Every date that matters across NIS2, DORA, CER, Part-IS and the Swiss ISG, verified against the legal texts, with the next deadline twelve days out.
Between January 2024 and July 2026, European resilience regulation moved from ambition to enforcement: the Swiss ISG, NIS2, the CER Directive, DORA and aviation's Part-IS all took effect or hit their key deadlines inside this window. This calendar lists each date, what it changed, and what remains ahead.
The Information Security Act (SR 128) takes effect with its four ordinances.
EU member states' deadline to transpose NIS2 into national law; obligations flow as national laws land.
Directive (EU) 2022/2557 on the resilience of critical entities applies across the EU.
The Digital Operational Resilience Act applies to financial entities and their critical ICT providers.
Swiss critical infrastructure operators must report significant cyber attacks to BACS within 24 hours, 14 days to complete.
Fines up to CHF 100,000 for non reporting after a BACS order (Art. 74g and 74h ISG).
Delegated Regulation (EU) 2022/1645 applies: information security management for the first group of aviation organisations.
Member states' deadline to adopt national strategies on the resilience of critical entities.
Implementing Regulation (EU) 2023/203 applies, extending Part-IS duties across aviation authorities and organisations.
Member states must identify their critical entities; designated operators inherit the full duty set. Twelve days from publication of this calendar.
Regime by regime detail: KRITIS and the CER Directive, the Swiss ISG in English (also auf Deutsch), and Part-IS for aviation.
It depends on sector, footprint and customers: Swiss critical infrastructure operators sit under the ISG; EU essential and important entities under NIS2 and, where designated, CER; financial entities and their ICT providers under DORA; aviation under Part-IS. Most internationally active organisations sit under more than one, and the efficient response is a single management system serving all of them. We map your exposure precisely in a first conversation.
No, but the posture has changed: regulators now assume the duty is known, so gaps read as non compliance rather than transition. The sequence that works is a rapid gap assessment against the regimes that bind you, remediation of reporting readiness first because it carries the shortest clocks, then the management system evidence behind it.
Evidenced response: tested plans, a drilled reporting pathway, exercised leadership and closed corrective actions. Every regime here converges on demonstration over documentation, which is why exercising has become the common denominator of compliance.
A rapid, confidential mapping of your regimes, gaps and sequence, from a practitioner team that implements all of them. We respond within 24 hours.
Book a consultation