check whether you fall into one of these three categories. Critical infrastructure outside the energy industry does not fall under this ordinance.\n- Activity: Operational technology (OT plant) (applies if additionally: Industry: Energy) (Likely applies): You operate or control OT installations (operational technology) in the energy sector - if these serve electricity generation, storage or grid operation, or you can permanently remote-control such installations for third parties, the ICT Minimum Standard under Art. 5a StromVV may apply to you. OT installations outside the energy industry are not covered.\n- Role towards customers: Operator (applies if additionally: Industry: Energy) (Recommend individual review): As the operator of an installation in the energy sector, you should check case by case whether you fall under one of the three categories named in Art. 5a(1) StromVV: grid operator, generator/storage operator with 100 MW or more (except nuclear power plants), or a service provider with permanent remote-control access to such installations.","quellen":[{"titel":"Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)","url":"https://www.fedlex.admin.ch/eli/oc/2024/282/de","herausgeber":"Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71)","abgerufen":"2026-09-24"},{"titel":"IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario","url":"https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv","herausgeber":"InfoGuard AG (Fachartikel)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ikt_minimalstandard_stromvv","sprache":"en"}
{"id":"en/ikt_minimalstandard_stromvv#ausnahmen","norm":"ikt_minimalstandard_stromvv","norm_name":"ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Operators of nuclear power plants are expressly exempted from the obligations for generators under Art. 5a(1)(b) StromVV; they are subject to their own nuclear-energy-law safety requirements.\n- Generators and storage operators whose installations together have less than 100 MW of capacity, or which cannot be controlled via a single system, are not covered under Art. 5a(1)(b) StromVV.\n- The internationally recognised standards named within the ICT Minimum Standard itself are not binding on their own (Art. 5a(2) StromVV); what is binding are the ICT Minimum Standard's recommendations, even where these refer to such standards.","quellen":[{"titel":"Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)","url":"https://www.fedlex.admin.ch/eli/oc/2024/282/de","herausgeber":"Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71)","abgerufen":"2026-09-24"},{"titel":"IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario","url":"https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv","herausgeber":"InfoGuard AG (Fachartikel)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ikt_minimalstandard_stromvv","sprache":"en"}
{"id":"en/ikt_minimalstandard_stromvv#pflichten","norm":"ikt_minimalstandard_stromvv","norm_name":"ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Implement the recommendations of the ICT Minimum Standard (May 2023 edition) according to the protection level assigned to one's own role or installation under Annex 1a StromVV (Art. 5a(1) StromVV).\n- Demonstrate to ElCom, on request, that the respective protection level has been reached (Art. 5a(3) StromVV).","quellen":[{"titel":"Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)","url":"https://www.fedlex.admin.ch/eli/oc/2024/282/de","herausgeber":"Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71)","abgerufen":"2026-09-24"},{"titel":"IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario","url":"https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv","herausgeber":"InfoGuard AG (Fachartikel)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ikt_minimalstandard_stromvv","sprache":"en"}
{"id":"en/ikt_minimalstandard_stromvv#nachweise","norm":"ikt_minimalstandard_stromvv","norm_name":"ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Evidence documentation on the protection level reached (A, B or C) towards ElCom.\n- Documentation of the implementation of the individual ICT Minimum Standard recommendations per assigned protection level (Annex 1a StromVV).","quellen":[{"titel":"Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)","url":"https://www.fedlex.admin.ch/eli/oc/2024/282/de","herausgeber":"Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71)","abgerufen":"2026-09-24"},{"titel":"IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario","url":"https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv","herausgeber":"InfoGuard AG (Fachartikel)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ikt_minimalstandard_stromvv","sprache":"en"}
{"id":"en/ikt_minimalstandard_stromvv#fristen","norm":"ikt_minimalstandard_stromvv","norm_name":"ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 1 July 2024: Art. 5a StromVV (protection against cyber threats / ICT Minimum Standard) enters into force (AS 2024 282).","quellen":[{"titel":"Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)","url":"https://www.fedlex.admin.ch/eli/oc/2024/282/de","herausgeber":"Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71)","abgerufen":"2026-09-24"},{"titel":"IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario","url":"https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv","herausgeber":"InfoGuard AG (Fachartikel)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ikt_minimalstandard_stromvv","sprache":"en"}
{"id":"en/ikt_minimalstandard_stromvv#sanktionen","norm":"ikt_minimalstandard_stromvv","norm_name":"ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"Art. 5a StromVV itself does not provide for a penalty provision of its own. ElCom can demand proof of the protection level being reached at any time (Art. 5a(3) StromVV) and order measures as part of its general supervisory and directive powers under the Electricity Supply Act (StromVG). A specifically quantified sanction provision for non-compliance with the ICT Minimum Standard could not be found in the ordinance text read (see unsicher).","quellen":[{"titel":"Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)","url":"https://www.fedlex.admin.ch/eli/oc/2024/282/de","herausgeber":"Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71)","abgerufen":"2026-09-24"},{"titel":"IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario","url":"https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv","herausgeber":"InfoGuard AG (Fachartikel)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ikt_minimalstandard_stromvv","sprache":"en"}
{"id":"en/ikt_minimalstandard_stromvv#fragen","norm":"ikt_minimalstandard_stromvv","norm_name":"ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**What exactly is the ICT Minimum Standard?**\nA catalogue of recommendations for improving ICT resilience (May 2023 edition). Per the footnote to Art. 5a StromVV, it is available free of charge from the Federal Office for National Economic Supply (FONES) via www.bwl.admin.ch or by email to info@bwl.admin.ch. Art. 5a StromVV declares its recommendations binding for certain electricity-supply actors, depending on the protection level.\n\n**Who determines which protection level (A, B, C) applies to my company?**\nThe assignment is made under Annex 1a StromVV. The exact assignment criteria were not examined in the full text of Annex 1a in this research; only the general three-tier structure is known from a professional source (see unsicher).\n\n**Is the ICT Minimum Standard the same as an NCSC document?**\nNo. The ordinance text itself (footnote 27 to Art. 5a StromVV) refers to the Federal Office for National Economic Supply (FONES) as the source, not to the NCSC/BACS. This attribution, taken directly from the ordinance's text, differs from an originally assumed NCSC responsibility.","quellen":[{"titel":"Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)","url":"https://www.fedlex.admin.ch/eli/oc/2024/282/de","herausgeber":"Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71)","abgerufen":"2026-09-24"},{"titel":"IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario","url":"https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv","herausgeber":"InfoGuard AG (Fachartikel)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ikt_minimalstandard_stromvv","sprache":"en"}
{"id":"en/ikt_minimalstandard_stromvv#unsicher","norm":"ikt_minimalstandard_stromvv","norm_name":"ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The exact assignment criteria for protection levels A, B and C to individual company categories (Annex 1a StromVV) were not read in full text; the classification 'A = most important companies, B = medium-sized, C = smaller actors' comes from a professional article (InfoGuard, secondary), not directly from the ordinance's text.\n- Per the footnote to Art. 5a StromVV, the ICT Minimum Standard is obtained via the Federal Office for National Economic Supply (FONES, www.bwl.admin.ch); a responsibility of ncsc.admin.ch for this specific document was not confirmed in this research.\n- A specific sanction provision for breaches of Art. 5a StromVV was not found; whether and how ElCom sanctions breaches case by case (e.g. based on the StromVG) was not researched.","quellen":[{"titel":"Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)","url":"https://www.fedlex.admin.ch/eli/oc/2024/282/de","herausgeber":"Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71)","abgerufen":"2026-09-24"},{"titel":"IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario","url":"https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv","herausgeber":"InfoGuard AG (Fachartikel)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/ikt_minimalstandard_stromvv","sprache":"en"}
{"id":"en/iec62304#kurzantwort","norm":"iec62304","norm_name":"IEC 62304 – Medical device software – Software life cycle processes","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"IEC 62304 sets out how you must safely develop and maintain software for medical devices across the entire life cycle - planning, requirements, architecture, implementation, verification, release, maintenance. It assigns your software to one of three safety classes (A, B or C) based on the risk to patients, users or third parties and, as the recognised 'state of the art', is the accepted basis for meeting the software requirements of the EU MDR and the Swiss MedDO.","quellen":[{"titel":"IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes","url":"https://webstore.iec.ch/","herausgeber":"International Electrotechnical Commission (IEC)","abgerufen":"2026-09-24"},{"titel":"IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)","url":"https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62304","sprache":"en"}
{"id":"en/iec62304#wann_gilt","norm":"iec62304","norm_name":"IEC 62304 – Medical device software – Software life cycle processes","abschnitt":"wann_gilt","ueberschrift":"When does IEC 62304 apply to you?","text":"- Activity: Products with software (applies if additionally: Activity: Medical devices) (Likely applies): You develop products with software, including a medical device - if this software is part of the medical device or itself qualifies as a medical device, IEC 62304 prescribes the software life cycle process, including risk classification (A/B/C) and documentation obligations. For software outside medical devices, IEC 62304 does not apply.\n- Activity: Medical devices (Recommend individual review): IEC 62304 only applies to the extent your medical device contains software or is itself software - check whether this condition applies to your specific product.\n- Industry: MedTech (Recommend individual review): As a MedTech company with a software component in your products, IEC 62304 is highly likely to be relevant to you; without a specific software element in the product, the standard does not apply.","quellen":[{"titel":"IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes","url":"https://webstore.iec.ch/","herausgeber":"International Electrotechnical Commission (IEC)","abgerufen":"2026-09-24"},{"titel":"IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)","url":"https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62304","sprache":"en"}
{"id":"en/iec62304#ausnahmen","norm":"iec62304","norm_name":"IEC 62304 – Medical device software – Software life cycle processes","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Purely hardware medical devices with no software component fall outside the standard's scope.\n- For products already in the field classified as 'legacy software', adapted evidence requirements apply in practice (a retrospective approach), the exact criteria for which were not verified in this session.","quellen":[{"titel":"IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes","url":"https://webstore.iec.ch/","herausgeber":"International Electrotechnical Commission (IEC)","abgerufen":"2026-09-24"},{"titel":"IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)","url":"https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62304","sprache":"en"}
{"id":"en/iec62304#pflichten","norm":"iec62304","norm_name":"IEC 62304 – Medical device software – Software life cycle processes","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Determine the software safety class (A, B or C) on a risk basis before development begins, or again if the risk context changes.\n- Draw up a software development plan covering the processes of planning, requirements analysis, architectural design, detailed design, implementation, integration and system testing, and release.\n- Document requirements and architecture in a risk-oriented manner and link them to safety aspects and - increasingly, in revised practice - security aspects.\n- Operate configuration management and a problem-resolution process for the entire service life of the software, including after market launch (software maintenance process).\n- Scale verification and testing activities to the risk of the respective class; higher classes require more extensive evidence.","quellen":[{"titel":"IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes","url":"https://webstore.iec.ch/","herausgeber":"International Electrotechnical Commission (IEC)","abgerufen":"2026-09-24"},{"titel":"IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)","url":"https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62304","sprache":"en"}
{"id":"en/iec62304#nachweise","norm":"iec62304","norm_name":"IEC 62304 – Medical device software – Software life cycle processes","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Software development plan.\n- Software requirements specification and architecture documentation.\n- Evidence of verification, integration and system testing, class-dependent in each case.\n- Configuration management records.\n- Documented software maintenance and problem-resolution process.\n- As part of MDR/MedDO conformity assessment: embedding this evidence in the technical documentation of the overall product.","quellen":[{"titel":"IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes","url":"https://webstore.iec.ch/","herausgeber":"International Electrotechnical Commission (IEC)","abgerufen":"2026-09-24"},{"titel":"IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)","url":"https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62304","sprache":"en"}
{"id":"en/iec62304#sanktionen","norm":"iec62304","norm_name":"IEC 62304 – Medical device software – Software life cycle processes","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"IEC 62304 is a technical standard with no penalties of its own. Since it is used as the state of the art for the software requirements of the EU MDR and the Swiss MedDO, non-compliance in practice leads to audit findings, refusal of CE marking or Swissmedic authorisation, and, in the event of harm, a weaker position in product liability.","quellen":[{"titel":"IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes","url":"https://webstore.iec.ch/","herausgeber":"International Electrotechnical Commission (IEC)","abgerufen":"2026-09-24"},{"titel":"IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)","url":"https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62304","sprache":"en"}
{"id":"en/iec62304#fragen","norm":"iec62304","norm_name":"IEC 62304 – Medical device software – Software life cycle processes","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**What distinguishes safety classes A, B and C?**\nThe classification depends on the possible harm from a software failure: broadly, class A applies to software where no injury or damage to health is possible, class B to software where a non-serious injury is possible, and class C to software where death or serious injury is possible. The exact, standard-conformant definition of the three classes was not verified word-for-word from a source read in this session (see 'unsicher') and should be checked against the standard itself before any binding classification.\n\n**Is IEC 62304 alone sufficient for the conformity of our medical device software?**\nNo. IEC 62304 covers the software life cycle but does not replace the overarching risk management (for which ISO 14971 is the accepted basis in practice) or the quality management system under ISO 13485, into which the software processes must be embedded.\n\n**Is the currently valid version of IEC 62304 up to date?**\nThe most recently consolidated, internationally valid version is IEC 62304:2006 with Amendment 1:2015 (sometimes referred to as Edition 1.1). A second edition is, per secondary sources, in preparation but had not yet been published as of this research.","quellen":[{"titel":"IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes","url":"https://webstore.iec.ch/","herausgeber":"International Electrotechnical Commission (IEC)","abgerufen":"2026-09-24"},{"titel":"IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)","url":"https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62304","sprache":"en"}
{"id":"en/iec62304#unsicher","norm":"iec62304","norm_name":"IEC 62304 – Medical device software – Software life cycle processes","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The full text of IEC 62304 is paywalled and could not be read in this session; the specific catalogue/publication page on webstore.iec.ch also could not be reliably located (the search function only returns results via JavaScript, and guessed publication IDs led to incorrect, unrelated documents). The URL cited is the general IEC webstore homepage, not a verified direct page for IEC 62304.\n- The exact, standard-conformant wording defining safety classes A/B/C (in particular the phrasing 'no injury or damage to health', 'non-serious injury', 'death or serious injury') was not quoted word-for-word from a source read in this session, but reproduced from established professional knowledge. This should be checked against the standard's text before any binding classification as part of the regulatory check.\n- The exact status and expected publication date of a second IEC 62304 edition were only sketched via a secondary source (Johner Institut) and not verified; for current compliance practice, the 2006+AMD1:2015 version is authoritative regardless.\n- A specific Swissmedic reference to IEC 62304 (e.g. its own guideline) could not be found in this session (the presumed Swissmedic page on medical software returned HTTP 404).","quellen":[{"titel":"IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes","url":"https://webstore.iec.ch/","herausgeber":"International Electrotechnical Commission (IEC)","abgerufen":"2026-09-24"},{"titel":"IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)","url":"https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62304","sprache":"en"}
{"id":"en/iec62443#kurzantwort","norm":"iec62443","norm_name":"IEC 62443 — Industrial communication networks, network and system security","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"IEC 62443 is the international standards series for cybersecurity in industrial automation and control systems (OT/ICS). It is voluntary to apply but is increasingly used as an accepted benchmark for OT security, for example in the context of NIS2 implementation and the Cyber Resilience Act. The series distinguishes requirements for operators (Part 2-1), technical system requirements with four security levels (Part 3-3), and requirements for manufacturers of components (Parts 4-1 and 4-2); certification is possible but not uniformly mandated.","quellen":[{"titel":"IEC TS 62443-1-1:2009 — Terminology, concepts and models","url":"https://webstore.iec.ch/en/publication/7029","herausgeber":"IEC (International Electrotechnical Commission)","abgerufen":"2026-09-24"},{"titel":"IEC 62443","url":"https://en.wikipedia.org/wiki/IEC_62443","herausgeber":"Wikipedia (Übersichtsartikel)","abgerufen":"2026-09-24"},{"titel":"IEC 62443 Standard: Industrial Cybersecurity Framework Explained","url":"https://www.fortinet.com/resources/cyberglossary/iec-62443","herausgeber":"Fortinet","abgerufen":"2026-09-24"},{"titel":"What Are ISO/IEC 62443-4-1 and 62443-4-2?","url":"https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/","herausgeber":"Security Compass (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62443","sprache":"en"}
{"id":"en/iec62443#wann_gilt","norm":"iec62443","norm_name":"IEC 62443 — Industrial communication networks, network and system security","abschnitt":"wann_gilt","ueberschrift":"When does IEC 62443 apply to you?","text":"- Activity: Operational technology (OT plant) (Applies): Anyone operating operational technology (OT) or industrial control systems finds in IEC 62443 the internationally recognised framework for systematically building and demonstrating their cybersecurity.\n- Industry: Energy (Recommend individual review): In energy supply, IEC 62443 is increasingly used as an accepted state of the art for securing control systems, complementing the ICT minimum standard under the Electricity Supply Ordinance.\n- Industry: Manufacturing (Likely applies): In manufacturing, IEC 62443 links requirements for operators (62443-2-1) with those for manufacturers of connected components (62443-4-1/4-2) and is increasingly accepted by customers and auditors as evidence of OT security.\n- Activity: Critical infrastructure (Recommend individual review): Operators of critical infrastructure are required by legislation such as NIS2 implementation to take appropriate technical measures; IEC 62443 is, in practice, regarded as an accepted way of giving concrete effect to this obligation for OT environments, even though the law does not name the standard in its wording.\n- Role towards customers: Manufacturer (only together with industry or activity) (Recommend individual review): Manufacturers of components for industrial control systems are increasingly asked by operators for a development process under IEC 62443-4-1 and components under 62443-4-2.","quellen":[{"titel":"IEC TS 62443-1-1:2009 — Terminology, concepts and models","url":"https://webstore.iec.ch/en/publication/7029","herausgeber":"IEC (International Electrotechnical Commission)","abgerufen":"2026-09-24"},{"titel":"IEC 62443","url":"https://en.wikipedia.org/wiki/IEC_62443","herausgeber":"Wikipedia (Übersichtsartikel)","abgerufen":"2026-09-24"},{"titel":"IEC 62443 Standard: Industrial Cybersecurity Framework Explained","url":"https://www.fortinet.com/resources/cyberglossary/iec-62443","herausgeber":"Fortinet","abgerufen":"2026-09-24"},{"titel":"What Are ISO/IEC 62443-4-1 and 62443-4-2?","url":"https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/","herausgeber":"Security Compass (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62443","sprache":"en"}
{"id":"en/iec62443#ausnahmen","norm":"iec62443","norm_name":"IEC 62443 — Industrial communication networks, network and system security","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- There is no legal obligation to be certified to IEC 62443 in Switzerland or the EU; the standards series as a whole is voluntary to apply.\n- Pure office IT with no connection to production or control systems falls outside the series' scope.","quellen":[{"titel":"IEC TS 62443-1-1:2009 — Terminology, concepts and models","url":"https://webstore.iec.ch/en/publication/7029","herausgeber":"IEC (International Electrotechnical Commission)","abgerufen":"2026-09-24"},{"titel":"IEC 62443","url":"https://en.wikipedia.org/wiki/IEC_62443","herausgeber":"Wikipedia (Übersichtsartikel)","abgerufen":"2026-09-24"},{"titel":"IEC 62443 Standard: Industrial Cybersecurity Framework Explained","url":"https://www.fortinet.com/resources/cyberglossary/iec-62443","herausgeber":"Fortinet","abgerufen":"2026-09-24"},{"titel":"What Are ISO/IEC 62443-4-1 and 62443-4-2?","url":"https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/","herausgeber":"Security Compass (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62443","sprache":"en"}
{"id":"en/iec62443#pflichten","norm":"iec62443","norm_name":"IEC 62443 — Industrial communication networks, network and system security","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- For operators (IEC 62443-2-1, 2024 edition): build a security programme for the OT environment with a four-stage maturity model (Initial, Managed, Defined, Improving), explicitly aligned with ISO/IEC 27001 to avoid duplicating work with an existing ISMS\n- For system design (IEC 62443-3-2, 3-3): risk assessment, a zones-and-conduits model, and defining a security level (SL1 to SL4) per zone\n- For manufacturers (IEC 62443-4-1): a secure development process across the entire product life cycle\n- For component manufacturers (IEC 62443-4-2): technical security requirements per component type (embedded devices, network components, host components, software applications)","quellen":[{"titel":"IEC TS 62443-1-1:2009 — Terminology, concepts and models","url":"https://webstore.iec.ch/en/publication/7029","herausgeber":"IEC (International Electrotechnical Commission)","abgerufen":"2026-09-24"},{"titel":"IEC 62443","url":"https://en.wikipedia.org/wiki/IEC_62443","herausgeber":"Wikipedia (Übersichtsartikel)","abgerufen":"2026-09-24"},{"titel":"IEC 62443 Standard: Industrial Cybersecurity Framework Explained","url":"https://www.fortinet.com/resources/cyberglossary/iec-62443","herausgeber":"Fortinet","abgerufen":"2026-09-24"},{"titel":"What Are ISO/IEC 62443-4-1 and 62443-4-2?","url":"https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/","herausgeber":"Security Compass (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62443","sprache":"en"}
{"id":"en/iec62443#nachweise","norm":"iec62443","norm_name":"IEC 62443 — Industrial communication networks, network and system security","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Conformity assessment/certification by specialised certification bodies is possible but not uniformly mandated\n- Documented risk assessment, zones/conduits model and assigned security level as an internal evidence document\n- For manufacturers: evidence of a secure development process (62443-4-1) and product conformity (62443-4-2), partly via manufacturer declaration, partly via certification by a testing body","quellen":[{"titel":"IEC TS 62443-1-1:2009 — Terminology, concepts and models","url":"https://webstore.iec.ch/en/publication/7029","herausgeber":"IEC (International Electrotechnical Commission)","abgerufen":"2026-09-24"},{"titel":"IEC 62443","url":"https://en.wikipedia.org/wiki/IEC_62443","herausgeber":"Wikipedia (Übersichtsartikel)","abgerufen":"2026-09-24"},{"titel":"IEC 62443 Standard: Industrial Cybersecurity Framework Explained","url":"https://www.fortinet.com/resources/cyberglossary/iec-62443","herausgeber":"Fortinet","abgerufen":"2026-09-24"},{"titel":"What Are ISO/IEC 62443-4-1 and 62443-4-2?","url":"https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/","herausgeber":"Security Compass (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62443","sprache":"en"}
{"id":"en/iec62443#sanktionen","norm":"iec62443","norm_name":"IEC 62443 — Industrial communication networks, network and system security","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"No fine from the standard itself, since it is voluntary; in practice: without documented implementation, auditors, cyber insurers and customers may object that the 'state of the art' for OT security has not been reached, which can make tenders and taking out cyber insurance more difficult.","quellen":[{"titel":"IEC TS 62443-1-1:2009 — Terminology, concepts and models","url":"https://webstore.iec.ch/en/publication/7029","herausgeber":"IEC (International Electrotechnical Commission)","abgerufen":"2026-09-24"},{"titel":"IEC 62443","url":"https://en.wikipedia.org/wiki/IEC_62443","herausgeber":"Wikipedia (Übersichtsartikel)","abgerufen":"2026-09-24"},{"titel":"IEC 62443 Standard: Industrial Cybersecurity Framework Explained","url":"https://www.fortinet.com/resources/cyberglossary/iec-62443","herausgeber":"Fortinet","abgerufen":"2026-09-24"},{"titel":"What Are ISO/IEC 62443-4-1 and 62443-4-2?","url":"https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/","herausgeber":"Security Compass (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62443","sprache":"en"}
{"id":"en/iec62443#fragen","norm":"iec62443","norm_name":"IEC 62443 — Industrial communication networks, network and system security","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Is IEC 62443 legally required?**\nNo, the standards series is voluntary. Laws such as NIS2 implementation or the Cyber Resilience Act require appropriate technical measures without naming IEC 62443 in their wording; in practice, however, the series is regarded as the accepted benchmark that such measures for OT environments are based on.\n\n**What is the difference between parts 2-1, 3-3 and 4-1/4-2?**\n62443-2-1 is addressed to operators and describes a security programme for the OT environment. 62443-3-3 sets technical system requirements and security levels (SL1 to SL4). 62443-4-1 and 62443-4-2 are addressed to manufacturers: 4-1 to the development process, 4-2 to the technical properties of the individual component.\n\n**What do security levels SL1 to SL4 mean?**\nThey describe resilience against increasingly capable attackers: SL1 protects against occasional, non-malicious misuse, SL2 against targeted attacks with simple means, SL3 against attacks with considerable effort and expertise, SL4 against attacks with very high effort, for example by state actors.","quellen":[{"titel":"IEC TS 62443-1-1:2009 — Terminology, concepts and models","url":"https://webstore.iec.ch/en/publication/7029","herausgeber":"IEC (International Electrotechnical Commission)","abgerufen":"2026-09-24"},{"titel":"IEC 62443","url":"https://en.wikipedia.org/wiki/IEC_62443","herausgeber":"Wikipedia (Übersichtsartikel)","abgerufen":"2026-09-24"},{"titel":"IEC 62443 Standard: Industrial Cybersecurity Framework Explained","url":"https://www.fortinet.com/resources/cyberglossary/iec-62443","herausgeber":"Fortinet","abgerufen":"2026-09-24"},{"titel":"What Are ISO/IEC 62443-4-1 and 62443-4-2?","url":"https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/","herausgeber":"Security Compass (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62443","sprache":"en"}
{"id":"en/iec62443#unsicher","norm":"iec62443","norm_name":"IEC 62443 — Industrial communication networks, network and system security","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- iec.ch (main site/blog) was unreachable in this session (HTTP 403); only the IEC webstore entry for part 1-1 (publication metadata, not the full text of the standard) could be read directly.\n- A literal reference to IEC 62443 in NIS2 implementation or the Cyber Resilience Act was not found in a statutory text in this session; the classification as 'accepted state of the art' rests on secondary sources and professional knowledge, not on a legal reference checked directly.\n- The complete list of all published parts of the series (in particular 2-2, 2-3, 2-4, 3-1) was only checked via secondary sources (Fortinet, Wikipedia), not individually verified in the IEC webstore.\n- Whether and which accredited certification bodies in Switzerland offer IEC 62443 certifications was not examined in this session.","quellen":[{"titel":"IEC TS 62443-1-1:2009 — Terminology, concepts and models","url":"https://webstore.iec.ch/en/publication/7029","herausgeber":"IEC (International Electrotechnical Commission)","abgerufen":"2026-09-24"},{"titel":"IEC 62443","url":"https://en.wikipedia.org/wiki/IEC_62443","herausgeber":"Wikipedia (Übersichtsartikel)","abgerufen":"2026-09-24"},{"titel":"IEC 62443 Standard: Industrial Cybersecurity Framework Explained","url":"https://www.fortinet.com/resources/cyberglossary/iec-62443","herausgeber":"Fortinet","abgerufen":"2026-09-24"},{"titel":"What Are ISO/IEC 62443-4-1 and 62443-4-2?","url":"https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/","herausgeber":"Security Compass (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iec62443","sprache":"en"}
{"id":"en/isg_meldepflicht#kurzantwort","norm":"isg_meldepflicht","norm_name":"Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"Since 1 April 2025, the authorities and organisations individually listed in Art. 74b of the Information Security Act (ISG, SR 128) must report cyberattacks on their IT resources to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery (Art. 74a and 74e ISG). Covered are 21 categories of critical infrastructure named in the act, from universities and energy suppliers to banks and hospitals to cloud providers headquartered in Switzerland; the Federal Council can exempt bodies with only minor impact from the reporting obligation (Art. 74c ISG).","quellen":[{"titel":"Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f","url":"https://www.fedlex.admin.ch/eli/cc/2022/232/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Meldepflicht für Cyberangriffe auf kritische Infrastrukturen","url":"https://www.bacs.admin.ch/de/meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"},{"titel":"FAQ zur Meldepflicht","url":"https://www.bacs.admin.ch/de/faq-meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/isg_meldepflicht","sprache":"en"}
{"id":"en/isg_meldepflicht#wann_gilt","norm":"isg_meldepflicht","norm_name":"Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)","abschnitt":"wann_gilt","ueberschrift":"When does ISG reporting obligation apply to you?","text":"- Activity: Critical infrastructure (Likely applies): You operate or manage critical infrastructure - Art. 74b ISG lists 21 categories of authorities and companies for this; if you are covered, you must report cyberattacks to BACS within 24 hours, unless an exemption under Art. 74c ISG applies.\n- Industry: Energy (Likely applies): Companies active in energy generation, trading, metering or control under the Energy Act belong to the reporting categories expressly named in Art. 74b(1)(d) ISG - the only exemption is for holders of licences under the Nuclear Energy Act.\n- Industry: Financial services (Applies): Companies subject to the Banking Act, the Insurance Supervision Act or the Financial Market Infrastructure Act are named individually as subject to the reporting obligation under Art. 74b(1)(e) ISG.\n- Industry: Healthcare (Recommend individual review): Healthcare institutions listed on a cantonal hospital list, as well as approved medical laboratories, fall under Art. 74b(1)(f-g) ISG; you should check case by case whether your specific institution is on a hospital list or holds a corresponding laboratory licence.\n- Industry: Software / SaaS (Recommend individual review): If you provide cloud computing, search engines, digital security or trust services, or data centres headquartered in Switzerland, you belong to the reporting providers named in Art. 74b(1)(t) ISG - this does not apply to every software/SaaS company.","quellen":[{"titel":"Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f","url":"https://www.fedlex.admin.ch/eli/cc/2022/232/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Meldepflicht für Cyberangriffe auf kritische Infrastrukturen","url":"https://www.bacs.admin.ch/de/meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"},{"titel":"FAQ zur Meldepflicht","url":"https://www.bacs.admin.ch/de/faq-meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/isg_meldepflicht","sprache":"en"}
{"id":"en/isg_meldepflicht#ausnahmen","norm":"isg_meldepflicht","norm_name":"Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- The Federal Council exempts authorities and organisations from the reporting obligation if malfunctions triggered by cyberattacks have only minor effects on the functioning of the economy or the wellbeing of the population (Art. 74c ISG).\n- If a body subject to the reporting obligation also carries out activities not covered by Art. 74b(1) ISG, there is no reporting obligation for cyberattacks that affect exclusively those other activities (Art. 74b(2) ISG).","quellen":[{"titel":"Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f","url":"https://www.fedlex.admin.ch/eli/cc/2022/232/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Meldepflicht für Cyberangriffe auf kritische Infrastrukturen","url":"https://www.bacs.admin.ch/de/meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"},{"titel":"FAQ zur Meldepflicht","url":"https://www.bacs.admin.ch/de/faq-meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/isg_meldepflicht","sprache":"en"}
{"id":"en/isg_meldepflicht#pflichten","norm":"isg_meldepflicht","norm_name":"Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Ensure that cyberattacks on one's own IT resources can be reported to BACS (Art. 74a(1) ISG).\n- Report reportable cyberattacks within 24 hours of their discovery; if not all details are yet known, the report must be supplemented as soon as new information becomes available (Art. 74e(1) and (3) ISG).\n- Include in the report details on the reporting body, the type and execution of the cyberattack, its effects, measures taken and, to the extent known, further planned action (Art. 74e(2) ISG).\n- Submit the report via the secure electronic transmission system provided by BACS (Art. 74f(1) ISG).","quellen":[{"titel":"Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f","url":"https://www.fedlex.admin.ch/eli/cc/2022/232/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Meldepflicht für Cyberangriffe auf kritische Infrastrukturen","url":"https://www.bacs.admin.ch/de/meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"},{"titel":"FAQ zur Meldepflicht","url":"https://www.bacs.admin.ch/de/faq-meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/isg_meldepflicht","sprache":"en"}
{"id":"en/isg_meldepflicht#nachweise","norm":"isg_meldepflicht","norm_name":"Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Confirmation of report or log from BACS's electronic reporting system.\n- Internal documentation of incident detection and escalation, showing the relevant discovery time for the 24-hour deadline (Art. 74e ISG).","quellen":[{"titel":"Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f","url":"https://www.fedlex.admin.ch/eli/cc/2022/232/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Meldepflicht für Cyberangriffe auf kritische Infrastrukturen","url":"https://www.bacs.admin.ch/de/meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"},{"titel":"FAQ zur Meldepflicht","url":"https://www.bacs.admin.ch/de/faq-meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/isg_meldepflicht","sprache":"en"}
{"id":"en/isg_meldepflicht#fristen","norm":"isg_meldepflicht","norm_name":"Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 1 April 2025: The reporting obligation for cyberattacks on critical infrastructure (Art. 74a-74f ISG) enters into force (AS 2024 257; AS 2025 173; BBl 2023 84).","quellen":[{"titel":"Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f","url":"https://www.fedlex.admin.ch/eli/cc/2022/232/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Meldepflicht für Cyberangriffe auf kritische Infrastrukturen","url":"https://www.bacs.admin.ch/de/meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"},{"titel":"FAQ zur Meldepflicht","url":"https://www.bacs.admin.ch/de/faq-meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/isg_meldepflicht","sprache":"en"}
{"id":"en/isg_meldepflicht#sanktionen","norm":"isg_meldepflicht","norm_name":"Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"The reporting obligation provisions themselves (Art. 74a-74f ISG) contain no penalty provision of their own. Per BACS (FAQ on the reporting obligation), BACS can issue a ruling with a threat of penalty if non-reporting is established; in the case of continued non-compliance, a complaint to the competent cantonal prosecution authorities is possible, which are responsible for prosecuting and adjudicating violations of BACS rulings. A quantified fine amount, and a date from which fines can specifically be imposed, could not be evidenced in this research either in the ISG full text or on the BACS pages reached (see unsicher).","quellen":[{"titel":"Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f","url":"https://www.fedlex.admin.ch/eli/cc/2022/232/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Meldepflicht für Cyberangriffe auf kritische Infrastrukturen","url":"https://www.bacs.admin.ch/de/meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"},{"titel":"FAQ zur Meldepflicht","url":"https://www.bacs.admin.ch/de/faq-meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/isg_meldepflicht","sprache":"en"}
{"id":"en/isg_meldepflicht#fragen","norm":"isg_meldepflicht","norm_name":"Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Who exactly is subject to the reporting obligation?**\nArt. 74b(1) ISG lists 21 categories (letters a-u) by name: universities; federal, cantonal and municipal authorities as well as inter-cantonal/municipal organisations; organisations with tasks in security/rescue, drinking water supply, wastewater treatment, waste disposal; companies in energy generation/trading/metering/control (except nuclear power plant licence holders); companies under the Banking Act, the Insurance Supervision Act or the Financial Market Infrastructure Act; healthcare institutions on cantonal hospital lists; approved medical laboratories; companies with a medicinal product licence; social insurance organisations; the Swiss Broadcasting Corporation; news agencies of national significance; registered postal service providers; railway, cable-car, trolleybus, bus and shipping companies with a concession; civil aviation companies; companies under the Maritime Navigation Act; companies for essential goods; registered telecommunications service providers; registrars/registry operators of internet domains; providers of services for exercising political rights; providers of cloud computing, search engines, digital security/trust services and data centres headquartered in Switzerland; and manufacturers of hardware/software able to remotely maintain critical infrastructure.\n\n**From when does the 24-hour deadline run?**\nFrom the discovery of the cyberattack by the reporting authority or organisation (Art. 74e(1) ISG). If information is still missing at that point, the report must be supplemented as soon as new information becomes available (Art. 74e(3) ISG).\n\n**What does BACS do with the reported data?**\nPer Art. 74a(4) ISG, the reporting obligation serves exclusively to enable BACS to detect attack patterns on critical infrastructure at an early stage, warn other potentially affected parties, and recommend suitable prevention and defence measures to them.\n\n**Does the ISG reporting obligation replace sector-specific reporting obligations?**\nNo. Depending on the sector, additional reporting or information obligations may exist, for example for electricity supply operators under the ICT Minimum Standard per the StromVV. The ISG reporting obligation applies in addition.","quellen":[{"titel":"Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f","url":"https://www.fedlex.admin.ch/eli/cc/2022/232/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Meldepflicht für Cyberangriffe auf kritische Infrastrukturen","url":"https://www.bacs.admin.ch/de/meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"},{"titel":"FAQ zur Meldepflicht","url":"https://www.bacs.admin.ch/de/faq-meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/isg_meldepflicht","sprache":"en"}
{"id":"en/isg_meldepflicht#unsicher","norm":"isg_meldepflicht","norm_name":"Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The statement given in the brief, 'fines have been possible since 1 October 2025', could not be evidenced either in the ISG full text (Art. 74a-74f contain no penalty provision of their own) or on the BACS pages reached (reporting obligation homepage, FAQ), and is therefore not adopted as fact.\n- The Cybersecurity Ordinance (CSV), which per BACS regulates details of the reporting obligation and exemptions under Art. 74c ISG, was not read in full text in this research; the SR number and exact content of the CSV are not confirmed.\n- The simplified formula of 'nine sectors' of critical infrastructure used on bacs.admin.ch does not match the exhaustive list of 21 letters (a-u) in Art. 74b(1) ISG; for this file, the statutory list was used as authoritative.","quellen":[{"titel":"Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f","url":"https://www.fedlex.admin.ch/eli/cc/2022/232/de","herausgeber":"Bundeskanzlei / Fedlex","abgerufen":"2026-09-24"},{"titel":"Meldepflicht für Cyberangriffe auf kritische Infrastrukturen","url":"https://www.bacs.admin.ch/de/meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"},{"titel":"FAQ zur Meldepflicht","url":"https://www.bacs.admin.ch/de/faq-meldepflicht","herausgeber":"Bundesamt für Cybersicherheit (BACS)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/isg_meldepflicht","sprache":"en"}
{"id":"en/iso13485#kurzantwort","norm":"iso13485","norm_name":"ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"ISO 13485 is the international standard for quality management systems specifically for medical device manufacturers. As a standard, it is not itself legally mandated, but in practice it is a precondition for obtaining CE marking under the EU MDR or authorisation via Swissmedic under the MedDO: without a certified QM system to ISO 13485, notified bodies and supervisory authorities generally refuse conformity assessment.","quellen":[{"titel":"ISO 13485:2016 – Medical devices – Quality management systems – Requirements for regulatory purposes","url":"https://www.iso.org/standard/59752.html","herausgeber":"International Organization for Standardization (ISO)","abgerufen":"2026-09-24"},{"titel":"ISO 13485 – Alles Wichtige zur Norm für Medizinprodukte-QM-Systeme","url":"https://www.johner-institut.de/blog/regulatory-affairs/iso-13485/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso13485","sprache":"en"}
{"id":"en/iso13485#wann_gilt","norm":"iso13485","norm_name":"ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes","abschnitt":"wann_gilt","ueberschrift":"When does ISO 13485 apply to you?","text":"- Activity: Medical devices (Likely applies): You manufacture a medical device - ISO 13485 is the de facto basis of every MDR conformity assessment and every Swissmedic authorisation; without a certified QM system, you generally will not get CE marking or market access.\n- Industry: MedTech (Likely applies): As a MedTech company, your quality management system is highly likely to be measured against ISO 13485 by customers, notified bodies and supervisory authorities, even though your own certification needs to be checked case by case.\n- Role towards customers: Manufacturer, Supplier (applies if additionally: Activity: Medical devices) (Recommend individual review): As a manufacturer or supplier for medical devices, your customers and the conformity assessment bodies typically require an ISO 13485-certified QM system, including for supplied components or software.","quellen":[{"titel":"ISO 13485:2016 – Medical devices – Quality management systems – Requirements for regulatory purposes","url":"https://www.iso.org/standard/59752.html","herausgeber":"International Organization for Standardization (ISO)","abgerufen":"2026-09-24"},{"titel":"ISO 13485 – Alles Wichtige zur Norm für Medizinprodukte-QM-Systeme","url":"https://www.johner-institut.de/blog/regulatory-affairs/iso-13485/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso13485","sprache":"en"}
{"id":"en/iso13485#ausnahmen","norm":"iso13485","norm_name":"ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Certification to ISO 13485 is not legally mandatory in every case; for very simple products in a low risk class, a reduced conformity assessment procedure without full ISO 13485 certification may suffice, depending on the jurisdiction. Which product classes this concerns case by case was not verified in this session.\n- Pure suppliers of non-medical-device components with no specific medical intended purpose do not fall directly within the standard's scope, even though customers can impose contractually similar requirements.","quellen":[{"titel":"ISO 13485:2016 – Medical devices – Quality management systems – Requirements for regulatory purposes","url":"https://www.iso.org/standard/59752.html","herausgeber":"International Organization for Standardization (ISO)","abgerufen":"2026-09-24"},{"titel":"ISO 13485 – Alles Wichtige zur Norm für Medizinprodukte-QM-Systeme","url":"https://www.johner-institut.de/blog/regulatory-affairs/iso-13485/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso13485","sprache":"en"}
{"id":"en/iso13485#pflichten","norm":"iso13485","norm_name":"ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Establish, document, implement and maintain a quality management system per the standard's requirements, across the entire product life cycle from development through manufacturing to post-market surveillance.\n- Integrate risk management into the QM system (in practice usually in conjunction with ISO 14971).\n- Ensure traceability of products and processes.\n- Conduct regular internal audits and management reviews.\n- Where certified: pass external surveillance audits by an accredited certification body.","quellen":[{"titel":"ISO 13485:2016 – Medical devices – Quality management systems – Requirements for regulatory purposes","url":"https://www.iso.org/standard/59752.html","herausgeber":"International Organization for Standardization (ISO)","abgerufen":"2026-09-24"},{"titel":"ISO 13485 – Alles Wichtige zur Norm für Medizinprodukte-QM-Systeme","url":"https://www.johner-institut.de/blog/regulatory-affairs/iso-13485/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso13485","sprache":"en"}
{"id":"en/iso13485#nachweise","norm":"iso13485","norm_name":"ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- ISO 13485 certificate from an accredited certification body.\n- QM manual and documented procedures.\n- Audit reports (internal and external).\n- Evidence of risk management, design and development documentation, supplier evaluation.","quellen":[{"titel":"ISO 13485:2016 – Medical devices – Quality management systems – Requirements for regulatory purposes","url":"https://www.iso.org/standard/59752.html","herausgeber":"International Organization for Standardization (ISO)","abgerufen":"2026-09-24"},{"titel":"ISO 13485 – Alles Wichtige zur Norm für Medizinprodukte-QM-Systeme","url":"https://www.johner-institut.de/blog/regulatory-affairs/iso-13485/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso13485","sprache":"en"}
{"id":"en/iso13485#sanktionen","norm":"iso13485","norm_name":"ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"ISO 13485 is not a statutory standard and carries no fines of its own. The de facto compulsion arises via the market: without a valid certificate, notified bodies and Swissmedic generally refuse conformity assessment or authorisation, which amounts to exclusion from the market. Where deviations are found in audit, consequences range from conditions up to withdrawal of the certificate by the certification body.","quellen":[{"titel":"ISO 13485:2016 – Medical devices – Quality management systems – Requirements for regulatory purposes","url":"https://www.iso.org/standard/59752.html","herausgeber":"International Organization for Standardization (ISO)","abgerufen":"2026-09-24"},{"titel":"ISO 13485 – Alles Wichtige zur Norm für Medizinprodukte-QM-Systeme","url":"https://www.johner-institut.de/blog/regulatory-affairs/iso-13485/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso13485","sprache":"en"}
{"id":"en/iso13485#fragen","norm":"iso13485","norm_name":"ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Is ISO 13485 legally required?**\nNot the standard itself, directly. Neither the EU MDR nor the Swiss MedDO literally prescribes 'ISO 13485' in their statutory text. In practice, however, it is the accepted evidence basis by which manufacturers meet the QM requirements of the MDR/MedDO - without it, you will in practice not get a conformity assessment.\n\n**Isn't ISO 9001 sufficient too?**\nNo. ISO 9001 is a general QM system; ISO 13485 builds on a similar structure but adds additional, medical-device-specific requirements, for example on risk management, traceability and regulatory documentation. Since the 2016 revision, the two standards have diverged more in substance.\n\n**Does an ISO 13485 certification automatically apply equally to Switzerland and the EU?**\nThe standard itself is international and region-independent. Whether a specific certification is recognised by the respective notified body or by Swissmedic depends on the accreditation of the certification body in the relevant jurisdiction - this was not examined in detail in this session.","quellen":[{"titel":"ISO 13485:2016 – Medical devices – Quality management systems – Requirements for regulatory purposes","url":"https://www.iso.org/standard/59752.html","herausgeber":"International Organization for Standardization (ISO)","abgerufen":"2026-09-24"},{"titel":"ISO 13485 – Alles Wichtige zur Norm für Medizinprodukte-QM-Systeme","url":"https://www.johner-institut.de/blog/regulatory-affairs/iso-13485/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso13485","sprache":"en"}
{"id":"en/iso13485#unsicher","norm":"iso13485","norm_name":"ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- iso.org blocks automated access (HTTP 403 on all attempted URLs, including via curl with a browser user agent); the full text of the standard or the catalogue page could not be read in this session. The current edition stated rests on established professional knowledge (ISO 13485:2016 is the most recently published international edition) and the secondary Johner Institut source, not on a primary text read in this session.\n- The Johner Institut page summarised via WebFetch inconsistently used the label 'ISO 13485:2021'; this presumably confuses it with the European implementation EN ISO 13485:2016/A11:2021 (an amendment for MDR/IVDR harmonisation), not a new ISO edition of its own. This was not conclusively verified against an iso.org source.\n- Whether and which product categories can do without full ISO 13485 certification (reduced conformity assessment) was not verified.","quellen":[{"titel":"ISO 13485:2016 – Medical devices – Quality management systems – Requirements for regulatory purposes","url":"https://www.iso.org/standard/59752.html","herausgeber":"International Organization for Standardization (ISO)","abgerufen":"2026-09-24"},{"titel":"ISO 13485 – Alles Wichtige zur Norm für Medizinprodukte-QM-Systeme","url":"https://www.johner-institut.de/blog/regulatory-affairs/iso-13485/","herausgeber":"Johner Institut","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso13485","sprache":"en"}
{"id":"en/iso27001#kurzantwort","norm":"iso27001","norm_name":"ISO/IEC 27001","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"ISO/IEC 27001 is the internationally recognised standard for an information security management system (ISMS); it is voluntary, but is frequently required by large customers, in tenders and in due-diligence reviews. The current version, ISO/IEC 27001:2022, requires a risk-based management system under chapters 4 to 10 and a justified selection from 93 controls in Annex A. A certificate from an accredited certification body is valid for three years and is confirmed through annual surveillance audits.","quellen":[{"titel":"ISO/IEC 27001:2022 — Information security management systems","url":"https://www.iso.org/standard/27001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – Information Security Systems","url":"https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/","herausgeber":"ANSI National Accreditation Board (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – The Information Security Management Standard","url":"https://grcsolutions.io/guide-to-iso-iec-27001-2022/","herausgeber":"GRC Solutions","abgerufen":"2026-09-24"},{"titel":"BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso27001","sprache":"en"}
{"id":"en/iso27001#wann_gilt","norm":"iso27001","norm_name":"ISO/IEC 27001","abschnitt":"wann_gilt","ueberschrift":"When does ISO 27001 apply to you?","text":"- Role towards customers: Supplier (only together with industry or activity) (Likely applies): Large customers and corporate groups increasingly require their suppliers to demonstrate a certified ISMS before entering into a contractual relationship.\n- Activity: Public-sector clients (Recommend individual review): Public-sector tenders in many cases require an ISO 27001 certificate or an equivalent ISMS as an eligibility criterion.\n- Industry: Aviation (Likely applies): The European Part-IS regulations expressly allow aviation organisations an information security management system based on ISO/IEC 27001; anyone choosing this route needs the standard as a foundation.\n- Activity: Special category personal data, AI provider (own AI products) (Recommend individual review): Anyone processing special category data or providing AI systems is frequently asked by customers and investors about a documented information security management system.\n- Markets: EU, Germany (only together with industry or activity) (Recommend individual review): In the EU area, an ISO 27001 certificate is a common standard piece of evidence in due-diligence reviews for funding rounds and company sales.","quellen":[{"titel":"ISO/IEC 27001:2022 — Information security management systems","url":"https://www.iso.org/standard/27001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – Information Security Systems","url":"https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/","herausgeber":"ANSI National Accreditation Board (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – The Information Security Management Standard","url":"https://grcsolutions.io/guide-to-iso-iec-27001-2022/","herausgeber":"GRC Solutions","abgerufen":"2026-09-24"},{"titel":"BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso27001","sprache":"en"}
{"id":"en/iso27001#ausnahmen","norm":"iso27001","norm_name":"ISO/IEC 27001","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- No statutory obligation to be certified; an ISMS can also be operated in line with the standard's principles without external certification.\n- Micro-enterprises without a contractual requirement from a customer generally have no trigger.","quellen":[{"titel":"ISO/IEC 27001:2022 — Information security management systems","url":"https://www.iso.org/standard/27001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – Information Security Systems","url":"https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/","herausgeber":"ANSI National Accreditation Board (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – The Information Security Management Standard","url":"https://grcsolutions.io/guide-to-iso-iec-27001-2022/","herausgeber":"GRC Solutions","abgerufen":"2026-09-24"},{"titel":"BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso27001","sprache":"en"}
{"id":"en/iso27001#pflichten","norm":"iso27001","norm_name":"ISO/IEC 27001","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Build an ISMS meeting the requirements of chapters 4 to 10 (context of the organisation, leadership, planning, support, operation, performance evaluation, improvement)\n- Carry out risk assessment and treatment, including a justified selection of which of the 93 controls in Annex A are applied or excluded (Statement of Applicability)\n- Conduct internal audits and management review at defined intervals\n- Continually improve the ISMS","quellen":[{"titel":"ISO/IEC 27001:2022 — Information security management systems","url":"https://www.iso.org/standard/27001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – Information Security Systems","url":"https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/","herausgeber":"ANSI National Accreditation Board (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – The Information Security Management Standard","url":"https://grcsolutions.io/guide-to-iso-iec-27001-2022/","herausgeber":"GRC Solutions","abgerufen":"2026-09-24"},{"titel":"BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso27001","sprache":"en"}
{"id":"en/iso27001#nachweise","norm":"iso27001","norm_name":"ISO/IEC 27001","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Certificate from an accredited certification body following a Stage 1 audit (document review) and Stage 2 audit (implementation review)\n- Annual surveillance audits\n- Recertification every three years\n- Statement of Applicability as an internal evidence document","quellen":[{"titel":"ISO/IEC 27001:2022 — Information security management systems","url":"https://www.iso.org/standard/27001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – Information Security Systems","url":"https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/","herausgeber":"ANSI National Accreditation Board (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – The Information Security Management Standard","url":"https://grcsolutions.io/guide-to-iso-iec-27001-2022/","herausgeber":"GRC Solutions","abgerufen":"2026-09-24"},{"titel":"BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso27001","sprache":"en"}
{"id":"en/iso27001#sanktionen","norm":"iso27001","norm_name":"ISO/IEC 27001","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"No fine, since voluntary; in practice: without a valid certificate, exclusion from tenders, loss of large customers, or deductions in due-diligence valuations for investments or company sales are a risk.","quellen":[{"titel":"ISO/IEC 27001:2022 — Information security management systems","url":"https://www.iso.org/standard/27001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – Information Security Systems","url":"https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/","herausgeber":"ANSI National Accreditation Board (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – The Information Security Management Standard","url":"https://grcsolutions.io/guide-to-iso-iec-27001-2022/","herausgeber":"GRC Solutions","abgerufen":"2026-09-24"},{"titel":"BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso27001","sprache":"en"}
{"id":"en/iso27001#fragen","norm":"iso27001","norm_name":"ISO/IEC 27001","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Does a start-up need to be certified to ISO 27001?**\nNot legally. But corporate customers, tenders and investors often ask about it. It makes sense to build your processes early on so that a later certification is a small step, not a rebuild.\n\n**What does an ISO 27001 certificate show, and what doesn't it show?**\nIt shows that a company operates a functioning, audited information security management system and has made a justified selection of the measures in Annex A. It does not guarantee one hundred percent protection against incidents, but it evidences a structured, repeatedly reviewed approach to risk.\n\n**How long is an ISO 27001 certificate valid?**\nThree years, with annual surveillance audits by the certification body; recertification is then required.\n\n**What changes with the 2022 version compared with 2013?**\nAnnex A was reorganised: instead of 114 controls in 14 categories, there are now 93 controls in four themes (organisational, people, physical, technological).","quellen":[{"titel":"ISO/IEC 27001:2022 — Information security management systems","url":"https://www.iso.org/standard/27001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – Information Security Systems","url":"https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/","herausgeber":"ANSI National Accreditation Board (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – The Information Security Management Standard","url":"https://grcsolutions.io/guide-to-iso-iec-27001-2022/","herausgeber":"GRC Solutions","abgerufen":"2026-09-24"},{"titel":"BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso27001","sprache":"en"}
{"id":"en/iso27001#unsicher","norm":"iso27001","norm_name":"ISO/IEC 27001","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- iso.org responded to direct retrieval in this session with HTTP 403 (bot block); the iso.org URL is kept only as a source reference (source type accordingly 'secondary', since no standard text was read). The facts on Annex A (93 controls, four themes: 37 organisational, 8 people, 14 physical, 34 technological) and on the certification process come from secondary sources (GRC Solutions, ANSI blog search result), not from the ISO original text.\n- That Part-IS expressly allows an ISMS 'based on ISO/IEC 27001' is evidenced via the FOCA (BAZL) page, but only as a secondary summary (search result), not as a verbatim reading of the regulation's text.\n- Specific thresholds (e.g. number of employees) from which customers require a certificate were not researched and are deliberately not listed as a trigger.","quellen":[{"titel":"ISO/IEC 27001:2022 — Information security management systems","url":"https://www.iso.org/standard/27001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – Information Security Systems","url":"https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/","herausgeber":"ANSI National Accreditation Board (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"ISO/IEC 27001:2022 – The Information Security Management Standard","url":"https://grcsolutions.io/guide-to-iso-iec-27001-2022/","herausgeber":"GRC Solutions","abgerufen":"2026-09-24"},{"titel":"BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso27001","sprache":"en"}
{"id":"en/iso9001#kurzantwort","norm":"iso9001","norm_name":"ISO 9001","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"ISO 9001 is the internationally recognised standard for quality management systems, voluntary, but often contractually required in manufacturing and supply chains as well as in public tenders. It is built on the PDCA cycle (Plan-Do-Check-Act) and is audited by accredited certification bodies, with a validity of three years and annual surveillance audits. ISO published the new ISO 9001:2026 version on 16 September 2026; existing certificates to ISO 9001:2015 remain valid until 30 September 2029 at the latest.","quellen":[{"titel":"ISO 9001:2015 — Quality management systems — Requirements","url":"https://www.iso.org/standard/62085.html","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 — Quality management systems — Requirements","url":"https://www.iso.org/standard/9001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"Overview & schedule: Revision of ISO 9001 coming in 2026","url":"https://www.tuv.com/world/en/revision-iso-9001-2026.html","herausgeber":"TÜV (TÜV Rheinland-Gruppe)","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 Revision: Changes & Transition","url":"https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/","herausgeber":"DNV","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso9001","sprache":"en"}
{"id":"en/iso9001#wann_gilt","norm":"iso9001","norm_name":"ISO 9001","abschnitt":"wann_gilt","ueberschrift":"When does ISO 9001 apply to you?","text":"- Industry: Manufacturing (Likely applies): In manufacturing and supply chains, a certified quality management system is a common precondition for even being listed as a supplier.\n- Industry: MedTech (Likely applies): In medical technology, ISO 9001 is the basis that the sector-specific ISO 13485 builds on; without a functioning quality management system, 13485 certification is not achievable.\n- Activity: Public-sector clients (Recommend individual review): Public tenders in manufacturing and services frequently require a certified quality management system as an eligibility criterion.\n- Role towards customers: Supplier (only together with industry or activity) (Likely applies): Large customers in supply chains regularly check suppliers for a certified quality management system before awarding contracts.\n- Activity: Supplier to the automotive industry (Recommend individual review): Automotive manufacturers and their suppliers require a quality management system to ISO 9001 as the basis on which sector-specific requirements such as IATF 16949 build.","quellen":[{"titel":"ISO 9001:2015 — Quality management systems — Requirements","url":"https://www.iso.org/standard/62085.html","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 — Quality management systems — Requirements","url":"https://www.iso.org/standard/9001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"Overview & schedule: Revision of ISO 9001 coming in 2026","url":"https://www.tuv.com/world/en/revision-iso-9001-2026.html","herausgeber":"TÜV (TÜV Rheinland-Gruppe)","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 Revision: Changes & Transition","url":"https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/","herausgeber":"DNV","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso9001","sprache":"en"}
{"id":"en/iso9001#ausnahmen","norm":"iso9001","norm_name":"ISO 9001","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- No legal obligation to be certified.\n- For micro-enterprises without a specific customer requirement, there is generally no trigger.\n- Medical technology companies generally need the sector-specific ISO 13485 in addition to ISO 9001; this is only mentioned here, with detail covered in a separate file (iso13485).","quellen":[{"titel":"ISO 9001:2015 — Quality management systems — Requirements","url":"https://www.iso.org/standard/62085.html","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 — Quality management systems — Requirements","url":"https://www.iso.org/standard/9001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"Overview & schedule: Revision of ISO 9001 coming in 2026","url":"https://www.tuv.com/world/en/revision-iso-9001-2026.html","herausgeber":"TÜV (TÜV Rheinland-Gruppe)","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 Revision: Changes & Transition","url":"https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/","herausgeber":"DNV","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso9001","sprache":"en"}
{"id":"en/iso9001#pflichten","norm":"iso9001","norm_name":"ISO 9001","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Establish a quality management system following the PDCA cycle (Plan-Do-Check-Act)\n- Documented processes, responsibilities and evidence (control of documents and records)\n- Internal audits and management review\n- Measures for continual improvement and for managing risks and opportunities","quellen":[{"titel":"ISO 9001:2015 — Quality management systems — Requirements","url":"https://www.iso.org/standard/62085.html","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 — Quality management systems — Requirements","url":"https://www.iso.org/standard/9001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"Overview & schedule: Revision of ISO 9001 coming in 2026","url":"https://www.tuv.com/world/en/revision-iso-9001-2026.html","herausgeber":"TÜV (TÜV Rheinland-Gruppe)","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 Revision: Changes & Transition","url":"https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/","herausgeber":"DNV","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso9001","sprache":"en"}
{"id":"en/iso9001#nachweise","norm":"iso9001","norm_name":"ISO 9001","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Certificate from an accredited certification body following a Stage 1 audit (document review) and Stage 2 audit (implementation review)\n- Annual surveillance audits\n- Recertification every three years\n- For existing ISO 9001:2015 certificates: validity ends 30 September 2029 at the latest, after which certification to ISO 9001:2026 is required","quellen":[{"titel":"ISO 9001:2015 — Quality management systems — Requirements","url":"https://www.iso.org/standard/62085.html","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 — Quality management systems — Requirements","url":"https://www.iso.org/standard/9001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"Overview & schedule: Revision of ISO 9001 coming in 2026","url":"https://www.tuv.com/world/en/revision-iso-9001-2026.html","herausgeber":"TÜV (TÜV Rheinland-Gruppe)","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 Revision: Changes & Transition","url":"https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/","herausgeber":"DNV","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso9001","sprache":"en"}
{"id":"en/iso9001#fristen","norm":"iso9001","norm_name":"ISO 9001","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 16 September 2026: Publication of ISO 9001:2026 by ISO (supersedes ISO 9001:2015)\n- 30 September 2029: Existing certificates to ISO 9001:2015 lose validity at the latest on this date (three-year transition period)","quellen":[{"titel":"ISO 9001:2015 — Quality management systems — Requirements","url":"https://www.iso.org/standard/62085.html","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 — Quality management systems — Requirements","url":"https://www.iso.org/standard/9001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"Overview & schedule: Revision of ISO 9001 coming in 2026","url":"https://www.tuv.com/world/en/revision-iso-9001-2026.html","herausgeber":"TÜV (TÜV Rheinland-Gruppe)","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 Revision: Changes & Transition","url":"https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/","herausgeber":"DNV","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso9001","sprache":"en"}
{"id":"en/iso9001#sanktionen","norm":"iso9001","norm_name":"ISO 9001","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"No fine, since voluntary; in practice: without a valid certificate, exclusion from tenders and supplier lists is a risk, particularly in manufacturing and supply chains.","quellen":[{"titel":"ISO 9001:2015 — Quality management systems — Requirements","url":"https://www.iso.org/standard/62085.html","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 — Quality management systems — Requirements","url":"https://www.iso.org/standard/9001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"Overview & schedule: Revision of ISO 9001 coming in 2026","url":"https://www.tuv.com/world/en/revision-iso-9001-2026.html","herausgeber":"TÜV (TÜV Rheinland-Gruppe)","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 Revision: Changes & Transition","url":"https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/","herausgeber":"DNV","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso9001","sprache":"en"}
{"id":"en/iso9001#fragen","norm":"iso9001","norm_name":"ISO 9001","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Is ISO 9001 legally required?**\nNo. The standard is voluntary, but is often contractually required in manufacturing and supply chains as well as in public tenders.\n\n**What changes with ISO 9001:2026?**\nISO published the new version on 16 September 2026; it replaces ISO 9001:2015 and, per certification bodies, brings among other things stronger requirements on resilience, supply chain management, sustainability, leadership responsibility, and managing risks and opportunities. Existing certificates to the old version remain valid until 30 September 2029 at the latest.\n\n**Is ISO 9001 sufficient for medical technology?**\nGenerally not on its own. Medical technology companies also need the sector-specific ISO 13485, which builds on the same principles but imposes additional regulatory requirements.","quellen":[{"titel":"ISO 9001:2015 — Quality management systems — Requirements","url":"https://www.iso.org/standard/62085.html","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 — Quality management systems — Requirements","url":"https://www.iso.org/standard/9001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"Overview & schedule: Revision of ISO 9001 coming in 2026","url":"https://www.tuv.com/world/en/revision-iso-9001-2026.html","herausgeber":"TÜV (TÜV Rheinland-Gruppe)","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 Revision: Changes & Transition","url":"https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/","herausgeber":"DNV","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso9001","sprache":"en"}
{"id":"en/iso9001#unsicher","norm":"iso9001","norm_name":"ISO 9001","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- iso.org responded to direct retrieval in this session with HTTP 403 (bot block); the facts on the 2026 revision come from the secondary sources TÜV and DNV, which agree on the publication date (16.09.2026) and the transition period (until 30.09.2029), but were not checked against the ISO original text.\n- The exact substantive scope of the changes from 2015 to 2026 (resilience, supply chain management, sustainability, leadership responsibility) is evidenced only via a secondary source (TÜV), not checked against the ISO original text.\n- Whether and how the PDCA cycle remains explicitly named in the 2026 version was not examined in this session.\n- An earlier note in the architecture document ('ISO 9001 revision not checked') is resolved by this research step: the revision is published (16.09.2026), evidenced via two consistent secondary sources, not via the ISO original text.","quellen":[{"titel":"ISO 9001:2015 — Quality management systems — Requirements","url":"https://www.iso.org/standard/62085.html","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 — Quality management systems — Requirements","url":"https://www.iso.org/standard/9001","herausgeber":"ISO","abgerufen":"2026-09-24"},{"titel":"Overview & schedule: Revision of ISO 9001 coming in 2026","url":"https://www.tuv.com/world/en/revision-iso-9001-2026.html","herausgeber":"TÜV (TÜV Rheinland-Gruppe)","abgerufen":"2026-09-24"},{"titel":"ISO 9001:2026 Revision: Changes & Transition","url":"https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/","herausgeber":"DNV","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/iso9001","sprache":"en"}
{"id":"en/maschinenverordnung_2023_1230#kurzantwort","norm":"maschinenverordnung_2023_1230","norm_name":"Machinery Regulation (EU Machinery Regulation)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"The EU Machinery Regulation (Regulation (EU) 2023/1230) supersedes the previous Machinery Directive 2006/42/EC and applies from 20 January 2027 to the placing on the market of machinery in the EU. New are explicit cybersecurity requirements: machinery with digital elements or safety-relevant functions must be designed so that its safety functions cannot be compromised by unauthorised digital interference. For Swiss machinery manufacturers, the regulation applies as soon as they place their products on the EU market.","quellen":[{"titel":"EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027","url":"https://de.nttdata.com/insights/blog/eu-maschinenverordnung-2023-1230-neue-cybersecurity-anforderungen-fuer-hersteller-ab-2027","herausgeber":"NTT DATA Deutschland","abgerufen":"2026-09-24"},{"titel":"Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit","url":"https://www.weka.de/produktsicherheit/maschinenverordnung-eu-2023-1230-anforderungen-an-digitale-technologien-und-cybersicherheit/","herausgeber":"WEKA Business Medien","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/maschinenverordnung_2023_1230","sprache":"en"}
{"id":"en/maschinenverordnung_2023_1230#wann_gilt","norm":"maschinenverordnung_2023_1230","norm_name":"Machinery Regulation (EU Machinery Regulation)","abschnitt":"wann_gilt","ueberschrift":"When does Machinery Regulation (EU) 2023/1230 apply to you?","text":"- Activity: Products with software (Likely applies): Your machinery contains digital elements or software-controlled safety functions - from January 2027, the EU Machinery Regulation additionally requires, on top of the existing safety requirements, protection against unauthorised digital interference (Annex III, including sections 1.1.9 and 1.2.1).\n- Role towards customers: Manufacturer (applies if additionally: Activity: Products with software) (Likely applies): As the manufacturer of machinery with digital elements, you bear the main responsibility for conformity assessment under the Machinery Regulation; importers and distributors who make safety-relevant changes to the machinery are also treated as manufacturers with corresponding obligations. This file specifically covers the new cybersecurity requirements; for machinery with no digital elements at all, check the regulation's classic safety requirements separately.\n- Markets: EU (applies if additionally: Activity: Products with software) (Recommend individual review): The Machinery Regulation is triggered by placing on the EU market - if you place machinery with digital elements on the market in the EU, the cybersecurity requirements described here apply regardless of your registered seat in Switzerland.\n- Industry: Manufacturing (Recommend individual review): In manufacturing and mechanical engineering, safety functions are increasingly digitally controlled - check whether your machinery falls under the regulation's new cybersecurity requirements.","quellen":[{"titel":"EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027","url":"https://de.nttdata.com/insights/blog/eu-maschinenverordnung-2023-1230-neue-cybersecurity-anforderungen-fuer-hersteller-ab-2027","herausgeber":"NTT DATA Deutschland","abgerufen":"2026-09-24"},{"titel":"Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit","url":"https://www.weka.de/produktsicherheit/maschinenverordnung-eu-2023-1230-anforderungen-an-digitale-technologien-und-cybersicherheit/","herausgeber":"WEKA Business Medien","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/maschinenverordnung_2023_1230","sprache":"en"}
{"id":"en/maschinenverordnung_2023_1230#pflichten","norm":"maschinenverordnung_2023_1230","norm_name":"Machinery Regulation (EU Machinery Regulation)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Ensure that machinery is protected against unintentional or deliberate corruption of its safety-relevant software or data (Annex III section 1.1.9).\n- Ensure the safety and reliability of controls, including protection against disrupted wireless connections and malfunctions caused by AI components (Annex III section 1.2.1).\n- Provide for evidence or logging of legitimate and illegitimate interference with safety-relevant components.\n- Carry out CE marking and conformity assessment under the Machinery Regulation; per secondary sources, a combined conformity assessment with the EU AI Act is envisaged where AI safety functions are integrated.\n- Maintain technical documentation including cybersecurity evidence.","quellen":[{"titel":"EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027","url":"https://de.nttdata.com/insights/blog/eu-maschinenverordnung-2023-1230-neue-cybersecurity-anforderungen-fuer-hersteller-ab-2027","herausgeber":"NTT DATA Deutschland","abgerufen":"2026-09-24"},{"titel":"Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit","url":"https://www.weka.de/produktsicherheit/maschinenverordnung-eu-2023-1230-anforderungen-an-digitale-technologien-und-cybersicherheit/","herausgeber":"WEKA Business Medien","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/maschinenverordnung_2023_1230","sprache":"en"}
{"id":"en/maschinenverordnung_2023_1230#nachweise","norm":"maschinenverordnung_2023_1230","norm_name":"Machinery Regulation (EU Machinery Regulation)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Technical documentation with cybersecurity evidence (Annex III section 1.1.9).\n- Declaration of conformity and CE marking.\n- Logs of interference with safety-relevant components.","quellen":[{"titel":"EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027","url":"https://de.nttdata.com/insights/blog/eu-maschinenverordnung-2023-1230-neue-cybersecurity-anforderungen-fuer-hersteller-ab-2027","herausgeber":"NTT DATA Deutschland","abgerufen":"2026-09-24"},{"titel":"Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit","url":"https://www.weka.de/produktsicherheit/maschinenverordnung-eu-2023-1230-anforderungen-an-digitale-technologien-und-cybersicherheit/","herausgeber":"WEKA Business Medien","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/maschinenverordnung_2023_1230","sprache":"en"}
{"id":"en/maschinenverordnung_2023_1230#fristen","norm":"maschinenverordnung_2023_1230","norm_name":"Machinery Regulation (EU Machinery Regulation)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 20 January 2027: Regulation (EU) 2023/1230 applies to the placing on the market of machinery and supersedes the Machinery Directive 2006/42/EC.","quellen":[{"titel":"EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027","url":"https://de.nttdata.com/insights/blog/eu-maschinenverordnung-2023-1230-neue-cybersecurity-anforderungen-fuer-hersteller-ab-2027","herausgeber":"NTT DATA Deutschland","abgerufen":"2026-09-24"},{"titel":"Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit","url":"https://www.weka.de/produktsicherheit/maschinenverordnung-eu-2023-1230-anforderungen-an-digitale-technologien-und-cybersicherheit/","herausgeber":"WEKA Business Medien","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/maschinenverordnung_2023_1230","sprache":"en"}
{"id":"en/maschinenverordnung_2023_1230#sanktionen","norm":"maschinenverordnung_2023_1230","norm_name":"Machinery Regulation (EU Machinery Regulation)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"The Machinery Regulation itself primarily harmonises safety requirements and conformity assessment; sanctions for breaches (e.g. market surveillance measures, fines) are governed by the national law of the member states and were not researched in this session.","quellen":[{"titel":"EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027","url":"https://de.nttdata.com/insights/blog/eu-maschinenverordnung-2023-1230-neue-cybersecurity-anforderungen-fuer-hersteller-ab-2027","herausgeber":"NTT DATA Deutschland","abgerufen":"2026-09-24"},{"titel":"Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit","url":"https://www.weka.de/produktsicherheit/maschinenverordnung-eu-2023-1230-anforderungen-an-digitale-technologien-und-cybersicherheit/","herausgeber":"WEKA Business Medien","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/maschinenverordnung_2023_1230","sprache":"en"}
{"id":"en/maschinenverordnung_2023_1230#fragen","norm":"maschinenverordnung_2023_1230","norm_name":"Machinery Regulation (EU Machinery Regulation)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**From when does the new Machinery Regulation apply as binding?**\nFrom 20 January 2027, only machinery that complies with Regulation (EU) 2023/1230 may be placed on the market in the EU; it supersedes the previous Machinery Directive 2006/42/EC.\n\n**What is new about the cybersecurity requirements compared with the old Machinery Directive?**\nFor the first time, software safety, protection against unauthorised digital interference, and risks from AI algorithms become an explicit part of the essential safety requirements and conformity assessment (Annex III, including sections 1.1.9 and 1.2.1) - the old directive had no such specific cybersecurity requirements.\n\n**How does the Machinery Regulation relate to the Cyber Resilience Act?**\nBoth frameworks address cybersecurity for connected products, but the Machinery Regulation is the more specific regime for machinery and its safety functions. The details of how the two frameworks are demarcated case by case have not been conclusively clarified in this knowledge base; see the separate norm file cra.","quellen":[{"titel":"EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027","url":"https://de.nttdata.com/insights/blog/eu-maschinenverordnung-2023-1230-neue-cybersecurity-anforderungen-fuer-hersteller-ab-2027","herausgeber":"NTT DATA Deutschland","abgerufen":"2026-09-24"},{"titel":"Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit","url":"https://www.weka.de/produktsicherheit/maschinenverordnung-eu-2023-1230-anforderungen-an-digitale-technologien-und-cybersicherheit/","herausgeber":"WEKA Business Medien","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/maschinenverordnung_2023_1230","sprache":"en"}
{"id":"en/maschinenverordnung_2023_1230#unsicher","norm":"maschinenverordnung_2023_1230","norm_name":"Machinery Regulation (EU Machinery Regulation)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The EUR-Lex primary text of Regulation (EU) 2023/1230 (eur-lex.europa.eu/eli/reg/2023/1230/oj) was not retrievable in this session (HTTP 503 or empty response); all statements come from two independent secondary sources (professional articles), not from the regulation's text itself.\n- The date of entry into force or publication of the regulation was not verified and is therefore not listed - only the application date of 20.1.2027 is evidenced.\n- Specific exemptions from the scope (e.g. for certain machinery categories, as under the old Machinery Directive) were not named in the sources retrieved and are therefore not documented; the 'ausnahmen' field is accordingly empty rather than guessed.\n- Sanctions/fine ranges for breaches were not researched (governed by the national law of the member states).\n- The statement on a combined conformity assessment with the EU AI Act for integrated AI safety functions comes from a single secondary source and was not cross-checked.","quellen":[{"titel":"EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027","url":"https://de.nttdata.com/insights/blog/eu-maschinenverordnung-2023-1230-neue-cybersecurity-anforderungen-fuer-hersteller-ab-2027","herausgeber":"NTT DATA Deutschland","abgerufen":"2026-09-24"},{"titel":"Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit","url":"https://www.weka.de/produktsicherheit/maschinenverordnung-eu-2023-1230-anforderungen-an-digitale-technologien-und-cybersicherheit/","herausgeber":"WEKA Business Medien","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/maschinenverordnung_2023_1230","sprache":"en"}
{"id":"en/mepv#kurzantwort","norm":"mepv","norm_name":"Medical Devices Ordinance of 1 July 2020 (SR 812.213)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"The Swiss Medical Devices Ordinance (MedDO, SR 812.213) governs the manufacture, placing on the market and surveillance of medical devices in Switzerland and is supervised by Swissmedic. It was brought into force in a completely revised version on 26 May 2021 and closely follows the substance of the EU MDR (Regulation (EU) 2017/745), but remains independent Swiss law with its own authorisation, registration and supervisory logic via Swissmedic instead of EU authorities.","quellen":[{"titel":"Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)","url":"https://www.fedlex.admin.ch/eli/cc/2020/552/de","herausgeber":"Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes)","abgerufen":"2026-09-24"},{"titel":"AS 2021 281 – Änderung der Medizinprodukteverordnung","url":"https://www.fedlex.admin.ch/eli/oc/2021/281/de","herausgeber":"Fedlex, Amtliche Sammlung des Bundesrechts","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mepv","sprache":"en"}
{"id":"en/mepv#wann_gilt","norm":"mepv","norm_name":"Medical Devices Ordinance of 1 July 2020 (SR 812.213)","abschnitt":"wann_gilt","ueberschrift":"When does MedDO apply to you?","text":"- Activity: Medical devices (Applies): You manufacture, import or distribute a medical device in Switzerland - the MedDO sets out which conformity evidence, registrations and notifications you must provide to Swissmedic.\n- Markets: Switzerland (applies if additionally: Activity: Medical devices) (Recommend individual review): You are active on the Swiss market and manufacture, import or distribute medical devices - for this, the MedDO applies to you under Swissmedic's supervision, regardless of whether you are also active in the EU.\n- Industry: MedTech (Likely applies): As a MedTech company with Swiss market relevance, you are highly likely to fall under the MedDO - check the classification of your product based on its intended purpose.\n- Role towards customers: Manufacturer, Distributor (applies if additionally: Activity: Medical devices) (Recommend individual review): As a manufacturer or distributor of medical devices in Switzerland, you have your own obligations under the MedDO, including registration with Swissmedic (Swiss Single Registration Number, CHRN) and appointing a Swiss authorised representative if you are based abroad.","quellen":[{"titel":"Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)","url":"https://www.fedlex.admin.ch/eli/cc/2020/552/de","herausgeber":"Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes)","abgerufen":"2026-09-24"},{"titel":"AS 2021 281 – Änderung der Medizinprodukteverordnung","url":"https://www.fedlex.admin.ch/eli/oc/2021/281/de","herausgeber":"Fedlex, Amtliche Sammlung des Bundesrechts","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mepv","sprache":"en"}
{"id":"en/mepv#ausnahmen","norm":"mepv","norm_name":"Medical Devices Ordinance of 1 July 2020 (SR 812.213)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Custom-made devices and manufacturing-specific regulated exemptions carry, analogous to the MDR, adapted rather than full conformity requirements.\n- For products already lawfully placed on the market under the old law before the revised MedDO applied, transition periods existed; whether and for which product categories these are still relevant in September 2026 was not verified in this session.\n- The exact article and paragraph numbers of these exemptions were not verified via full-text retrieval from Fedlex (see 'unsicher').","quellen":[{"titel":"Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)","url":"https://www.fedlex.admin.ch/eli/cc/2020/552/de","herausgeber":"Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes)","abgerufen":"2026-09-24"},{"titel":"AS 2021 281 – Änderung der Medizinprodukteverordnung","url":"https://www.fedlex.admin.ch/eli/oc/2021/281/de","herausgeber":"Fedlex, Amtliche Sammlung des Bundesrechts","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mepv","sprache":"en"}
{"id":"en/mepv#pflichten","norm":"mepv","norm_name":"Medical Devices Ordinance of 1 July 2020 (SR 812.213)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Carry out conformity assessment and classify the product by risk class, substantively aligned with the MDR system.\n- Draw up technical documentation and make it available to Swissmedic on request.\n- As manufacturer, authorised representative or importer: register with Swissmedic and obtain a Swiss Single Registration Number (CHRN).\n- As a foreign manufacturer with no seat in Switzerland: appoint an authorised representative established in Switzerland who carries out the regulatory obligations towards Swissmedic (mirroring the obligation of Swiss manufacturers to appoint an EU authorised representative).\n- Operate a vigilance system and report serious incidents to Swissmedic.\n- Ensure post-market surveillance and keep the product file current.","quellen":[{"titel":"Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)","url":"https://www.fedlex.admin.ch/eli/cc/2020/552/de","herausgeber":"Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes)","abgerufen":"2026-09-24"},{"titel":"AS 2021 281 – Änderung der Medizinprodukteverordnung","url":"https://www.fedlex.admin.ch/eli/oc/2021/281/de","herausgeber":"Fedlex, Amtliche Sammlung des Bundesrechts","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mepv","sprache":"en"}
{"id":"en/mepv#nachweise","norm":"mepv","norm_name":"Medical Devices Ordinance of 1 July 2020 (SR 812.213)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Technical documentation per the requirements set out in the MedDO, aligned with the MDR.\n- Manufacturer's declaration of conformity.\n- Swiss Single Registration Number (CHRN) for manufacturers, authorised representatives and importers.\n- Certificate from a conformity assessment body, where required for the risk class.\n- Evidence of an appointed Swiss authorised representative where the manufacturer's seat is outside Switzerland.","quellen":[{"titel":"Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)","url":"https://www.fedlex.admin.ch/eli/cc/2020/552/de","herausgeber":"Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes)","abgerufen":"2026-09-24"},{"titel":"AS 2021 281 – Änderung der Medizinprodukteverordnung","url":"https://www.fedlex.admin.ch/eli/oc/2021/281/de","herausgeber":"Fedlex, Amtliche Sammlung des Bundesrechts","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mepv","sprache":"en"}
{"id":"en/mepv#fristen","norm":"mepv","norm_name":"Medical Devices Ordinance of 1 July 2020 (SR 812.213)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 26 May 2021: Entry into force of the completely revised MedDO (enactment date of the ordinance: 1 July 2020) and of the new ordinance on clinical trials with medical devices; simultaneously the start of Switzerland's third-country status towards the EU in medical device law.","quellen":[{"titel":"Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)","url":"https://www.fedlex.admin.ch/eli/cc/2020/552/de","herausgeber":"Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes)","abgerufen":"2026-09-24"},{"titel":"AS 2021 281 – Änderung der Medizinprodukteverordnung","url":"https://www.fedlex.admin.ch/eli/oc/2021/281/de","herausgeber":"Fedlex, Amtliche Sammlung des Bundesrechts","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mepv","sprache":"en"}
{"id":"en/mepv#sanktionen","norm":"mepv","norm_name":"Medical Devices Ordinance of 1 July 2020 (SR 812.213)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"Breaches of the MedDO are penalised via the penal provisions of the Therapeutic Products Act (TPA); depending on severity and intent, the range extends to imprisonment or fines. In addition, Swissmedic as the supervisory authority can order sales bans, recalls and withdrawal of registrations or licences. The exact article numbers of the TPA were not verified via full text in this session (see 'unsicher').","quellen":[{"titel":"Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)","url":"https://www.fedlex.admin.ch/eli/cc/2020/552/de","herausgeber":"Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes)","abgerufen":"2026-09-24"},{"titel":"AS 2021 281 – Änderung der Medizinprodukteverordnung","url":"https://www.fedlex.admin.ch/eli/oc/2021/281/de","herausgeber":"Fedlex, Amtliche Sammlung des Bundesrechts","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mepv","sprache":"en"}
{"id":"en/mepv#fragen","norm":"mepv","norm_name":"Medical Devices Ordinance of 1 July 2020 (SR 812.213)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Is CE marking under the EU MDR sufficient to sell in Switzerland?**\nNot automatically as a full substitute for the Swiss obligations: you additionally need a Swiss authorised representative (if based abroad) and registration with Swissmedic. In substance, the MedDO closely follows the MDR, but it is independent Swiss law with its own registration logic.\n\n**Who supervises compliance with the MedDO?**\nSwissmedic, the Swiss Agency for Therapeutic Products. It carries out market surveillance, receives vigilance reports, and issues the Swiss Single Registration Number (CHRN).\n\n**What does 'substantively aligned with the MDR' specifically mean?**\nSwitzerland has largely adopted the substantive requirements of the EU MDR into its own law, to maintain equivalence and make later EU market access easier for Swiss manufacturers. Legally, however, it is an independent Swiss ordinance with its own supervision, not a direct application of the EU MDR.","quellen":[{"titel":"Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)","url":"https://www.fedlex.admin.ch/eli/cc/2020/552/de","herausgeber":"Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes)","abgerufen":"2026-09-24"},{"titel":"AS 2021 281 – Änderung der Medizinprodukteverordnung","url":"https://www.fedlex.admin.ch/eli/oc/2021/281/de","herausgeber":"Fedlex, Amtliche Sammlung des Bundesrechts","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mepv","sprache":"en"}
{"id":"en/mepv#unsicher","norm":"mepv","norm_name":"Medical Devices Ordinance of 1 July 2020 (SR 812.213)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The full text of the MedDO on Fedlex (SR 812.213) could not be read in an automated way in this session: Fedlex serves bots only the JavaScript application shell (WebFetch and several curl variants, including guessed filestore paths, returned identical empty shell pages). The substantive statements rest on the Swissmedic notice of 26.5.2021 (authority source, read in full text) and the Swissmedic factsheet on the obligations of economic operators, not on the ordinance's text itself.\n- The exact article numbers on transition periods for legacy products, and on the penal provisions in the TPA, were not verified via full text.\n- Whether and which transition periods from the 2020/2021 revision are still actively relevant in September 2026 was not examined.","quellen":[{"titel":"Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)","url":"https://www.fedlex.admin.ch/eli/cc/2020/552/de","herausgeber":"Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes)","abgerufen":"2026-09-24"},{"titel":"AS 2021 281 – Änderung der Medizinprodukteverordnung","url":"https://www.fedlex.admin.ch/eli/oc/2021/281/de","herausgeber":"Fedlex, Amtliche Sammlung des Bundesrechts","abgerufen":"2026-09-24"},{"titel":"Neue Regulierung der Medizinprodukte ab 26. Mai 2021","url":"https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html","herausgeber":"Swissmedic","abgerufen":"2026-09-24"},{"titel":"Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)","url":"https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf","herausgeber":"Swissmedic","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/mepv","sprache":"en"}
{"id":"en/nis2#kurzantwort","norm":"nis2","norm_name":"Directive on measures for a high common level of cybersecurity across the Union (NIS2)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"The NIS2 Directive (Directive (EU) 2022/2555) obliges operators in critical and important sectors to manage risk and report significant security incidents. As an EU directive, it does not have direct effect but works via national transposition laws - in Germany via the NIS2 Implementation Act (NIS2UmsuCG), in force since 6 December 2025. NIS2 affects Swiss companies via an EU establishment, via the representative obligation for certain digital services under Art. 26, or because EU customers must demonstrate their supply chain security and pass this requirement on.","quellen":[{"titel":"NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)","url":"https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"Sektoren mit hoher Kritikalität – Anhang I NIS2","url":"https://www.buzer.de/I_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"},{"titel":"Sonstige kritische Sektoren – Anhang II NIS2","url":"https://www.buzer.de/II_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/nis2","sprache":"en"}
{"id":"en/nis2#wann_gilt","norm":"nis2","norm_name":"Directive on measures for a high common level of cybersecurity across the Union (NIS2)","abschnitt":"wann_gilt","ueberschrift":"When does NIS2 apply to you?","text":"- Activity: Critical infrastructure (Likely applies): You state that you operate critical infrastructure - the NIS2 sector lists in Annex I (including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space) and Annex II (including postal/courier services, waste management, chemicals, food, manufacturing, digital services, research) are a strong indication that NIS2 is relevant to you.\n- Industry: Energy (Likely applies): Energy supply is one of the eleven sectors of high criticality in Annex I of the NIS2 Directive - as an operator in this sector, NIS2 checks whether you reach the size threshold for 'important' or 'essential' entities.\n- Industry: Software / SaaS (Recommend individual review): Digital infrastructure and certain digital services (cloud, data centres, managed services, online marketplaces, search engines, social networks) fall under Annex I or II of the NIS2 Directive - whether your specific offering is covered depends on the exact type of service.\n- Employees: from 50 (applies if additionally: Industry: Energy, Software / SaaS) (Recommend individual review): From around 50 employees and the associated revenue or balance-sheet thresholds, companies in the NIS2 sectors generally count as an 'important entity' - what additionally matters is whether your activity is assigned to a sector under Annex I or II at all. Outside these sectors, the number of employees alone does not trigger NIS2.\n- Markets: EU (only together with industry or activity) (Recommend individual review): If, as a provider of certain digital services (e.g. DNS, cloud, data centre, content delivery, managed service or managed security service, online marketplace, search engine, social network), you offer your services in the EU without being established there, you must appoint a representative in an EU member state under Art. 26(3) NIS2.","quellen":[{"titel":"NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)","url":"https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"Sektoren mit hoher Kritikalität – Anhang I NIS2","url":"https://www.buzer.de/I_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"},{"titel":"Sonstige kritische Sektoren – Anhang II NIS2","url":"https://www.buzer.de/II_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/nis2","sprache":"en"}
{"id":"en/nis2#ausnahmen","norm":"nis2","norm_name":"Directive on measures for a high common level of cybersecurity across the Union (NIS2)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Micro and small enterprises (below the thresholds for medium-sized enterprises under Recommendation 2003/361/EC) generally do not fall under NIS2 - unless they belong to the exemptions from the size rule named in Art. 2(2) NIS2 (including providers of public electronic communications networks/services, trust service providers, TLD name registries and DNS service providers, sole providers of a service important to society in a member state, certain public administration bodies, entities identified as critical under the CER Directive (EU) 2022/2557).\n- Member states can additionally extend the scope to local administrative units and certain educational institutions with critical research activity.","quellen":[{"titel":"NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)","url":"https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"Sektoren mit hoher Kritikalität – Anhang I NIS2","url":"https://www.buzer.de/I_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"},{"titel":"Sonstige kritische Sektoren – Anhang II NIS2","url":"https://www.buzer.de/II_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/nis2","sprache":"en"}
{"id":"en/nis2#pflichten","norm":"nis2","norm_name":"Directive on measures for a high common level of cybersecurity across the Union (NIS2)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Implement state-of-the-art cybersecurity risk management measures, at minimum: risk analysis/security policy, incident handling, business continuity/backup/disaster recovery/crisis management, supply chain security, security in system acquisition/development/maintenance including vulnerability management, assessment of the effectiveness of measures, cyber hygiene and training, cryptography/encryption policy, personnel security/access control/asset management, multi-factor authentication (Art. 21(2) NIS2).\n- Take into account security in the supply chain, including relationships with direct suppliers and service providers (Art. 21(3) NIS2).\n- Report significant security incidents to the competent authority: early warning within 24 hours, notification within 72 hours, final report within one month (in Germany, to the BSI).\n- In Germany: register as a NIS2 company via 'Mein Unternehmenskonto' and the BSI portal.\n- Where Art. 26(3) applies: appoint in writing a representative in a member state where the services are offered.","quellen":[{"titel":"NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)","url":"https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"Sektoren mit hoher Kritikalität – Anhang I NIS2","url":"https://www.buzer.de/I_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"},{"titel":"Sonstige kritische Sektoren – Anhang II NIS2","url":"https://www.buzer.de/II_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/nis2","sprache":"en"}
{"id":"en/nis2#nachweise","norm":"nis2","norm_name":"Directive on measures for a high common level of cybersecurity across the Union (NIS2)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Documented risk management framework under Art. 21(2).\n- Evidence of registration (in Germany: the BSI portal).\n- Reporting logs for security incidents.\n- Supply chain assessment of security-relevant suppliers and service providers.\n- Evidence of the representative appointment under Art. 26(3), where applicable.","quellen":[{"titel":"NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)","url":"https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"Sektoren mit hoher Kritikalität – Anhang I NIS2","url":"https://www.buzer.de/I_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"},{"titel":"Sonstige kritische Sektoren – Anhang II NIS2","url":"https://www.buzer.de/II_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/nis2","sprache":"en"}
{"id":"en/nis2#fristen","norm":"nis2","norm_name":"Directive on measures for a high common level of cybersecurity across the Union (NIS2)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 17 October 2024: Deadline for transposing the NIS2 Directive into national law (Art. 41 NIS2) - missed by several member states, including Germany.\n- 6 December 2025: The German NIS2 Implementation Act (NIS2UmsuCG) enters into force.\n- 6 January 2026: The BSI portal for NIS2 registration goes live.","quellen":[{"titel":"NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)","url":"https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"Sektoren mit hoher Kritikalität – Anhang I NIS2","url":"https://www.buzer.de/I_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"},{"titel":"Sonstige kritische Sektoren – Anhang II NIS2","url":"https://www.buzer.de/II_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/nis2","sprache":"en"}
{"id":"en/nis2#sanktionen","norm":"nis2","norm_name":"Directive on measures for a high common level of cybersecurity across the Union (NIS2)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"Under Art. 34 NIS2, the fine ranges for 'essential entities' must be at least EUR 10 million or 2% of worldwide annual turnover (whichever is higher), and for 'important entities' at least EUR 7 million or 1.4% of worldwide annual turnover. The specific implementation and fine amount is governed by national law, in Germany by the NIS2 Implementation Act.","quellen":[{"titel":"NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)","url":"https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"Sektoren mit hoher Kritikalität – Anhang I NIS2","url":"https://www.buzer.de/I_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"},{"titel":"Sonstige kritische Sektoren – Anhang II NIS2","url":"https://www.buzer.de/II_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/nis2","sprache":"en"}
{"id":"en/nis2#fragen","norm":"nis2","norm_name":"Directive on measures for a high common level of cybersecurity across the Union (NIS2)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Does a Swiss company without an EU establishment have to implement NIS2 directly?**\nOnly directly if it offers one of the digital services named in Art. 26(1)(b) (e.g. DNS, cloud, data centre, content delivery network, managed service/managed security service, online marketplace, search engine, social network) in the EU and must appoint a representative for that. Otherwise, NIS2 usually affects Swiss companies indirectly - via an EU establishment or via supply chain requirements from EU customers.\n\n**What is the difference between 'essential' and 'important' entities?**\nThe classification depends on sector and size: in particularly critical sectors (Annex I), large companies generally count as an 'essential entity', medium-sized companies in Annex I or Annex II sectors generally as an 'important entity'. The same risk management and reporting obligations apply to both categories, but with different supervisory intensity and fine ranges.\n\n**Does NIS2 apply uniformly across the EU?**\nNo. NIS2 is a directive and must be transposed into national law by each member state; details on sector demarcation, reporting deadlines and supervision can vary nationally. This file primarily covers the German transposition (NIS2UmsuCG).","quellen":[{"titel":"NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)","url":"https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"Sektoren mit hoher Kritikalität – Anhang I NIS2","url":"https://www.buzer.de/I_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"},{"titel":"Sonstige kritische Sektoren – Anhang II NIS2","url":"https://www.buzer.de/II_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/nis2","sprache":"en"}
{"id":"en/nis2#unsicher","norm":"nis2","norm_name":"Directive on measures for a high common level of cybersecurity across the Union (NIS2)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The EUR-Lex primary text of Directive (EU) 2022/2555 was not retrievable in this session (empty/blocked response across several URL forms); article texts were verified via the secondary source nis-2-directive.com and sector lists via buzer.de, not via the Official Journal itself.\n- The exact revenue/balance-sheet thresholds for 'essential' (per secondary sources approx. ≥250 employees or >EUR 50 million turnover or >EUR 43 million balance sheet total) and 'important' entities (approx. ≥50 employees or >EUR 10 million turnover/balance sheet total) were not verified directly against Art. 2 NIS2 or the underlying Recommendation 2003/361/EC.\n- The German reporting deadlines (24h/72h/1 month) are the NIS2 reference values; the exact design in the German NIS2UmsuCG statutory text was not checked in full text.","quellen":[{"titel":"NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)","url":"https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html","herausgeber":"Bundesamt für Sicherheit in der Informationstechnik (BSI)","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)","url":"https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html","herausgeber":"nis-2-directive.com","abgerufen":"2026-09-24"},{"titel":"Sektoren mit hoher Kritikalität – Anhang I NIS2","url":"https://www.buzer.de/I_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"},{"titel":"Sonstige kritische Sektoren – Anhang II NIS2","url":"https://www.buzer.de/II_NIS2.htm","herausgeber":"buzer.de","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/nis2","sprache":"en"}
{"id":"en/easa_partis#kurzantwort","norm":"easa_partis","norm_name":"EU regulations on information security in aviation (Part-IS)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"Part-IS requires aviation organisations - from airports to airlines to air navigation services - to operate an information security management system (ISMS), which may be based on ISO/IEC 27001, together with risk management and reporting of security-relevant occurrences. The obligation applies in stages: from 16 October 2025 for airport operators, apron management services, and design and production organisations; from 22 February 2026 for airlines, maintenance organisations, CAMOs, training organisations and air navigation services. In Switzerland, Part-IS is implemented by FOCA; the exact legal anchoring via the Air Transport Agreement was not examined in the wording in this research.","quellen":[{"titel":"EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"EU regulation on information security (Part-IS)","url":"https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"IS — Information Security (Regulation Groups)","url":"https://www.easa.europa.eu/en/regulation-groups/information-security","herausgeber":"European Union Aviation Safety Agency (EASA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/easa_partis","sprache":"en"}
{"id":"en/easa_partis#wann_gilt","norm":"easa_partis","norm_name":"EU regulations on information security in aviation (Part-IS)","abschnitt":"wann_gilt","ueberschrift":"When does Part-IS apply to you?","text":"- Industry: Aviation (Likely applies): As an aviation organisation - for example an airport, airline, maintenance organisation, CAMO, training organisation or air navigation service provider - you generally fall under the Part-IS information security requirements once your type of organisation reaches the relevant deadline.\n- Activity: Critical infrastructure (applies if additionally: Industry: Aviation) (Recommend individual review): If, as an aviation organisation, you also operate critical infrastructure in air transport (e.g. air navigation services, airport operations), this additionally falls under Part-IS - outside the aviation industry, 'critical infrastructure' alone does not trigger Part-IS, since it is not a general critical-infrastructure regulation.\n- Markets: Switzerland (applies if additionally: Industry: Aviation) (Recommend individual review): For the Swiss market, FOCA implements Part-IS for aviation organisations; the exact legal transposition into the Air Transport Agreement was not examined in this research in the regulation's wording, only via FOCA's information pages. Outside the aviation industry, the Swiss market alone does not trigger Part-IS.","quellen":[{"titel":"EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"EU regulation on information security (Part-IS)","url":"https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"IS — Information Security (Regulation Groups)","url":"https://www.easa.europa.eu/en/regulation-groups/information-security","herausgeber":"European Union Aviation Safety Agency (EASA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/easa_partis","sprache":"en"}
{"id":"en/easa_partis#ausnahmen","norm":"easa_partis","norm_name":"EU regulations on information security in aviation (Part-IS)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Organisations outside the categories named in the regulations (airport operators, apron management services, design/production organisations, air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers) are, per the source status examined, not directly covered.\n- A third regulation on ground handling (Commission Delegated Regulation (EU) 2025/22) was identified in this research only via a secondary source and was not examined for content - it therefore belongs under 'unsicher'.","quellen":[{"titel":"EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"EU regulation on information security (Part-IS)","url":"https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"IS — Information Security (Regulation Groups)","url":"https://www.easa.europa.eu/en/regulation-groups/information-security","herausgeber":"European Union Aviation Safety Agency (EASA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/easa_partis","sprache":"en"}
{"id":"en/easa_partis#pflichten","norm":"easa_partis","norm_name":"EU regulations on information security in aviation (Part-IS)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Establish and operate an information security management system (ISMS), which per FOCA may be based on ISO/IEC 27001.\n- Identify and assess information security risks with a potential impact on flight safety, and derive suitable measures.\n- Integrate the ISMS into the organisation's existing safety management system (SMS).\n- Train personnel on information security and monitor compliance with the requirements.\n- Report occurrences with an information-security dimension to the competent authority.","quellen":[{"titel":"EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"EU regulation on information security (Part-IS)","url":"https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"IS — Information Security (Regulation Groups)","url":"https://www.easa.europa.eu/en/regulation-groups/information-security","herausgeber":"European Union Aviation Safety Agency (EASA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/easa_partis","sprache":"en"}
{"id":"en/easa_partis#nachweise","norm":"easa_partis","norm_name":"EU regulations on information security in aviation (Part-IS)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- Documented ISMS with roles, responsibilities and a risk register.\n- Evidence of the ISMS's integration into the safety management system.\n- Training records for affected personnel.\n- Auditability towards FOCA or EASA as part of ongoing oversight (per the EASA source, monitoring takes place via 'regular audits').","quellen":[{"titel":"EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"EU regulation on information security (Part-IS)","url":"https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"IS — Information Security (Regulation Groups)","url":"https://www.easa.europa.eu/en/regulation-groups/information-security","herausgeber":"European Union Aviation Safety Agency (EASA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/easa_partis","sprache":"en"}
{"id":"en/easa_partis#fristen","norm":"easa_partis","norm_name":"EU regulations on information security in aviation (Part-IS)","abschnitt":"fristen","ueberschrift":"Deadlines","text":"- 16 October 2025: Part-IS applies to airport operators, apron management services, and design and production organisations (Delegated Regulation (EU) 2022/1645).\n- 22 February 2026: Part-IS applies to air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers, as well as the competent supervisory authorities and EASA (Implementing Regulation (EU) 2023/203).","quellen":[{"titel":"EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"EU regulation on information security (Part-IS)","url":"https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"IS — Information Security (Regulation Groups)","url":"https://www.easa.europa.eu/en/regulation-groups/information-security","herausgeber":"European Union Aviation Safety Agency (EASA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/easa_partis","sprache":"en"}
{"id":"en/easa_partis#sanktionen","norm":"easa_partis","norm_name":"EU regulations on information security in aviation (Part-IS)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"The FOCA and EASA pages examined do not state specific fines or sanction provisions for Part-IS. Per EASA, oversight is carried out via regular audits by the competent national authorities and EASA itself; at FOCA, a dedicated Information Security unit within the Protective Measures section has been responsible for this since 1 August 2024. Possible consequences of non-compliance (e.g. conditions or withdrawal of approvals) were not examined in the regulation's text itself as part of this research.","quellen":[{"titel":"EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"EU regulation on information security (Part-IS)","url":"https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"IS — Information Security (Regulation Groups)","url":"https://www.easa.europa.eu/en/regulation-groups/information-security","herausgeber":"European Union Aviation Safety Agency (EASA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/easa_partis","sprache":"en"}
{"id":"en/easa_partis#fragen","norm":"easa_partis","norm_name":"EU regulations on information security in aviation (Part-IS)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Does our ISMS have to be certified to ISO/IEC 27001 to comply with Part-IS?**\nNo. The FOCA page phrases it as an option for orientation ('may be based on ISO/IEC 27001'), not as a certification requirement. Whether certification is worthwhile case by case, or in practice expected by the regulator, was not conclusively clarified in this research and is marked 'pruefen'.\n\n**Does Part-IS apply to our Swiss company in the same way as in the EU?**\nFOCA implements Part-IS in Switzerland; the specific legal basis (transposition via the Air Transport Agreement) was not verified in the wording in this research, only via FOCA's information pages. A robust legal assessment in an individual case requires examining the Air Transport Agreement or consulting FOCA.","quellen":[{"titel":"EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"EU regulation on information security (Part-IS)","url":"https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"IS — Information Security (Regulation Groups)","url":"https://www.easa.europa.eu/en/regulation-groups/information-security","herausgeber":"European Union Aviation Safety Agency (EASA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/easa_partis","sprache":"en"}
{"id":"en/easa_partis#unsicher","norm":"easa_partis","norm_name":"EU regulations on information security in aviation (Part-IS)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The legal transposition of Part-IS in Switzerland via the Air Transport Agreement was not examined in the regulation's wording or the agreement's annex, only via FOCA's information pages, which themselves do not state an explicit legal basis for the transposition. This corresponds to open item 8 in the website's architecture document ('Transposition into the Air Transport Agreement not read in the wording, only FOCA pages. Cross-check.').\n- A third, more recent regulation on ground handling (Commission Delegated Regulation (EU) 2025/22) was identified only via a search result, not examined in full text.\n- Specific sanction or fine provisions for non-compliance were not researched in the regulation's text itself, only the statement on audits on the authorities' pages.\n- Whether there is a de facto certification expectation (rather than mere orientation towards ISO/IEC 27001) was not clarified.","quellen":[{"titel":"EU-Verordnungen zur Informationssicherheit (Part-IS)","url":"https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"EU regulation on information security (Part-IS)","url":"https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is","herausgeber":"Bundesamt für Zivilluftfahrt (BAZL)","abgerufen":"2026-09-24"},{"titel":"IS — Information Security (Regulation Groups)","url":"https://www.easa.europa.eu/en/regulation-groups/information-security","herausgeber":"European Union Aviation Safety Agency (EASA)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/easa_partis","sprache":"en"}
{"id":"en/tisax#kurzantwort","norm":"tisax","norm_name":"TISAX (Trusted Information Security Assessment Exchange)","abschnitt":"kurzantwort","ueberschrift":"Short answer","text":"TISAX is an information security assessment procedure for the automotive supply chain, run by the ENX Association based on the VDA ISA assessment catalogue. It is not a law and not a public certificate, but a result label shared via the ENX portal and contractually required by vehicle manufacturers and large suppliers. The ENX Association was founded by several European vehicle manufacturers, national automotive associations and suppliers; TISAX is therefore not limited to German manufacturers but is carried by the European industry and performed by audit providers worldwide.","quellen":[{"titel":"TISAX — Trusted Information Security Assessment Exchange","url":"https://enx.com/tisax","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"ENX Association — Übersicht","url":"https://enx.com/en-US/","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"TISAX® deep dive: the three assessment levels","url":"https://www.cis-cert.com/en/news/tisax-deep-dive-the-three-assessment-levels/","herausgeber":"CIS Cert (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"TISAX Assessment Levels: AL1, AL2 and AL3 Compared","url":"https://kopexa.com/en/catalog/tisax/assessment-levels","herausgeber":"Kopexa (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/tisax","sprache":"en"}
{"id":"en/tisax#wann_gilt","norm":"tisax","norm_name":"TISAX (Trusted Information Security Assessment Exchange)","abschnitt":"wann_gilt","ueberschrift":"When does TISAX apply to you?","text":"- Activity: Supplier to the automotive industry (Applies): Anyone supplying the automotive industry is contractually required by manufacturers and large tier-1 suppliers to hold a valid TISAX result before sensitive design or production data is exchanged.\n- Industry: Manufacturing (applies if additionally: Activity: Supplier to the automotive industry) (Likely applies): In manufacturing, vehicle manufacturers regularly check their supply chain via the ENX portal for a valid TISAX result before awarding contracts - this concerns you if you specifically operate as an automotive supplier.\n- Role towards customers: Supplier (applies if additionally: Activity: Supplier to the automotive industry) (Likely applies): As a supplier in the automotive value chain, a TISAX result frequently becomes a condition for new contracts and for exchanging development data. This does not apply to suppliers outside the automotive industry.\n- Markets: EU, Germany, Worldwide (applies if additionally: Activity: Supplier to the automotive industry) (Recommend individual review): TISAX is not a purely German matter: the assessment procedure is carried by several European vehicle manufacturers and associations and is performed by audit providers worldwide, which is why, as an automotive supplier, it can become a condition outside Germany as well.","quellen":[{"titel":"TISAX — Trusted Information Security Assessment Exchange","url":"https://enx.com/tisax","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"ENX Association — Übersicht","url":"https://enx.com/en-US/","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"TISAX® deep dive: the three assessment levels","url":"https://www.cis-cert.com/en/news/tisax-deep-dive-the-three-assessment-levels/","herausgeber":"CIS Cert (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"TISAX Assessment Levels: AL1, AL2 and AL3 Compared","url":"https://kopexa.com/en/catalog/tisax/assessment-levels","herausgeber":"Kopexa (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/tisax","sprache":"en"}
{"id":"en/tisax#ausnahmen","norm":"tisax","norm_name":"TISAX (Trusted Information Security Assessment Exchange)","abschnitt":"ausnahmen","ueberschrift":"Exceptions","text":"- Not a law and not a state obligation; the requirement arises exclusively contractually via customers in the automotive supply chain.\n- Assessment Level 1 (pure self-assessment without external review) does not lead to a TISAX label and is not accepted by most vehicle manufacturers as full evidence.","quellen":[{"titel":"TISAX — Trusted Information Security Assessment Exchange","url":"https://enx.com/tisax","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"ENX Association — Übersicht","url":"https://enx.com/en-US/","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"TISAX® deep dive: the three assessment levels","url":"https://www.cis-cert.com/en/news/tisax-deep-dive-the-three-assessment-levels/","herausgeber":"CIS Cert (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"TISAX Assessment Levels: AL1, AL2 and AL3 Compared","url":"https://kopexa.com/en/catalog/tisax/assessment-levels","herausgeber":"Kopexa (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/tisax","sprache":"en"}
{"id":"en/tisax#pflichten","norm":"tisax","norm_name":"TISAX (Trusted Information Security Assessment Exchange)","abschnitt":"pflichten","ueberschrift":"Obligations","text":"- Registration in the ENX portal and definition of the assessment scope (assessment objective: information security, prototype protection and/or data protection when connecting third parties)\n- Choice of the appropriate assessment level depending on the customer's protection needs: AL1 self-assessment without a label, AL2 remote audit by an accredited assessment provider (the standard case for most participants), AL3 on-site audit for particularly sensitive information or vehicle prototypes\n- Implementation of the requirements from the VDA ISA assessment catalogue\n- Carrying out the assessment via an assessment provider approved by ENX","quellen":[{"titel":"TISAX — Trusted Information Security Assessment Exchange","url":"https://enx.com/tisax","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"ENX Association — Übersicht","url":"https://enx.com/en-US/","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"TISAX® deep dive: the three assessment levels","url":"https://www.cis-cert.com/en/news/tisax-deep-dive-the-three-assessment-levels/","herausgeber":"CIS Cert (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"TISAX Assessment Levels: AL1, AL2 and AL3 Compared","url":"https://kopexa.com/en/catalog/tisax/assessment-levels","herausgeber":"Kopexa (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/tisax","sprache":"en"}
{"id":"en/tisax#nachweise","norm":"tisax","norm_name":"TISAX (Trusted Information Security Assessment Exchange)","abschnitt":"nachweise","ueberschrift":"Evidence","text":"- TISAX result/label in the ENX portal, shared specifically with individual customers (not a public certificate as with ISO 27001)\n- For AL2, the result is stored in the ENX portal, visible to TISAX participants\n- Sharing of the result with individual customers is done by the assessed company itself in the portal","quellen":[{"titel":"TISAX — Trusted Information Security Assessment Exchange","url":"https://enx.com/tisax","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"ENX Association — Übersicht","url":"https://enx.com/en-US/","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"TISAX® deep dive: the three assessment levels","url":"https://www.cis-cert.com/en/news/tisax-deep-dive-the-three-assessment-levels/","herausgeber":"CIS Cert (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"TISAX Assessment Levels: AL1, AL2 and AL3 Compared","url":"https://kopexa.com/en/catalog/tisax/assessment-levels","herausgeber":"Kopexa (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/tisax","sprache":"en"}
{"id":"en/tisax#sanktionen","norm":"tisax","norm_name":"TISAX (Trusted Information Security Assessment Exchange)","abschnitt":"sanktionen","ueberschrift":"Penalties","text":"No fine, since it is not a law; in practice: without a valid TISAX result, exclusion from vehicle manufacturers' supplier lists and tenders is a risk, as is termination or non-renewal of existing supply contracts.","quellen":[{"titel":"TISAX — Trusted Information Security Assessment Exchange","url":"https://enx.com/tisax","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"ENX Association — Übersicht","url":"https://enx.com/en-US/","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"TISAX® deep dive: the three assessment levels","url":"https://www.cis-cert.com/en/news/tisax-deep-dive-the-three-assessment-levels/","herausgeber":"CIS Cert (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"TISAX Assessment Levels: AL1, AL2 and AL3 Compared","url":"https://kopexa.com/en/catalog/tisax/assessment-levels","herausgeber":"Kopexa (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/tisax","sprache":"en"}
{"id":"en/tisax#fragen","norm":"tisax","norm_name":"TISAX (Trusted Information Security Assessment Exchange)","abschnitt":"fragen","ueberschrift":"Frequently asked questions","text":"**Is TISAX only relevant for German vehicle manufacturers?**\nNo. TISAX is carried by the ENX Association, a non-profit organisation founded by several vehicle manufacturers, national automotive associations and suppliers in Europe. The assessment procedure is applied across Europe, and assessments are performed by assessment providers worldwide, not only in Germany.\n\n**What is the difference between ISO 27001 and TISAX?**\nISO 27001 is an international standard for information security management systems, with a certificate. TISAX is an automotive industry assessment procedure based on the VDA ISA catalogue, with a label instead of a certificate, and is contractually required by vehicle manufacturers.\n\n**What do assessment levels AL1 to AL3 mean?**\nAL1 is a pure self-assessment without external review and does not lead to a TISAX label. AL2 is the level typical for most participants: a remote audit by an accredited assessment provider, whose result is shared in the ENX portal. AL3 is the most comprehensive level, with an on-site audit, for particularly sensitive information or vehicle prototypes.\n\n**Do you get a public certificate with TISAX?**\nNo. The result is stored in the ENX portal, and the assessed company shares it specifically with individual customers. There is no publicly viewable certificate as with ISO 27001.","quellen":[{"titel":"TISAX — Trusted Information Security Assessment Exchange","url":"https://enx.com/tisax","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"ENX Association — Übersicht","url":"https://enx.com/en-US/","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"TISAX® deep dive: the three assessment levels","url":"https://www.cis-cert.com/en/news/tisax-deep-dive-the-three-assessment-levels/","herausgeber":"CIS Cert (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"TISAX Assessment Levels: AL1, AL2 and AL3 Compared","url":"https://kopexa.com/en/catalog/tisax/assessment-levels","herausgeber":"Kopexa (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/tisax","sprache":"en"}
{"id":"en/tisax#unsicher","norm":"tisax","norm_name":"TISAX (Trusted Information Security Assessment Exchange)","abschnitt":"unsicher","ueberschrift":"Open points of the research","text":"- The complete list of ENX members (exactly which vehicle manufacturers/associations, from which countries) was not conclusively checked in this session; enx.com/en-US/ only generally confirms 'automotive manufacturers, national automotive associations, and automotive suppliers' without a name list.\n- vda.de was unreachable in this session (HTTP 404 on two attempted paths); statements on the VDA ISA catalogue come exclusively from secondary sources (search results, the ENX page), not read from the VDA itself.\n- The exact validity period of a TISAX result and details on VDA ISA version 6.0/2027 are evidenced only from secondary sources (search result summaries), not checked against the ENX or VDA original text in this session.\n- The AL1/AL2/AL3 detailed description comes from secondary sources (cis-cert, kopexa, further search results), not from the ENX or VDA original text in this session.","quellen":[{"titel":"TISAX — Trusted Information Security Assessment Exchange","url":"https://enx.com/tisax","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"ENX Association — Übersicht","url":"https://enx.com/en-US/","herausgeber":"ENX Association","abgerufen":"2026-09-24"},{"titel":"TISAX® deep dive: the three assessment levels","url":"https://www.cis-cert.com/en/news/tisax-deep-dive-the-three-assessment-levels/","herausgeber":"CIS Cert (Suchergebnis)","abgerufen":"2026-09-24"},{"titel":"TISAX Assessment Levels: AL1, AL2 and AL3 Compared","url":"https://kopexa.com/en/catalog/tisax/assessment-levels","herausgeber":"Kopexa (Suchergebnis)","abgerufen":"2026-09-24"}],"stand":"2026-09-24","url":"https://sacosi.ch/en/norms/tisax","sprache":"en"}
