SCRM Supplier Compliance & Risk Management

Home

CSG of 5 December 2024 · LGBl. 2025 No. 111

Small, but EEA: EU law applies in Liechtenstein – often sooner than expected.

Through the EEA Agreement Liechtenstein adopts the rulebook of the internal market. The Cyber Security Act implements NIS2, with the same supply chain requirements as in the EU.

The Cyber Security Act of 5 December 2024 transposes the NIS2 Directive into Liechtenstein law. It covers entities in Annexes 1 and 2 that qualify as medium-sized or large companies under the Persons and Companies Act and provide their services in Liechtenstein; special cases apply regardless of size.

For the financial centre, financial market regulation follows the EEA as well. The FMA publishes guidance on the effects of the Digital Operational Resilience Act for Liechtenstein. The same core duties therefore apply as in the EU internal market: risk management, reporting routes, governance of third-party providers.

Who is affected

  • Medium-sized and large companies under the PGR in the covered sectors.
  • Banks, insurers, fund companies and trustees in the financial centre – through EEA financial regulation.
  • Industrial and technology companies in the principality operating in covered areas.
  • Swiss suppliers of Liechtenstein entities – by contract rather than by statute.

The core duties

Risk management
State-of-the-art technical and organisational measures, documented.
Supply chain
Assess security aspects in relationships with direct suppliers and service providers.
Reporting
Report significant incidents within the statutory deadlines.
Management
Approval and oversight by management, training included.
Registration
Registration with the competent body where the entity falls in scope.

How SCRM covers it

Provider register

All third parties with access, classified by criticality – the basis of the supply chain duty.

Security profiles

Questionnaires and certificates per supplier, comparable across the portfolio.

Incidents and deadlines

Reporting chains and contacts where they are needed.

Management report

One page with status and open items for the board meeting.

Frequently asked

We are in Switzerland and supply a bank in Vaduz. What applies?

No Liechtenstein supervisory law applies to you. Your customer must assess and govern its providers, and those requirements reach you through the contract – usually as questionnaires, audit rights and notification duties.

Why does EU law apply in Liechtenstein?

Liechtenstein is a member of the European Economic Area. Internal-market legislation is incorporated by decisions of the EEA Joint Committee and then implemented nationally.

Is this relevant for small companies?

Scope builds on size criteria but includes exceptions for certain entities regardless of size. Suppliers get asked either way.

As of July 2026. The state of EEA incorporation changes; the official publications in the Liechtenstein Law Gazette govern. Not legal advice.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required