Market Access vs. Sovereignty? Analysing the Brussels Effect of European Cybersecurity Requirements on Switzerland: The Case of NIS 2
How does EU law shape Swiss cybersecurity? This thesis explores how the EU's NIS 2 Directive, through the “Brussels Effect”, contractually forces Swiss companies to upgrade defences to keep doing business in Europe, transforming corporate responsibility across Switzerland.
Gombert, Lasse, 2026
Art der Arbeit Bachelor Thesis
Auftraggebende FHNW - HSW - IWI
Betreuende Dozierende Grimberg, Frank
Views: 1
Swiss firms are deeply integrated into European supply chains. Under new EU rules, European partners must audit their suppliers' cybersecurity. If Swiss companies fail to match these standards, they risk losing access to the European market. While Swiss national law requires reporting major attacks within 24 hours, it lacks the EU's strict boardroom training and direct personal liability. Swiss companies face a confusing “compliance thicket” of overlapping standards while trying to resolve a vacuum in board accountability.
Using an exploratory design, this study has three phases. First, a systematic document review compares Swiss and European laws. Second, a technical comparison maps NIS 2 against standard security controls (ISO 27001 and Swiss guidelines) using the NIST CSF 2.0 framework. Third, interviews with four cybersecurity experts (such as a CISO and a security engineer) validate these findings with real-world industry perspectives.
While having an ISO 27001 certification covers most of technical requirements, it leaves critical gaps in board liability and multi-stage reporting workflows. To avoid repetitive audits (audit fatigue") and empty “checkbox compliance”, Swiss companies must shift toward “coordinated assurance”. This means aligning risk, compliance, and auditing into a single unified model.The benefit for the client, and Swiss firms is a practical roadmap to “equivalence-by-design”. This approach bridges the boardroom governance gap and transforms compliance from an annoying administrative burden into a competitive advantage. It ensures Swiss companies remain trusted, secure partners in European trade without drowning in paperwork.
Studiengang: Business Information Technology (Bachelor)
Keywords Market Access, NIS 2 Directive, Sovereignty, Compliance Thicket, ISO/IEC 27001, ISG, IKT, Brussels Effect
Vertraulichkeit: vertraulich