Compliance: standards and laws
Which IT regulations apply to your company?
That depends on three things: your industry, your markets and your customers. This page assesses the most important rules and does not replace legal advice.
01 Regulatory Check
Which standards apply to your industry?
Six short questions, then the evaluation. The check compares your details with 22 standards and laws in our knowledge base and shows what may apply to you and why. It calculates in your browser according to fixed rules, without a language model.
Step 1 of 6
Role
Evaluation
Important
The results are generated from the information you provided and may be incomplete. The assessment can therefore be wrong. This is not legal advice. Knowledge base as of: 24 September 2026 (22 standards).
Receive the detailed evaluation
With the reason for each standard why it applies to you, with obligations, evidence and deadlines. You will see it here after submitting and receive it by email. We need the company name to assign the evaluation to your company.
Your detailed evaluation
The results are generated from the information you provided and may be incomplete. The assessment can therefore be wrong. This is not legal advice. Knowledge base as of: 24 September 2026. Source: sacosi.ch/en/norms
02 Overview
What applies in Switzerland, what in the EU?
All 22 rules of the knowledge base in one list. As of: September 2026.
22 of 22 standards
-
CH AI Regulation Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence) Next deadline
Switzerland does not yet have an AI-specific act. On 12 February 2025, the Federal Council discussed a stocktaking report on possible regulatory approaches to artificial intelligence and instructed the Federal Office of Justice (FOJ) to draft a consultation bill by the end of 2026, implementing in particular the Council of Europe's Framework Convention on Artificial Intelligence. Until this process is concluded, there is no horizontal, AI-specific legal obligation in Switzerland; existing obligations, for instance under the FADP, already apply today regardless.
- Industries according to triggers
- cross-industry
- Deadlines
- The Federal Council discusses a stocktaking report on possible AI regulatory approaches and instructs several offices, including the Federal Office of Justice, to develop regulatory measures.
- Target date: by this point, the Federal Office of Justice is to submit a consultation bill for legally binding measures as well as an implementation plan for non-binding measures. This is a milestone for the bill, not the entry-into-force date of an act.
-
CRA Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act) Next deadline
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets EU-wide, uniform cybersecurity requirements for hardware and software products with digital elements across their entire life cycle. Manufacturers must report actively exploited vulnerabilities and severe security incidents in stages - the reporting obligations have applied since 11 September 2026, with the regulation's full application from 11 December 2027. For Swiss manufacturers, the CRA applies as soon as they place products with digital elements on the EU market.
Cybersecurity requirements for hardware and software with digital elements across the entire life cycle. Manufacturers must report actively exploited vulnerabilities and severe incidents.
- Switzerland
- Applies to Swiss manufacturers that sell products with digital elements in the EU
- EU
- Reporting obligations since 11 September 2026, full application from 11 December 2027
- Typically relevant for
- Manufacturing, MedTech, manufacturers of connected products
- Industries according to triggers
- cross-industry
- Deadlines
- Notifying authorities must have established the procedures for conformity assessment bodies.
- Reporting obligations for manufacturers (actively exploited vulnerabilities, severe incidents) become applicable.
- The Cyber Resilience Act applies in full, including conformity assessment obligations for all affected products.
-
DORA Digital Operational Resilience Act (Regulation (EU) 2022/2554) No open deadline
DORA obliges EU financial entities - banks, insurers, investment firms, payment service providers and others - to comply with uniform requirements for ICT risk management, incident reporting, resilience testing and the management of ICT third-party providers. The regulation has applied directly in the EU since 17 January 2025. For Swiss companies this is, per the client's assessment, a candidate not yet conclusively examined: relevant above all are Swiss financial institutions with an EU establishment, as well as Swiss ICT providers who supply financial entities in the EU/EEA.
- Industries according to triggers
- Financial services
- Deadlines
- DORA becomes binding and applicable in the EU/EEA (regulation in force since 17 January 2023, applicable from 17 January 2025 per the secondary sources examined).
-
EU AI Act Regulation laying down harmonised rules on artificial intelligence (EU AI Act) Next deadline
The EU AI Act (Regulation (EU) 2024/1689) regulates AI systems in stages by risk class and applies to providers and deployers whose AI systems are placed on the market in the EU or whose output is used there - regardless of registered seat. Bans on certain practices have applied since February 2025, rules for general-purpose AI models since August 2025, and transparency obligations since August 2026. The amending regulation (EU) 2026/1744 ('Digital Omnibus', published on 24 July 2026) has postponed the obligations for high-risk systems under Annex III to December 2027 and for AI in regulated products under Annex I to August 2028.
The obligations apply in stages: prohibitions since February 2025, rules for general-purpose AI models since August 2025, transparency obligations since August 2026. The obligations for high-risk systems were postponed in 2026, to December 2027 and, for AI in regulated products, to August 2028. Switzerland is preparing its own bill by the end of 2026.
- Switzerland
- Applies to Swiss providers that place AI systems on the market in the EU or whose output is used in the EU
- EU
- Phased in since 2 February 2025
- Typically relevant for
- All industries that use or provide AI
- Industries according to triggers
- cross-industry
- Deadlines
- Bans on certain AI practices and the obligation on AI literacy become applicable.
- Rules for general-purpose AI (GPAI) models become applicable.
- The amending regulation (EU) 2026/1744 ('Digital Omnibus') is published in the Official Journal.
- Transparency obligations under Art. 50 become applicable.
- The transition period for transparency obligations for systems already on the market ends; two further bans under Art. 5 enter into force.
- Obligations for high-risk AI systems under Annex III become applicable (postponed from originally August 2026).
- Obligations for high-risk AI as a safety component in regulated products under Annex I become applicable (postponed from originally August 2027).
-
EU MDR Regulation (EU) 2017/745 on medical devices No open deadline
The EU Medical Device Regulation (MDR, Regulation (EU) 2017/745) governs conformity assessment, CE marking, technical documentation and market surveillance for medical devices in the EU; it has applied since 26 May 2021. Since that date, Switzerland has been a third country for the EU, because the mutual recognition agreement (MRA) was not updated - Swiss manufacturers therefore need an authorised representative in the EU for the EU market. Software can itself be a medical device, and the MDR sets its own requirements on IT security for it in Annex I.
Since the mutual recognition agreement for medical devices is no longer being updated, Swiss manufacturers need an authorised representative in the EU for the EU market. Software can itself be a medical device, and the MDR sets requirements for the IT security of software and connected products.
- Switzerland
- Swiss law: Medical Devices Ordinance (MedDO), supervised by Swissmedic. For the EU, Switzerland has been a third country since 26 May 2021
- EU
- In force since 26 May 2021
- Typically relevant for
- MedTech
- Industries according to triggers
- MedTech
- Deadlines
- The MDR (Regulation (EU) 2017/745) becomes applicable; from this date, Switzerland is treated as a third country by the EU in medical device law, because the MRA was not updated.
-
FADP Federal Act on Data Protection (Data Protection Act, FADP) No open deadline
The revised Federal Act on Data Protection (FADP, SR 235.1) has, since 1 September 2023, governed the processing of personal data of natural persons by private companies and federal bodies in Switzerland. It obliges controllers, among other things, to data protection by design and by default (Art. 7 FADP), to keep a record of processing activities (Art. 12 FADP, with an exemption for most SMEs), and to notify data security breaches to the Federal Data Protection and Information Commissioner (FDPIC, Art. 24 FADP).
Governs the processing of personal data by companies in Switzerland, with obligations such as data protection by design, a record of processing activities and notification of data security breaches to the FDPIC.
- Switzerland
- In force since 1 September 2023
- EU
- Does not apply directly
- Typically relevant for
- All companies that process personal data in Switzerland
- Industries according to triggers
- cross-industry
- Deadlines
- The revised FADP and the Data Protection Ordinance (DPO) enter into force (Art. 74(2) FADP in conjunction with the Federal Council decision of 31 August 2022).
-
FINMA Circular 2023/1 FINMA Circular 2023/1 "Operational risks and resilience – banks" No open deadline
FINMA Circular 2023/1 sets out in detail, for Swiss banks under the Banking Act, how operational risks are to be managed - including ICT risk management, cyber risk management and business continuity management. It replaced the earlier Circular 2008/21. IMPORTANT: the title and content of this file come from secondary sources, not from a document examined in full text on finma.ch - the FINMA website could not be technically read in full text in this research. Before external use, the exact wording should be verified on finma.ch.
- Industries according to triggers
- Financial services
- Deadlines
- FINMA Circular 2023/1 entered into force per a secondary source (replacing Circular 2008/21); not verified on finma.ch itself.
-
GDPR General Data Protection Regulation No open deadline
The EU General Data Protection Regulation (Regulation (EU) 2016/679) has applied since 25 May 2018 and governs the processing of personal data in the EU. Under the market-location principle in Article 3(2), it also covers Swiss companies that offer goods or services to people in the EU or monitor their behaviour - regardless of their own registered seat. Anyone covered generally has to appoint a representative in the EU under Article 27.
A Swiss company that serves customers in the EU falls under the GDPR under Article 3(2) and as a rule needs a representative in the EU.
- Switzerland
- Applies to Swiss companies that offer goods or services to persons in the EU or monitor their behaviour
- EU
- In force since 25 May 2018
- Typically relevant for
- All industries with EU customers
- Industries according to triggers
- cross-industry
- Deadlines
- The GDPR becomes applicable across the entire EU.
-
GeBüV / CO accounting Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts) No open deadline
Anyone obliged to keep accounts under Art. 957 CO must retain business books, accounting records, the annual report and the auditor's report for ten years; the period begins at the end of the financial year (Art. 958f CO - checked in the wording). Retention on paper, electronically or in a comparable form is permitted, provided that conformity with the underlying business transactions is guaranteed and the records can be made legible again at any time. The details of keeping and retention are set out by the Federal Council, based on Art. 958f(4) CO, in the Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431).
- Industries according to triggers
- cross-industry
-
GoBD Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD) No open deadline
The GoBD is an administrative circular of the German Federal Ministry of Finance (BMF) that sets out in detail how books, records and electronic documents are to be kept properly, recorded immutably and retained under the Fiscal Code (Sections 146 f. AO), together with requirements on procedural documentation and the tax authorities' data access. It is relevant to you if you are obliged to keep books or records in Germany - for example via a German subsidiary, permanent establishment or your own business activity in Germany. Retention periods under Section 147 AO were checked in full text: 10 years for books, records, inventories, annual financial statements and customs documents, 8 years for accounting records, 6 years for commercial and business correspondence.
- Industries according to triggers
- cross-industry
- Deadlines
- Revised version of the GoBD circular (reference number per a secondary source IV A 4 - S 0316/19/10003), in force from 1 January 2020 - date verified not in the BMF circular itself but only via a secondary source (Wikipedia).
- First known amendment of the GoBD circular (reference number per a secondary source IV D 2 - S 0316/21/10001:002) - not verified in the BMF circular itself.
- Further amendment, per a secondary source with a focus on electronic invoices - not verified in the BMF circular itself.
-
ICT Minimum Standard (StromVV) ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a) No open deadline
Since 1 July 2024, the recommendations of the Minimum Standard for Improving ICT Resilience (ICT Minimum Standard, May 2023 edition) have been binding, per the respective protection level under Annex 1a, under Art. 5a of the Electricity Supply Ordinance (StromVV, SR 734.71) for grid operators, for generators and storage operators with a total of 100 MW or more of controllable capacity via a single system, and for service providers able to permanently remote-control such installations. The Swiss Federal Electricity Commission (ElCom) can demand proof of the protection level being reached at any time.
The Electricity Supply Ordinance obliges grid operators, producers, storage operators and service providers in the Swiss electricity supply sector to meet minimum requirements for information security, graded by protection level. ElCom monitors compliance.
- Switzerland
- Binding since 1 July 2024
- EU
- Does not apply
- Typically relevant for
- Energy
- Industries according to triggers
- Energy
- Deadlines
- Art. 5a StromVV (protection against cyber threats / ICT Minimum Standard) enters into force (AS 2024 282).
-
IEC 62304 IEC 62304 – Medical device software – Software life cycle processes No open deadline
IEC 62304 sets out how you must safely develop and maintain software for medical devices across the entire life cycle - planning, requirements, architecture, implementation, verification, release, maintenance. It assigns your software to one of three safety classes (A, B or C) based on the risk to patients, users or third parties and, as the recognised 'state of the art', is the accepted basis for meeting the software requirements of the EU MDR and the Swiss MedDO.
- Industries according to triggers
- MedTech
-
IEC 62443 IEC 62443 — Industrial communication networks, network and system security No open deadline
IEC 62443 is the international standards series for cybersecurity in industrial automation and control systems (OT/ICS). It is voluntary to apply but is increasingly used as an accepted benchmark for OT security, for example in the context of NIS2 implementation and the Cyber Resilience Act. The series distinguishes requirements for operators (Part 2-1), technical system requirements with four security levels (Part 3-3), and requirements for manufacturers of components (Parts 4-1 and 4-2); certification is possible but not uniformly mandated.
- Industries according to triggers
- cross-industry
-
ISG reporting obligation Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG) No open deadline
Since 1 April 2025, the authorities and organisations individually listed in Art. 74b of the Information Security Act (ISG, SR 128) must report cyberattacks on their IT resources to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery (Art. 74a and 74e ISG). Covered are 21 categories of critical infrastructure named in the act, from universities and energy suppliers to banks and hospitals to cloud providers headquartered in Switzerland; the Federal Council can exempt bodies with only minor impact from the reporting obligation (Art. 74c ISG).
Operators of critical infrastructure, for example in energy supply or transport, must report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours.
- Switzerland
- In force since 1 April 2025 for operators of critical infrastructure
- EU
- Does not apply
- Typically relevant for
- Energy, transport, other critical infrastructure
- Industries according to triggers
- cross-industry
- Deadlines
- The reporting obligation for cyberattacks on critical infrastructure (Art. 74a-74f ISG) enters into force (AS 2024 257; AS 2025 173; BBl 2023 84).
-
ISO 13485 ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes No open deadline
ISO 13485 is the international standard for quality management systems specifically for medical device manufacturers. As a standard, it is not itself legally mandated, but in practice it is a precondition for obtaining CE marking under the EU MDR or authorisation via Swissmedic under the MedDO: without a certified QM system to ISO 13485, notified bodies and supervisory authorities generally refuse conformity assessment.
- Industries according to triggers
- MedTech
-
ISO 27001 ISO/IEC 27001 No open deadline
ISO/IEC 27001 is the internationally recognised standard for an information security management system (ISMS); it is voluntary, but is frequently required by large customers, in tenders and in due-diligence reviews. The current version, ISO/IEC 27001:2022, requires a risk-based management system under chapters 4 to 10 and a justified selection from 93 controls in Annex A. A certificate from an accredited certification body is valid for three years and is confirmed through annual surveillance audits.
International standard for an information security management system (ISMS). Not a law, but frequently a prerequisite in tenders, with corporate customers and in due diligence reviews. Several regulatory frameworks, for example Part-IS in aviation, permit an ISMS based on this standard.
- Switzerland
- Voluntary, often required by contract
- EU
- Voluntary, often required by contract
- Typically relevant for
- All industries
- Industries according to triggers
- cross-industry
-
ISO 9001 Next deadline
ISO 9001 is the internationally recognised standard for quality management systems, voluntary, but often contractually required in manufacturing and supply chains as well as in public tenders. It is built on the PDCA cycle (Plan-Do-Check-Act) and is audited by accredited certification bodies, with a validity of three years and annual surveillance audits. ISO published the new ISO 9001:2026 version on 16 September 2026; existing certificates to ISO 9001:2015 remain valid until 30 September 2029 at the latest.
International standard for quality management systems. Basis for documented procedures with approvals and evidence. In medical technology, the sector-specific ISO 13485 is added.
- Switzerland
- Voluntary, often required by contract
- EU
- Voluntary, often required by contract
- Typically relevant for
- All industries, especially manufacturing and supply chains
- Industries according to triggers
- cross-industry
- Deadlines
- Publication of ISO 9001:2026 by ISO (supersedes ISO 9001:2015)
- Existing certificates to ISO 9001:2015 lose validity at the latest on this date (three-year transition period)
-
Machinery Regulation (EU) 2023/1230 Machinery Regulation (EU Machinery Regulation) Next deadline
The EU Machinery Regulation (Regulation (EU) 2023/1230) supersedes the previous Machinery Directive 2006/42/EC and applies from 20 January 2027 to the placing on the market of machinery in the EU. New are explicit cybersecurity requirements: machinery with digital elements or safety-relevant functions must be designed so that its safety functions cannot be compromised by unauthorised digital interference. For Swiss machinery manufacturers, the regulation applies as soon as they place their products on the EU market.
- Industries according to triggers
- cross-industry
- Deadlines
- Regulation (EU) 2023/1230 applies to the placing on the market of machinery and supersedes the Machinery Directive 2006/42/EC.
-
MedDO Medical Devices Ordinance of 1 July 2020 (SR 812.213) No open deadline
The Swiss Medical Devices Ordinance (MedDO, SR 812.213) governs the manufacture, placing on the market and surveillance of medical devices in Switzerland and is supervised by Swissmedic. It was brought into force in a completely revised version on 26 May 2021 and closely follows the substance of the EU MDR (Regulation (EU) 2017/745), but remains independent Swiss law with its own authorisation, registration and supervisory logic via Swissmedic instead of EU authorities.
- Industries according to triggers
- MedTech
- Deadlines
- Entry into force of the completely revised MedDO (enactment date of the ordinance: 1 July 2020) and of the new ordinance on clinical trials with medical devices; simultaneously the start of Switzerland's third-country status towards the EU in medical device law.
-
NIS2 Directive on measures for a high common level of cybersecurity across the Union (NIS2) No open deadline
The NIS2 Directive (Directive (EU) 2022/2555) obliges operators in critical and important sectors to manage risk and report significant security incidents. As an EU directive, it does not have direct effect but works via national transposition laws - in Germany via the NIS2 Implementation Act (NIS2UmsuCG), in force since 6 December 2025. NIS2 affects Swiss companies via an EU establishment, via the representative obligation for certain digital services under Art. 26, or because EU customers must demonstrate their supply chain security and pass this requirement on.
Obligations on risk management and reporting of security incidents for companies in critical sectors. NIS2 affects Swiss companies via an establishment in the EU or because EU customers have to demonstrate the security of their supply chain and pass this requirement on. Providers of certain digital services, for example cloud, data centres or managed services, must designate a representative in the EU if they have no EU establishment.
- Switzerland
- Not directly. Indirectly via EU subsidiaries, EU customers in the supply chain and for certain digital services
- EU
- Transposed into national law, in Germany since 6 December 2025
- Typically relevant for
- Energy, manufacturing, health, transport, digital services
- Industries according to triggers
- cross-industry
- Deadlines
- Deadline for transposing the NIS2 Directive into national law (Art. 41 NIS2) - missed by several member states, including Germany.
- The German NIS2 Implementation Act (NIS2UmsuCG) enters into force.
- The BSI portal for NIS2 registration goes live.
-
Part-IS EU regulations on information security in aviation (Part-IS) No open deadline
Part-IS requires aviation organisations - from airports to airlines to air navigation services - to operate an information security management system (ISMS), which may be based on ISO/IEC 27001, together with risk management and reporting of security-relevant occurrences. The obligation applies in stages: from 16 October 2025 for airport operators, apron management services, and design and production organisations; from 22 February 2026 for airlines, maintenance organisations, CAMOs, training organisations and air navigation services. In Switzerland, Part-IS is implemented by FOCA; the exact legal anchoring via the Air Transport Agreement was not examined in the wording in this research.
Aviation organisations such as airports, airlines, maintenance organisations and air navigation service providers must operate an information security management system, which can be based on ISO 27001, and report security incidents.
- Switzerland
- Implemented by FOCA
- EU
- Since 16 October 2025 and 22 February 2026, depending on the organisation
- Typically relevant for
- Aviation
- Industries according to triggers
- Aviation
- Deadlines
- Part-IS applies to airport operators, apron management services, and design and production organisations (Delegated Regulation (EU) 2022/1645).
- Part-IS applies to air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers, as well as the competent supervisory authorities and EASA (Implementing Regulation (EU) 2023/203).
-
TISAX TISAX (Trusted Information Security Assessment Exchange) No open deadline
TISAX is an information security assessment procedure for the automotive supply chain, run by the ENX Association based on the VDA ISA assessment catalogue. It is not a law and not a public certificate, but a result label shared via the ENX portal and contractually required by vehicle manufacturers and large suppliers. The ENX Association was founded by several European vehicle manufacturers, national automotive associations and suppliers; TISAX is therefore not limited to German manufacturers but is carried by the European industry and performed by audit providers worldwide.
Assessment procedure for information security in the automotive supply chain, run by the ENX Association on the basis of the VDA ISA catalogue. Not a law and not a certificate, but a label that vehicle manufacturers and large suppliers require from their suppliers by contract.
- Switzerland
- Contractual, in the automotive supply chain
- EU
- Contractual, in the automotive supply chain
- Typically relevant for
- Manufacturing, suppliers to the automotive industry
- Industries according to triggers
- Manufacturing
No standard matches these filters.
03 Evidence
Conformant or certified?
Conformant does not mean certified, but in customer due-diligence reviews it makes a real difference.
- Conformity means: you meet the requirements and can demonstrate it, with documentation, approvals and records.
- Certification means: an accredited body has audited and confirmed it.
- In practice, customers ask about both in supplier assessments and security questionnaires. Demonstrable conformity shortens these reviews considerably, even without a certificate.
04 Roadmap
How is a compliance roadmap created?
From the situation picture: first clarify which rules really apply, then implement in the order of risk and business impact.
- Assess
- Prioritise and build in
- Evidence
In detail Sources (13), as of 24 September 2026
- Federal Act on Data Protection (FADP), SR 235.1, in force since 1 September 2023
- Regulation (EU) 2016/679, General Data Protection Regulation, Articles 3 and 27
- Directive (EU) 2022/2555 (NIS2), in particular Articles 21 and 26
- BSI: NIS2 Implementation Act in force, press release of 5 December 2025
- Federal Office for Cybersecurity BACS: reporting obligation for cyberattacks on critical infrastructure
- Regulation (EU) 2024/1689 (AI Act), amended by Regulation (EU) 2026/1744, published on 24 July 2026
- Federal Chancellery: artificial intelligence, status of Swiss regulation
- Regulation (EU) 2017/745 on medical devices
- Swissmedic: new regulation for medical devices from 26 May 2021
- European Commission: Cyber Resilience Act, reporting obligations
- Electricity Supply Ordinance, amendment AS 2024 282 (ICT minimum standard, Article 5a)
- FOCA: EU regulations on information security (Part-IS)
- ENX Association: TISAX
This overview is a professional assessment, not legal advice. The legal assessment of any individual case belongs in a proper legal review.
05 Formats
Watch, listen, take away.
The full version of this page: Full text as Markdown
FAQ Answers
Questions about regulation.
Does NIS2 apply to Swiss companies?
Not directly. NIS2 is an EU directive. It affects Swiss companies via an establishment in the EU, because EU customers have to demonstrate the security of their supply chain and pass this requirement on by contract, or when they offer certain digital services such as cloud or managed services in the EU. A representative in the EU must then be designated.
Since when has the new Swiss data protection act applied?
Since 1 September 2023. It applies to all companies that process personal data in Switzerland. Anyone serving customers in the EU must also observe the GDPR.
Does the EU AI Act apply to Swiss companies?
Yes, if they place AI systems on the market in the EU or the output of their AI systems is used in the EU. The obligations have applied in stages since February 2025. The obligations for high-risk systems apply from December 2027, for AI in regulated products from August 2028.
What is the difference between ISO 27001 and TISAX?
ISO 27001 is an international standard for information security management systems, with a certificate. TISAX is an assessment procedure of the automotive industry based on the VDA ISA catalogue, with a label instead of a certificate, and is required by vehicle manufacturers by contract.
Does the EU MDR apply in Switzerland?
In Switzerland, the Medical Devices Ordinance (MedDO) applies, with Swissmedic as supervisory authority. For access to the EU market, the EU MDR applies. Since 26 May 2021, the EU has treated Switzerland as a third country for medical devices, so Swiss manufacturers need an authorised representative in the EU.
Does a start-up have to be certified to ISO 27001?
Not by law. But corporate customers, tenders and investors often ask for it. It makes sense to set up processes early so that a certification later is a small step and not a rebuild.
Which rules apply to you?
Thirty minutes, no presentation.
