Skip to content
DEEN
Book a call

Compliance: standards and laws

Which IT regulations apply to your company?

Short answer

That depends on three things: your industry, your markets and your customers. This page assesses the most important rules and does not replace legal advice.

Ivo Schönberner hands a successor a MacBook and a documentation folder
Evidence · Documentation

01 Regulatory Check

Which standards apply to your industry?

Six short questions, then the evaluation. The check compares your details with 22 standards and laws in our knowledge base and shows what may apply to you and why. It calculates in your browser according to fixed rules, without a language model.

Question 1 of 6 What is your role in the company?

One answer. The role does not change the evaluation; it helps us with the assessment.

Question 2 of 6 In which industry does your company operate?

One answer. If none fits, choose “Another industry”.

Question 3 of 6 How many employees does your company have?

One answer. If you enter the exact number, the check uses it.

Question 4 of 6 In which markets are you active or do you have locations?

Several answers possible. Germany automatically counts as part of the EU, “Worldwide” covers all.

Question 5 of 6 Which of these apply to your company?

Several answers possible. If none applies, simply continue.

Question 6 of 6 What is your role towards your customers?

Several answers possible. If none applies, simply continue.

02 Overview

What applies in Switzerland, what in the EU?

All 22 rules of the knowledge base in one list. As of: September 2026.

22 of 22 standards

  • CH AI Regulation Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence) Act Voluntary CH Next deadline

    Switzerland does not yet have an AI-specific act. On 12 February 2025, the Federal Council discussed a stocktaking report on possible regulatory approaches to artificial intelligence and instructed the Federal Office of Justice (FOJ) to draft a consultation bill by the end of 2026, implementing in particular the Council of Europe's Framework Convention on Artificial Intelligence. Until this process is concluded, there is no horizontal, AI-specific legal obligation in Switzerland; existing obligations, for instance under the FADP, already apply today regardless.

    Industries according to triggers
    cross-industry
    Deadlines
    • The Federal Council discusses a stocktaking report on possible AI regulatory approaches and instructs several offices, including the Federal Office of Justice, to develop regulatory measures.
    • Target date: by this point, the Federal Office of Justice is to submit a consultation bill for legally binding measures as well as an implementation plan for non-binding measures. This is a milestone for the bill, not the entry-into-force date of an act.
    Triggers, obligations, evidence and sources for CH AI Regulation
  • CRA Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act) Regulation Statutory EU Next deadline

    The Cyber Resilience Act (Regulation (EU) 2024/2847) sets EU-wide, uniform cybersecurity requirements for hardware and software products with digital elements across their entire life cycle. Manufacturers must report actively exploited vulnerabilities and severe security incidents in stages - the reporting obligations have applied since 11 September 2026, with the regulation's full application from 11 December 2027. For Swiss manufacturers, the CRA applies as soon as they place products with digital elements on the EU market.

    Cybersecurity requirements for hardware and software with digital elements across the entire life cycle. Manufacturers must report actively exploited vulnerabilities and severe incidents.

    Switzerland
    Applies to Swiss manufacturers that sell products with digital elements in the EU
    EU
    Reporting obligations since 11 September 2026, full application from 11 December 2027
    Typically relevant for
    Manufacturing, MedTech, manufacturers of connected products
    Industries according to triggers
    cross-industry
    Deadlines
    • Notifying authorities must have established the procedures for conformity assessment bodies.
    • Reporting obligations for manufacturers (actively exploited vulnerabilities, severe incidents) become applicable.
    • The Cyber Resilience Act applies in full, including conformity assessment obligations for all affected products.
    Triggers, obligations, evidence and sources for CRA
  • DORA Digital Operational Resilience Act (Regulation (EU) 2022/2554) Regulation Statutory EU No open deadline

    DORA obliges EU financial entities - banks, insurers, investment firms, payment service providers and others - to comply with uniform requirements for ICT risk management, incident reporting, resilience testing and the management of ICT third-party providers. The regulation has applied directly in the EU since 17 January 2025. For Swiss companies this is, per the client's assessment, a candidate not yet conclusively examined: relevant above all are Swiss financial institutions with an EU establishment, as well as Swiss ICT providers who supply financial entities in the EU/EEA.

    Industries according to triggers
    Financial services
    Deadlines
    • DORA becomes binding and applicable in the EU/EEA (regulation in force since 17 January 2023, applicable from 17 January 2025 per the secondary sources examined).
    Triggers, obligations, evidence and sources for DORA
  • EU AI Act Regulation laying down harmonised rules on artificial intelligence (EU AI Act) Regulation Statutory EU Next deadline

    The EU AI Act (Regulation (EU) 2024/1689) regulates AI systems in stages by risk class and applies to providers and deployers whose AI systems are placed on the market in the EU or whose output is used there - regardless of registered seat. Bans on certain practices have applied since February 2025, rules for general-purpose AI models since August 2025, and transparency obligations since August 2026. The amending regulation (EU) 2026/1744 ('Digital Omnibus', published on 24 July 2026) has postponed the obligations for high-risk systems under Annex III to December 2027 and for AI in regulated products under Annex I to August 2028.

    The obligations apply in stages: prohibitions since February 2025, rules for general-purpose AI models since August 2025, transparency obligations since August 2026. The obligations for high-risk systems were postponed in 2026, to December 2027 and, for AI in regulated products, to August 2028. Switzerland is preparing its own bill by the end of 2026.

    Switzerland
    Applies to Swiss providers that place AI systems on the market in the EU or whose output is used in the EU
    EU
    Phased in since 2 February 2025
    Typically relevant for
    All industries that use or provide AI
    Industries according to triggers
    cross-industry
    Deadlines
    • Bans on certain AI practices and the obligation on AI literacy become applicable.
    • Rules for general-purpose AI (GPAI) models become applicable.
    • The amending regulation (EU) 2026/1744 ('Digital Omnibus') is published in the Official Journal.
    • Transparency obligations under Art. 50 become applicable.
    • The transition period for transparency obligations for systems already on the market ends; two further bans under Art. 5 enter into force.
    • Obligations for high-risk AI systems under Annex III become applicable (postponed from originally August 2026).
    • Obligations for high-risk AI as a safety component in regulated products under Annex I become applicable (postponed from originally August 2027).
    Triggers, obligations, evidence and sources for EU AI Act
  • EU MDR Regulation (EU) 2017/745 on medical devices Regulation Statutory EU No open deadline

    The EU Medical Device Regulation (MDR, Regulation (EU) 2017/745) governs conformity assessment, CE marking, technical documentation and market surveillance for medical devices in the EU; it has applied since 26 May 2021. Since that date, Switzerland has been a third country for the EU, because the mutual recognition agreement (MRA) was not updated - Swiss manufacturers therefore need an authorised representative in the EU for the EU market. Software can itself be a medical device, and the MDR sets its own requirements on IT security for it in Annex I.

    Since the mutual recognition agreement for medical devices is no longer being updated, Swiss manufacturers need an authorised representative in the EU for the EU market. Software can itself be a medical device, and the MDR sets requirements for the IT security of software and connected products.

    Switzerland
    Swiss law: Medical Devices Ordinance (MedDO), supervised by Swissmedic. For the EU, Switzerland has been a third country since 26 May 2021
    EU
    In force since 26 May 2021
    Typically relevant for
    MedTech
    Industries according to triggers
    MedTech
    Deadlines
    • The MDR (Regulation (EU) 2017/745) becomes applicable; from this date, Switzerland is treated as a third country by the EU in medical device law, because the MRA was not updated.
    Triggers, obligations, evidence and sources for EU MDR
  • FADP Federal Act on Data Protection (Data Protection Act, FADP) Act Statutory CH No open deadline

    The revised Federal Act on Data Protection (FADP, SR 235.1) has, since 1 September 2023, governed the processing of personal data of natural persons by private companies and federal bodies in Switzerland. It obliges controllers, among other things, to data protection by design and by default (Art. 7 FADP), to keep a record of processing activities (Art. 12 FADP, with an exemption for most SMEs), and to notify data security breaches to the Federal Data Protection and Information Commissioner (FDPIC, Art. 24 FADP).

    Governs the processing of personal data by companies in Switzerland, with obligations such as data protection by design, a record of processing activities and notification of data security breaches to the FDPIC.

    Switzerland
    In force since 1 September 2023
    EU
    Does not apply directly
    Typically relevant for
    All companies that process personal data in Switzerland
    Industries according to triggers
    cross-industry
    Deadlines
    • The revised FADP and the Data Protection Ordinance (DPO) enter into force (Art. 74(2) FADP in conjunction with the Federal Council decision of 31 August 2022).
    Triggers, obligations, evidence and sources for FADP
  • FINMA Circular 2023/1 FINMA Circular 2023/1 "Operational risks and resilience – banks" Industry standard Statutory CH No open deadline

    FINMA Circular 2023/1 sets out in detail, for Swiss banks under the Banking Act, how operational risks are to be managed - including ICT risk management, cyber risk management and business continuity management. It replaced the earlier Circular 2008/21. IMPORTANT: the title and content of this file come from secondary sources, not from a document examined in full text on finma.ch - the FINMA website could not be technically read in full text in this research. Before external use, the exact wording should be verified on finma.ch.

    Industries according to triggers
    Financial services
    Deadlines
    • FINMA Circular 2023/1 entered into force per a secondary source (replacing Circular 2008/21); not verified on finma.ch itself.
    Triggers, obligations, evidence and sources for FINMA Circular 2023/1
  • GDPR General Data Protection Regulation Regulation Statutory EU No open deadline

    The EU General Data Protection Regulation (Regulation (EU) 2016/679) has applied since 25 May 2018 and governs the processing of personal data in the EU. Under the market-location principle in Article 3(2), it also covers Swiss companies that offer goods or services to people in the EU or monitor their behaviour - regardless of their own registered seat. Anyone covered generally has to appoint a representative in the EU under Article 27.

    A Swiss company that serves customers in the EU falls under the GDPR under Article 3(2) and as a rule needs a representative in the EU.

    Switzerland
    Applies to Swiss companies that offer goods or services to persons in the EU or monitor their behaviour
    EU
    In force since 25 May 2018
    Typically relevant for
    All industries with EU customers
    Industries according to triggers
    cross-industry
    Deadlines
    • The GDPR becomes applicable across the entire EU.
    Triggers, obligations, evidence and sources for GDPR
  • GeBüV / CO accounting Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts) Act Statutory CH No open deadline

    Anyone obliged to keep accounts under Art. 957 CO must retain business books, accounting records, the annual report and the auditor's report for ten years; the period begins at the end of the financial year (Art. 958f CO - checked in the wording). Retention on paper, electronically or in a comparable form is permitted, provided that conformity with the underlying business transactions is guaranteed and the records can be made legible again at any time. The details of keeping and retention are set out by the Federal Council, based on Art. 958f(4) CO, in the Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431).

    Industries according to triggers
    cross-industry
    Triggers, obligations, evidence and sources for GeBüV / CO accounting
  • GoBD Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD) Regulation Statutory DE No open deadline

    The GoBD is an administrative circular of the German Federal Ministry of Finance (BMF) that sets out in detail how books, records and electronic documents are to be kept properly, recorded immutably and retained under the Fiscal Code (Sections 146 f. AO), together with requirements on procedural documentation and the tax authorities' data access. It is relevant to you if you are obliged to keep books or records in Germany - for example via a German subsidiary, permanent establishment or your own business activity in Germany. Retention periods under Section 147 AO were checked in full text: 10 years for books, records, inventories, annual financial statements and customs documents, 8 years for accounting records, 6 years for commercial and business correspondence.

    Industries according to triggers
    cross-industry
    Deadlines
    • Revised version of the GoBD circular (reference number per a secondary source IV A 4 - S 0316/19/10003), in force from 1 January 2020 - date verified not in the BMF circular itself but only via a secondary source (Wikipedia).
    • First known amendment of the GoBD circular (reference number per a secondary source IV D 2 - S 0316/21/10001:002) - not verified in the BMF circular itself.
    • Further amendment, per a secondary source with a focus on electronic invoices - not verified in the BMF circular itself.
    Triggers, obligations, evidence and sources for GoBD
  • ICT Minimum Standard (StromVV) ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a) Regulation Statutory CH No open deadline

    Since 1 July 2024, the recommendations of the Minimum Standard for Improving ICT Resilience (ICT Minimum Standard, May 2023 edition) have been binding, per the respective protection level under Annex 1a, under Art. 5a of the Electricity Supply Ordinance (StromVV, SR 734.71) for grid operators, for generators and storage operators with a total of 100 MW or more of controllable capacity via a single system, and for service providers able to permanently remote-control such installations. The Swiss Federal Electricity Commission (ElCom) can demand proof of the protection level being reached at any time.

    The Electricity Supply Ordinance obliges grid operators, producers, storage operators and service providers in the Swiss electricity supply sector to meet minimum requirements for information security, graded by protection level. ElCom monitors compliance.

    Switzerland
    Binding since 1 July 2024
    EU
    Does not apply
    Typically relevant for
    Energy
    Industries according to triggers
    Energy
    Deadlines
    • Art. 5a StromVV (protection against cyber threats / ICT Minimum Standard) enters into force (AS 2024 282).
    Triggers, obligations, evidence and sources for ICT Minimum Standard (StromVV)
  • IEC 62304 IEC 62304 – Medical device software – Software life cycle processes Standard Market-driven CH · EU · DE No open deadline

    IEC 62304 sets out how you must safely develop and maintain software for medical devices across the entire life cycle - planning, requirements, architecture, implementation, verification, release, maintenance. It assigns your software to one of three safety classes (A, B or C) based on the risk to patients, users or third parties and, as the recognised 'state of the art', is the accepted basis for meeting the software requirements of the EU MDR and the Swiss MedDO.

    Industries according to triggers
    MedTech
    Triggers, obligations, evidence and sources for IEC 62304
  • IEC 62443 IEC 62443 — Industrial communication networks, network and system security Standard Voluntary CH · EU · DE No open deadline

    IEC 62443 is the international standards series for cybersecurity in industrial automation and control systems (OT/ICS). It is voluntary to apply but is increasingly used as an accepted benchmark for OT security, for example in the context of NIS2 implementation and the Cyber Resilience Act. The series distinguishes requirements for operators (Part 2-1), technical system requirements with four security levels (Part 3-3), and requirements for manufacturers of components (Parts 4-1 and 4-2); certification is possible but not uniformly mandated.

    Industries according to triggers
    cross-industry
    Triggers, obligations, evidence and sources for IEC 62443
  • ISG reporting obligation Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG) Act Statutory CH No open deadline

    Since 1 April 2025, the authorities and organisations individually listed in Art. 74b of the Information Security Act (ISG, SR 128) must report cyberattacks on their IT resources to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery (Art. 74a and 74e ISG). Covered are 21 categories of critical infrastructure named in the act, from universities and energy suppliers to banks and hospitals to cloud providers headquartered in Switzerland; the Federal Council can exempt bodies with only minor impact from the reporting obligation (Art. 74c ISG).

    Operators of critical infrastructure, for example in energy supply or transport, must report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours.

    Switzerland
    In force since 1 April 2025 for operators of critical infrastructure
    EU
    Does not apply
    Typically relevant for
    Energy, transport, other critical infrastructure
    Industries according to triggers
    cross-industry
    Deadlines
    • The reporting obligation for cyberattacks on critical infrastructure (Art. 74a-74f ISG) enters into force (AS 2024 257; AS 2025 173; BBl 2023 84).
    Triggers, obligations, evidence and sources for ISG reporting obligation
  • ISO 13485 ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes Standard Market-driven CH · EU · DE No open deadline

    ISO 13485 is the international standard for quality management systems specifically for medical device manufacturers. As a standard, it is not itself legally mandated, but in practice it is a precondition for obtaining CE marking under the EU MDR or authorisation via Swissmedic under the MedDO: without a certified QM system to ISO 13485, notified bodies and supervisory authorities generally refuse conformity assessment.

    Industries according to triggers
    MedTech
    Triggers, obligations, evidence and sources for ISO 13485
  • ISO 27001 ISO/IEC 27001 Standard Market-driven CH · EU · DE No open deadline

    ISO/IEC 27001 is the internationally recognised standard for an information security management system (ISMS); it is voluntary, but is frequently required by large customers, in tenders and in due-diligence reviews. The current version, ISO/IEC 27001:2022, requires a risk-based management system under chapters 4 to 10 and a justified selection from 93 controls in Annex A. A certificate from an accredited certification body is valid for three years and is confirmed through annual surveillance audits.

    International standard for an information security management system (ISMS). Not a law, but frequently a prerequisite in tenders, with corporate customers and in due diligence reviews. Several regulatory frameworks, for example Part-IS in aviation, permit an ISMS based on this standard.

    Switzerland
    Voluntary, often required by contract
    EU
    Voluntary, often required by contract
    Typically relevant for
    All industries
    Industries according to triggers
    cross-industry
    Triggers, obligations, evidence and sources for ISO 27001
  • ISO 9001 Standard Market-driven CH · EU · DE Next deadline

    ISO 9001 is the internationally recognised standard for quality management systems, voluntary, but often contractually required in manufacturing and supply chains as well as in public tenders. It is built on the PDCA cycle (Plan-Do-Check-Act) and is audited by accredited certification bodies, with a validity of three years and annual surveillance audits. ISO published the new ISO 9001:2026 version on 16 September 2026; existing certificates to ISO 9001:2015 remain valid until 30 September 2029 at the latest.

    International standard for quality management systems. Basis for documented procedures with approvals and evidence. In medical technology, the sector-specific ISO 13485 is added.

    Switzerland
    Voluntary, often required by contract
    EU
    Voluntary, often required by contract
    Typically relevant for
    All industries, especially manufacturing and supply chains
    Industries according to triggers
    cross-industry
    Deadlines
    • Publication of ISO 9001:2026 by ISO (supersedes ISO 9001:2015)
    • Existing certificates to ISO 9001:2015 lose validity at the latest on this date (three-year transition period)
    Triggers, obligations, evidence and sources for ISO 9001
  • Machinery Regulation (EU) 2023/1230 Machinery Regulation (EU Machinery Regulation) Regulation Statutory EU Next deadline

    The EU Machinery Regulation (Regulation (EU) 2023/1230) supersedes the previous Machinery Directive 2006/42/EC and applies from 20 January 2027 to the placing on the market of machinery in the EU. New are explicit cybersecurity requirements: machinery with digital elements or safety-relevant functions must be designed so that its safety functions cannot be compromised by unauthorised digital interference. For Swiss machinery manufacturers, the regulation applies as soon as they place their products on the EU market.

    Industries according to triggers
    cross-industry
    Deadlines
    • Regulation (EU) 2023/1230 applies to the placing on the market of machinery and supersedes the Machinery Directive 2006/42/EC.
    Triggers, obligations, evidence and sources for Machinery Regulation (EU) 2023/1230
  • MedDO Medical Devices Ordinance of 1 July 2020 (SR 812.213) Regulation Statutory CH No open deadline

    The Swiss Medical Devices Ordinance (MedDO, SR 812.213) governs the manufacture, placing on the market and surveillance of medical devices in Switzerland and is supervised by Swissmedic. It was brought into force in a completely revised version on 26 May 2021 and closely follows the substance of the EU MDR (Regulation (EU) 2017/745), but remains independent Swiss law with its own authorisation, registration and supervisory logic via Swissmedic instead of EU authorities.

    Industries according to triggers
    MedTech
    Deadlines
    • Entry into force of the completely revised MedDO (enactment date of the ordinance: 1 July 2020) and of the new ordinance on clinical trials with medical devices; simultaneously the start of Switzerland's third-country status towards the EU in medical device law.
    Triggers, obligations, evidence and sources for MedDO
  • NIS2 Directive on measures for a high common level of cybersecurity across the Union (NIS2) Act Statutory EU · DE No open deadline

    The NIS2 Directive (Directive (EU) 2022/2555) obliges operators in critical and important sectors to manage risk and report significant security incidents. As an EU directive, it does not have direct effect but works via national transposition laws - in Germany via the NIS2 Implementation Act (NIS2UmsuCG), in force since 6 December 2025. NIS2 affects Swiss companies via an EU establishment, via the representative obligation for certain digital services under Art. 26, or because EU customers must demonstrate their supply chain security and pass this requirement on.

    Obligations on risk management and reporting of security incidents for companies in critical sectors. NIS2 affects Swiss companies via an establishment in the EU or because EU customers have to demonstrate the security of their supply chain and pass this requirement on. Providers of certain digital services, for example cloud, data centres or managed services, must designate a representative in the EU if they have no EU establishment.

    Switzerland
    Not directly. Indirectly via EU subsidiaries, EU customers in the supply chain and for certain digital services
    EU
    Transposed into national law, in Germany since 6 December 2025
    Typically relevant for
    Energy, manufacturing, health, transport, digital services
    Industries according to triggers
    cross-industry
    Deadlines
    • Deadline for transposing the NIS2 Directive into national law (Art. 41 NIS2) - missed by several member states, including Germany.
    • The German NIS2 Implementation Act (NIS2UmsuCG) enters into force.
    • The BSI portal for NIS2 registration goes live.
    Triggers, obligations, evidence and sources for NIS2
  • Part-IS EU regulations on information security in aviation (Part-IS) Regulation Statutory EU · CH No open deadline

    Part-IS requires aviation organisations - from airports to airlines to air navigation services - to operate an information security management system (ISMS), which may be based on ISO/IEC 27001, together with risk management and reporting of security-relevant occurrences. The obligation applies in stages: from 16 October 2025 for airport operators, apron management services, and design and production organisations; from 22 February 2026 for airlines, maintenance organisations, CAMOs, training organisations and air navigation services. In Switzerland, Part-IS is implemented by FOCA; the exact legal anchoring via the Air Transport Agreement was not examined in the wording in this research.

    Aviation organisations such as airports, airlines, maintenance organisations and air navigation service providers must operate an information security management system, which can be based on ISO 27001, and report security incidents.

    Switzerland
    Implemented by FOCA
    EU
    Since 16 October 2025 and 22 February 2026, depending on the organisation
    Typically relevant for
    Aviation
    Industries according to triggers
    Aviation
    Deadlines
    • Part-IS applies to airport operators, apron management services, and design and production organisations (Delegated Regulation (EU) 2022/1645).
    • Part-IS applies to air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers, as well as the competent supervisory authorities and EASA (Implementing Regulation (EU) 2023/203).
    Triggers, obligations, evidence and sources for Part-IS
  • TISAX TISAX (Trusted Information Security Assessment Exchange) Industry standard Market-driven CH · EU · DE No open deadline

    TISAX is an information security assessment procedure for the automotive supply chain, run by the ENX Association based on the VDA ISA assessment catalogue. It is not a law and not a public certificate, but a result label shared via the ENX portal and contractually required by vehicle manufacturers and large suppliers. The ENX Association was founded by several European vehicle manufacturers, national automotive associations and suppliers; TISAX is therefore not limited to German manufacturers but is carried by the European industry and performed by audit providers worldwide.

    Assessment procedure for information security in the automotive supply chain, run by the ENX Association on the basis of the VDA ISA catalogue. Not a law and not a certificate, but a label that vehicle manufacturers and large suppliers require from their suppliers by contract.

    Switzerland
    Contractual, in the automotive supply chain
    EU
    Contractual, in the automotive supply chain
    Typically relevant for
    Manufacturing, suppliers to the automotive industry
    Industries according to triggers
    Manufacturing
    Triggers, obligations, evidence and sources for TISAX

03 Evidence

Conformant or certified?

Conformant does not mean certified, but in customer due-diligence reviews it makes a real difference.

  • Conformity means: you meet the requirements and can demonstrate it, with documentation, approvals and records.
  • Certification means: an accredited body has audited and confirmed it.
  • In practice, customers ask about both in supplier assessments and security questionnaires. Demonstrable conformity shortens these reviews considerably, even without a certificate.

05 Formats

Watch, listen, take away.

Film 03The audit is comingIn production
Podcast Situation Picture · Episode 05Conformant or certified?In preparation
Download · Situation Briefing 05Situational Awareness from the perspective of QM and complianceIn preparation

The full version of this page: Full text as Markdown

FAQ Answers

Questions about regulation.

Does NIS2 apply to Swiss companies?

Not directly. NIS2 is an EU directive. It affects Swiss companies via an establishment in the EU, because EU customers have to demonstrate the security of their supply chain and pass this requirement on by contract, or when they offer certain digital services such as cloud or managed services in the EU. A representative in the EU must then be designated.

Since when has the new Swiss data protection act applied?

Since 1 September 2023. It applies to all companies that process personal data in Switzerland. Anyone serving customers in the EU must also observe the GDPR.

Does the EU AI Act apply to Swiss companies?

Yes, if they place AI systems on the market in the EU or the output of their AI systems is used in the EU. The obligations have applied in stages since February 2025. The obligations for high-risk systems apply from December 2027, for AI in regulated products from August 2028.

What is the difference between ISO 27001 and TISAX?

ISO 27001 is an international standard for information security management systems, with a certificate. TISAX is an assessment procedure of the automotive industry based on the VDA ISA catalogue, with a label instead of a certificate, and is required by vehicle manufacturers by contract.

Does the EU MDR apply in Switzerland?

In Switzerland, the Medical Devices Ordinance (MedDO) applies, with Swissmedic as supervisory authority. For access to the EU market, the EU MDR applies. Since 26 May 2021, the EU has treated Switzerland as a third country for medical devices, so Swiss manufacturers need an authorised representative in the EU.

Does a start-up have to be certified to ISO 27001?

Not by law. But corporate customers, tenders and investors often ask for it. It makes sense to set up processes early so that a certification later is a small step and not a rebuild.

Which rules apply to you?

Thirty minutes, no presentation.

Ivo Schönberner on a lakeside promenade in the morning light