On 1 July 2026, ENISA launched the survey that feeds its NIS360 2027 report — the annual maturity-and-criticality assessment of essential and important entities across the EU. The survey is open to national competent authorities and entities of high criticality until 30 October 2026. What many Swiss security teams have not yet internalised is that NIS360 is not an academic exercise: the maturity scores it produces are the primary input regulators use to decide where to concentrate enforcement energy the following year. Sectors that score low become audit priorities. Sectors that score high earn relative supervisory breathing room. For Swiss holding companies with EU subsidiaries — banks, insurers, energy operators, digital-infrastructure providers — this autumn's survey is the first moment to shape how hard 2027 will be.
What NIS360 Measures and Why the Scores Matter
NIS360 assesses each sector across two axes: criticality (how significant a disruption would be to the EU economy or society) and maturity (how far organisations in that sector have implemented the security measures NIS2 requires). The 2026 edition, covering data from 2025, placed banking, electricity, and telecoms at the top of the maturity ranking. Health and gas scored materially lower. The consequence of that gap is visible in supervisory calendars: health-sector entities in Germany, France, and Italy faced the first systematic NIS2 audit waves in early 2026, precisely because NIS360 2026 identified health as critically important but insufficiently mature.
The 2027 edition will use the same methodology. Sectors that have not closed the maturity gap between the 2026 and 2027 surveys will attract the same enforcement attention. The difference is that enforcement is no longer a future risk: Belgium has already imposed a €185,000 fine, Italy a €450,000 fine, and the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice on 8 July 2026 for failing to fully transpose NIS2. The regulatory machine is running.
Which Swiss Structures Are in Scope
NIS2 applies to entities established in the EU that meet the size and sector thresholds — mid-size and large operators in the sixteen critical sectors, plus any entity a member state designates regardless of size due to its role in the national economy. Swiss holding companies are not directly regulated, but their EU-incorporated subsidiaries are. A Swiss bank with a licensed entity in Frankfurt, a Swiss insurer with a Dutch subsidiary, or a Swiss cloud provider with a Belgian legal entity all have NIS2-in-scope operations that are subject to both the NIS360 survey and the enforcement consequences that follow from it.
The personal liability provision — Article 20 — runs through the management body of the in-scope entity, not the Swiss parent. However, board members of the Swiss parent who also sit on the subsidiary board, or who exercise effective management influence, can be named in enforcement actions. The practical implication is that Swiss executives with cross-border board roles need documented cybersecurity oversight now, not after an incident triggers a regulator's attention.
Reading the NIS360 2026 Data as a Forward Indicator
The NIS360 2026 report published sector-by-sector maturity scores that are publicly available and should be mandatory reading for every Swiss compliance team with EU exposure. Key findings from 2026 that will set the enforcement baseline for 2027:
Banking and financial market infrastructure scored highest on maturity — regulators expect this lead to be maintained, and any regression will draw immediate scrutiny from the ECB's supervisory function and national competent authorities. Swiss FINMA-regulated banks with EU presences need to demonstrate that their NIS2 maturity matches or exceeds the sector average, not just that they have a programme in place.
Health remained the sector with the widest gap between criticality and maturity. Swiss medtech companies and hospital groups with EU operations face the hardest supervisory environment in 2027. Any entity in this sector that has not completed a gap assessment against Article 21's ten minimum security measures — including supply chain security, incident handling, and multi-factor authentication — should treat the NIS360 survey deadline of 30 October as a forcing function.
Digital infrastructure — including cloud service providers, DNS operators, and data centres — scored moderately but with high variance. Swiss cloud providers serving EU customers through EU-established entities should compare their controls against the ENISA cloud security baseline that NIS360 uses as its reference, because that is the document inspectors will carry into on-site audits.
What Swiss Compliance Teams Should Do Before 30 October
The NIS360 survey is submitted by national competent authorities, not by individual entities. But the data those authorities submit is drawn from the regulatory reporting and supervisory exchanges they have already conducted with in-scope entities. Swiss groups whose EU subsidiaries have engaged actively with national regulators — through incident notifications, threat-intelligence sharing, and supervisory dialogues — will be represented in the maturity data more favourably than those that have kept a low profile.
There is still time to shift the picture. A subsidiary that completes its NIS2 registration, submits any outstanding incident notifications, and requests a compliance dialogue with its national competent authority before October will generate the kind of evidence that flows into NIS360 data. A subsidiary that has done none of these things will not.
◆ Key Takeaway
The ENISA NIS360 2027 survey closes 30 October 2026. The maturity scores it produces determine which sectors face the heaviest NIS2 enforcement in 2027. Swiss holding companies cannot afford to treat this as an EU-only exercise: their EU subsidiaries are in scope, their executives may carry personal liability, and the enforcement consequences — fines, audit obligations, and supervisory mandates — are now real and documented across multiple member states.
- Map every EU-incorporated subsidiary against NIS2 sector definitions and size thresholds; assume mid-size entities are in scope unless proven otherwise.
- Complete NIS2 registration with the relevant national competent authority for each in-scope entity before 30 October — registration is the baseline evidence of compliance engagement.
- Run a gap assessment against Article 21's ten minimum security measures for each in-scope entity and document the findings at board level; Article 20 requires the management body to approve the risk measures, not merely be informed of them.
- Benchmark each subsidiary's sector against the NIS360 2026 maturity scores — entities in health, gas, and waste management should treat the gap as a 2026 remediation priority, not a 2027 aspiration.
- Establish an incident reporting chain from each in-scope EU subsidiary to its national CSIRT that can meet the 24-hour initial notification deadline; test it with a tabletop exercise before year-end.
- For Swiss executives holding dual board seats (Swiss parent and EU subsidiary), obtain formal legal advice on the scope of Article 20 personal liability under the laws of each relevant member state.
- Engage the relevant national competent authority proactively — request a compliance dialogue, share threat-intelligence findings, and participate in any sector-specific ISAC the authority runs; active engagement improves supervisory relationships and the data that flows into NIS360.
NIS2 enforcement in the EU passed the theoretical stage in 2026. With NIS360 2027 data collection open through October, the next twelve months will determine whether Swiss groups with EU operations enter 2027 as compliant entities with documented maturity — or as audit targets whose gaps became visible to every regulator on the continent at the same time.