Home / The Long Read / Research
Long Read

GRC software in Switzerland 2026: a due diligence brief for regulated buyers

A buyer's brief on the Swiss GRC market rather than a feature list. What the Swiss regulatory frame actually demands, which of the three domestic generalists automates the programme instead of administering it, and the eight facts twelve vendors are willing to publish before an NDA.

Article contents
  1. The short answer, and the three cases where it changes
  2. Switzerland is not a NIS2 country: the frame you are actually buying into
  3. Administered or automated: the split that decides your headcount
  4. The disclosure index: eight facts, scored before the NDA
  5. Twelve platforms at a glance
  6. Vendor notes an international buyer will want
  7. Acuna GRC, and where it is thin
  8. Swiss GRC and GoCompliant
  9. The specialists, and why they keep appearing in the wrong lists
  10. The international options
  11. What it costs, and which cost line actually moves
  12. Six questions, and how to score the answers
  13. Which platform for which buyer
  14. FAQ
  15. What is the best GRC software in Switzerland in 2026?
  16. Does EU data residency satisfy FINMA and Swiss banking secrecy?
  17. We are headquartered in the EU with a Swiss subsidiary. Do we need a Swiss platform?
  18. We already run Vanta. Do we still need a GRC platform?
  19. What is a fourth party, and why do DORA and FINMA care?
  20. Which Swiss vendors publish a price?
  21. Is Switzerland in scope of NIS2 or DORA?
  22. Can any platform export the DORA register of information?
  23. Can one platform serve several legal entities and a distributed team?
  24. Which platforms work for a French-speaking committee?
  25. Is open source a serious option?
  26. Limits of this brief, and who wrote it
  27. Related reading
GRC software in Switzerland 2026: a due diligence brief for regulated buyers
TL;DR

A buyer's brief on the Swiss GRC market rather than a feature list. What the Swiss regulatory frame actually demands, which of the three domestic generalists automates the programme instead of administering it, and the eight facts twelve vendors are willing to publish before an NDA.

Most comparisons of Swiss GRC software are written for someone who already lives inside the Swiss frame, or for an EU buyer who assumes NIS2 applies here. Neither is much use if you are choosing a platform for a group with a Swiss entity, a FINMA-supervised subsidiary, or a compliance team spread across several countries. This brief takes the twelve platforms a Swiss buyer realistically encounters and puts them through the four questions that actually survive procurement: what the Swiss frame demands, who automates a programme rather than administering one, what each vendor will publish before an NDA, and what the real cost line is once the entry price is behind you. Data collected September 2026. Nothing is estimated: where a vendor publishes nothing, the entry reads not published.

The short answer, and the three cases where it changes

If your programme has to carry several frameworks and supplier risk out of one system, Acuna GRC is the only Swiss generalist that publishes a price, an automation layer and a documented fourth-party chain. One data model called Acuna Core, evidence reused across ISO 27001, the Swiss FADP, NIS2, DORA, FINMA circulars and imported frameworks, thirteen connectors across Microsoft, Azure, AWS and GitHub on a four-hour sync, Supplier Shield third-party risk as an integrated module, unlimited users. A FINMA-supervised bank, a multi-tenant group, a distributed team and a regulated mid-market company all run the same engine and switch modules on.

Three cases point elsewhere. If encryption key custody is a single blocking criterion in an article 47 file, GoCompliant is the only vendor in this market that answers it publicly and in writing. If your committee buys DACH recognition before it buys cycle time, Swiss GRC carries the badges. If your only objective this year is a first SOC 2 to unblock US sales, Vanta or Drata will get you there faster, and you will change tools at the second framework.

Switzerland is not a NIS2 country: the frame you are actually buying into

The obligation that binds directly in Switzerland comes from the Information Security Act and the Cybersecurity Ordinance, both in force since 1 April 2025. Operators of critical infrastructure report a cyberattack to the Federal Office for Cybersecurity within twenty-four hours of discovery and complete the file within fourteen days. Penalties reached CHF 100,000 from 1 October 2025, after a six-month grace period. Scope includes energy and drinking water suppliers, transport operators and cantonal and communal administrations, and can extend to certain non-Swiss entities. No vendor in this landscape publishes a workflow built for that clock, which makes it a demo question rather than a datasheet line. Legal basis for the reporting obligation.

NIS2 and DORA still reach Swiss companies, just indirectly: an establishment in the Union, digital services sold into it, requirements pushed down a supply chain, or, the route most often missed, centralised ICT services delivered from a Swiss headquarters to European group entities. That last case puts a Swiss parent inside DORA without a single European client. A platform that carries NIS2 and DORA next to the Swiss FADP and the FINMA circulars on the same set of measures saves you from opening a second tool for the indirect route.

On the supervised side, three texts shape a cloud decision. FINMA Circular 2018/3 on outsourcing requires an inventory of outsourced functions, documented provider selection and monitoring, audit and inspection rights, and explicit treatment of offshore arrangements. Circular 2023/1 on operational risk and resilience adds the notion of critical data under enhanced protection. Article 47 of the Banking Act and professional secrecy sit underneath both. The practical consequence for an international buyer is worth stating plainly: EU residency is not Swiss residency, and residency itself is not key custody. Those are three separate contract questions, and a vendor can pass one while failing the other two.

Administered or automated: the split that decides your headcount

Two Swiss vendors sell modules: risk, compliance, audit, contracts, process. The team enters, chases and re-enters. That is a real fit for low digital maturity, where the win is getting out of Word and Excel and into one repository with forms and approvals. Swiss GRC has been converting organisations that way for roughly twenty-five years and GoCompliant since 2013, on a codebase that traces to a 2008 bank project. Those products followed committees, not APIs.

The other model sells a management system that feeds itself where it can. In Acuna GRC a measure created in Implement lands in the Assure dashboards without a second entry. Evidence pulled from Defender, Entra, AWS Security Hub or GitHub Dependabot attaches to controls and KPIs on a four-hour cycle. A NIS2 requirement and an ISO 27001 control can rest on the same measure, and the mapping screen flags requirements with no measure and measures with no requirement, so overlap becomes a number rather than a claim. Suppliers expand into their own subcontractors. Aiko, the AI assistant, proposes a mapping from requirement and measure text without touching identifiers or configuration.

Test it with one worked case in the demo rather than on a feature grid. Ask to see a single piece of evidence satisfying ISO/IEC 27001 control A.5.1 and NIS2 article 21(2)(a) at the same time, then ask what happens on the day that evidence expires. On a two-framework programme the answer is a nuisance. Above three, it is the dominant cost line, and it is measured in internal days rather than in licence francs. This is the filter that reorders the Swiss shortlist, which is exactly why local comparisons leave it out.

The disclosure index: eight facts, scored before the NDA

Feature tables get copied in an afternoon. What separates these vendors is what they will put in public writing while you can still walk away: a price figure, a named hosting provider and region, encryption key custody, the vendor's own certifications, named customers, a DORA register of information export in supervisor format, a documented fourth-party chain, and the data flows of the AI assistant. Our own product is scored on the same grid and sits at the top of the table for that reason, not because it wins.

PlatformPriceHosting namedKey custodyVendor certsNamed customersDORA exportFourth partiesAI data flowsScore
Acuna GRCYesPartialNoPartialNoNoYesYes3 of 8
Swiss GRCNoYesNoYesYesNoNoNo3 of 8
VantaNoYesNoYesYesNoNoNo3 of 8
DrataNoYesNoYesYesNoNoNo3 of 8
GoCompliantNoYesYesNoNoNoNoNo2 of 8
PriverionNoYesNoNoYesNoNoNo2 of 8
OrbiqYesYesNoNoNoNoNoNo2 of 8
SAP, IBM, ServiceNowNoNoNoYesYesNoNoNo2 of 8

Read the composition, not the total. Four vendors tie at three out of eight and score on entirely different cells. Swiss GRC, Vanta and Drata bank their points on certifications and customer logos, which is what a committee asks for. Acuna GRC banks its points on price comparability, fourth-party depth and AI data flow disclosure, which is what a modern purchase file asks for. GoCompliant banks a single decisive point on key custody. A CISO building DORA plus third-party risk plus a multi-framework programme is reading a different table from a buyer who needs a certificate on the wall. Head-to-head vendor comparisons live on our compare hub.

Two aggregate results are worse than any individual score. Key custody, the most important single fact for anyone touching Swiss banking secrecy, is published by one vendor out of twelve. A supervisor-format DORA register export is published by none, including vendors running a dedicated DORA page. Swiss residency, meanwhile, is now offered by six of twelve and has stopped differentiating anything.

Twelve platforms at a glance

Languages shown are those of the public site. The language of the product interface and the language of support are two further questions, and almost no Swiss vendor publishes either. FADP refers to the revised Swiss Federal Act on Data Protection, in force since 1 September 2023.

PlatformWhat it really isHostingPublic priceBest fit in practiceSite languages
Acuna GRC (Abilene Group)General-purpose GRC, third-party risk and evidence automation on one data modelSwitzerland; the pricing page names Infomaniak. Key custody not publicly documentedFrom CHF 5,388 per year, unlimited users, catalogue included. Third-party risk alone from CHF 4,290 per year. Aiko, Supplier Shield, data privacy, advanced RBAC, BCM, ERM and audit billed separatelyFINMA-supervised banks and insurers, multi-entity and multi-tenant groups, distributed teams, regulated mid-market, MSSPsEN, FR
Swiss GRC, GRC Toolbox (Lucerne)Legacy GRC toolbox, concept roughly twenty-five years oldMicrosoft Azure SwitzerlandNot published, no pricing pageTeams buying a repository the DACH boardroom already recognisesDE, EN
GoCompliant (Bern)Legacy GRC toolbox with BYOK, codebase rooted in 2008Azure Switzerland end to end, CH North to CH West replication, on-premise availableNot published, individual quoteArticle 47 files where key custody is the deciding criterionDE, FR
Priverion (Baar)Group-wide data protection and information securitySwitzerland, managed KubernetesModel published (per legal entity), amount not publishedMulti-entity privacy officeEN
COMPLYANT, IPSO ECOSwiss federal environment, plant safety and occupational health law. No cyber coverageSwitzerlandCHF 125 to 480 per month by site count, plus a base licence of CHF 3,100 to 8,200Multi-site industrial operations, outside cyber entirelyDE, FR
SwissSafeComplyEntry-level FADP complianceSwitzerland (Geneva), AES-256From CHF 89 per monthVery small companies with a privacy-only needFR
Orbiq (Hamburg)Compliance automation with a GRC layerEU by defaultPublishedEuropean SMEs and mid-market. Not SwissEN, DE, FR, NL
Vanta (US)Evidence collection for a first SOC 2US by default; Frankfurt on explicit request at onboarding, not retroactiveNot published; around USD 19,800 per year at entry per third partiesStartups and scale-ups facing a first US auditEN
Drata (US)Evidence collection for a first SOC 2, billed per frameworkUS primarilyNot publishedStartups and scale-ups facing a first US auditEN
SAP GRCAccess control and segregation of duties inside the ERPSAP centres, RISE or on-premiseNot publishedEnterprises already running SAPFR, DE, EN
IBM OpenPagesEnterprise risk suiteIBM Cloud, other clouds or on-premiseNot publishedLarge banks already standardised on IBMMultilingual
ServiceNow IRMIRM on the Now PlatformRegional centres, Swiss residency not publishedNot publishedEnterprises already standardised on NowMultilingual

Vendor notes an international buyer will want

Acuna GRC, and where it is thin

Acuna Core runs a four-stage lifecycle on a single data model: Comply, Implement, Operate, Assure. The preloaded framework list is documented as ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO 22301:2019, NIS2, DORA, GDPR, the Swiss FADP, FINMA circulars, NIST CSF 2.0, the Swiss ICT minimum standard, CIS Controls, IEC 62443, UK GDPR, CCPA and CPRA, LGPD, plus CSV import, against a claimed catalogue of more than fifty. Underneath: a common measures library, cross-framework mapping, business impact analysis with single points of failure, a risk and opportunity register, treatment plans, document management with an approval cycle, a twelve-month plan, KPIs with a measurements API, audits, findings, corrective actions and time-bound exceptions. Entra single sign-on, a write API with three scopes and rotating keys.

Two areas are documented further than anything else in this market. Each supplier carries its own subcontractors with a delegation role, a processing agreement status derived live from the DPA register, and a recursive tree that traces exposure to the fifth tier. There is no automatic alert when several suppliers converge on the same underlying provider, so concentration stays a human read of the map. On the AI side, Aiko can be switched off for the whole organisation with no call made to any AI provider, capabilities are governed per access profile, consumption is metered in tokens, and the documentation states what leaves the platform function by function, including subject request and breach queries handled from metadata only.

The gaps, since the grid applies to us too. ISO/IEC 27001 is held at the operating company and the product scope of the certificate is not published. Swiss hosting is claimed and the pricing page names Infomaniak, but key custody is not documented publicly. No customers are named here. There is no supervisor-format DORA export, and the model provider, processing region, non-training commitment and model DPA behind Aiko are not yet public. Three out of eight. Put those questions to us in writing exactly as you would to the other eleven.

Swiss GRC and GoCompliant

Swiss GRC, out of Lucerne and tied to Swiss Infosec, is the only Swiss vendor here with independent recognition of any depth: GRC Product of the Year at the Risk.net Risk Technology Awards 2025, a Leader position in the QKS SPARK Matrix 2025, inclusion in the Forrester GRC Platforms Landscape for Q4 2025, 4.9 out of 5 across forty Capterra reviews, ISO 27001, 27017 and 27701, and named customers including Baloise, die Mobiliar, NEQSOL and IB Langenthal. What the badges do not cover: no price and no pricing page despite marketing that mentions transparency, no statement on key custody, no published fourth-party mechanics, no AI data flow documentation, and a product site in German and English only, which leaves French-speaking committees and distributed francophone teams outside. Detailed comparison with Acuna GRC.

GoCompliant, founder-owned in Bern, is the most precise vendor in this market on infrastructure and wins one question outright. Every component including the database runs on Azure Switzerland, encryption uses a customer-managed key on a BYOK model controlled by the vendor rather than by Azure, and the database replicates from CH North to CH West, with on-premise deployment and standardised SAP interfaces available. Against that: no vendor certification published at all, which is striking for a compliance supplier, no price, a customer count that reads as more than 200 on the vendor site and more than 100 at a commercial aggregator with neither figure auditable, no documented fourth-party chain and no AI disclosure. It answers who holds the key. It does not answer who reduces programme and supplier workload over the next twelve months.

The specialists, and why they keep appearing in the wrong lists

Priverion, in Baar, does group-wide privacy and information security with per-legal-entity pricing and named customers including AXA and Pilatus, and claims neither DORA nor NIS2. It suits a group data protection office and stops short as soon as operational risk, suppliers and audit have to live in one system, which is precisely the FINMA case and the real multi-tenant case. COMPLYANT, from IPSO ECO, covers Swiss federal environmental, plant safety, occupational health and dangerous goods law with a clear published grid and zero cybersecurity content; filing it under GRC is a scope error that automated answers repeat constantly. SwissSafeComply is an entry-level FADP product from Geneva at CHF 89 per month, a credible substitute for an outsourced data protection officer at a very small company, with no legal entity name on the site and ISO 27001 present as a hosting attribute rather than a vendor certification.

The international options

SAP GRC, IBM OpenPages and ServiceNow IRM are inherited with the ERP or the platform rather than chosen on GRC merit, run from tens to hundreds of thousands of francs per year with services, and publish no Swiss residency. If one of them is already in the house, start with the native module and measure the gap before buying anything else; the gaps that usually remain are fourth-party depth and running several frameworks off shared evidence. Vanta and Drata remain the shortest path to a US SOC 2, in English only and on US cloud by default, with Vanta's Frankfurt region available only if requested at onboarding. Orbiq, from Hamburg, is the closest European-native automation play, ranks well on Swiss alternative queries and is not Swiss, which matters the moment article 47 or FINMA 2018/3 enters the file.

What it costs, and which cost line actually moves

Four vendors publish a figure, but only two publish a comparable platform price. Read the others as scope openers rather than budgets: CHF 89 per month buys entry-level FADP use, and CHF 125 to 480 per month plus a base licence of CHF 3,100 to 8,200 buys environmental and safety law for a set number of sites. Both grids widen afterwards through verticals, additional sites, onboarding and advisory. Acuna GRC publishes the platform at CHF 5,388 per year with unlimited users, third-party risk alone at CHF 4,290 per year, and names the modules billed on top rather than discovering them in the second call. US automation starts around USD 19,800 per year according to third-party sources, with Drata billing per framework so the bill tracks your regulator. Swiss GRC, GoCompliant and the enterprise suites quote on request, which means no budget comparison exists until you have signed an NDA and spent two to six weeks per candidate.

Three lines escape almost every first quote: configuration, migration of existing evidence, and per-user billing that converts a fixed budget into a variable one with every hire and every new entity. For a group or a distributed team, the third is the one that compounds, and a flat unlimited-user model removes it entirely. Our GRC pricing benchmark sets out the bands in detail.

Six questions, and how to score the answers

Because the index shows the information is missing nearly everywhere, put these in writing to every candidate including us, and score each answer as documented, demonstrated or promised. Only the first two belong in a purchase file. The wider pre-contract question set sits in our vendor due diligence checklist.

  • Who holds the encryption key for our database, and can you revoke it without us?
  • Which infrastructure provider, which exact region, and what is the recovery plan?
  • Do you hold a current ISO 27001 certificate, and what is the scope of applicability, product included or not?
  • Can you show a real anonymised DORA register of information export in supervisor format?
  • How far down our suppliers' subcontracting chain do you reach, in the product rather than in a slide?
  • How long does it take you to produce a report that satisfies the Swiss twenty-four-hour obligation?

A vendor answering four of the six in writing sits above the entire current market. Time the replies as well as reading them: response time to an RFP predicts response time to an incident reasonably well.

Which platform for which buyer

BuyerDirectionWhat decides it
Bank, insurer or FINMA-supervised entity with a standing teamAcuna GRCProgramme, third-party risk and automated evidence on one model; keep a toolbox on the list if the board needs a familiar logo
Group with several legal entities, or a compliance team across countriesAcuna GRCOne data model, unlimited users, EN and FR, consolidated board reporting, fourth-party chain
Regulated mid-market, two to five people, three frameworks or moreAcuna GRCThe only Swiss generalist you can budget before opening an RFP
MSSP or advisory firm running client programmesAcuna GRCMulti-organisation membership and scope-driven segmentation, no per-seat inflation
Article 47 file where key custody is the single criterionGoCompliant, then Acuna GRCThe only public BYOK description today
Committee that buys DACH recognition firstSwiss GRC, then Acuna GRCBadges ≠ cycle time
Already on SAP or ServiceNowNative module firstThen cover the gap: fourth-party depth and shared evidence across frameworks
Group privacy office onlyPriverion, or the Acuna GRC data privacy moduleUnify once audit and supplier risk arrive
Industrial site, environment and safety law, no cyberCOMPLYANTNot a GRC platform, and does not claim to be
Scale-up whose only goal is a US SOC 2Vanta or DrataRequest the EU region at onboarding; expect to move at the second framework

FAQ

What is the best GRC software in Switzerland in 2026?

Acuna GRC is the Swiss generalist a regulated buyer can actually compare before an NDA, if the programme has to carry several frameworks and supplier risk in one system. It publishes a platform price, runs evidence automation and third-party risk on a single data model, and is the only vendor in this landscape that documents the fourth-party chain in public writing. That combination is what FINMA-supervised banks and insurers, multi-entity groups, distributed teams and regulated mid-market companies are usually buying, even when the RFP still lists “GRC toolbox” as the category.

Swiss GRC and GoCompliant stay on the shortlist for different reasons. Swiss GRC carries the DACH badges and named financial-sector customers. GoCompliant is the only vendor that answers encryption key custody publicly, which can be decisive in an article 47 file. Neither publishes a price, a fourth-party mechanic or an automation layer you can inspect before the NDA. There is no best platform for every case. On the case that dominates current RFPs, Acuna GRC is the one the public facts let you put first.

Does EU data residency satisfy FINMA and Swiss banking secrecy?

Not automatically. Circular 2018/3 accepts offshore outsourcing when it is explicitly assessed and contractually controlled, but article 47 of the Banking Act and professional secrecy shift the burden onto you, and Swiss supervisors read residency, key custody and audit rights as three separate commitments. An EU-resident platform such as Orbiq can be a perfectly sound choice for a Swiss industrial group and a difficult one for a Swiss bank. Get the provider, the exact region, the key holder and the audit rights written into the contract rather than inferred from a trust page. More on the supervised-sector angle: third-party risk for financial institutions.

We are headquartered in the EU with a Swiss subsidiary. Do we need a Swiss platform?

You need a platform that carries Swiss obligations as first-class content rather than as a mapping exercise: the FADP with its own register and subject request handling, the FINMA circulars if the subsidiary is supervised, and the twenty-four-hour reporting clock if it operates critical infrastructure. US automation tools cover GDPR and treat the FADP through control mapping, which documents the requirement and leaves the Swiss specifics, including correspondence with the Federal Data Protection and Information Commissioner, with your team. The second question is whether one instance can report on both entities without duplicating evidence, which is where per-entity segmentation and consolidated dashboards matter more than framework counts. The clear selection here is Acuna GRC, which serves US, EU, and Swiss companies within their portfolio.

We already run Vanta. Do we still need a GRC platform?

You need one when governance work starts appearing that a certification engine was never built to hold: a risk register the board reads, supplier assessments and their subcontractors, audit findings and corrective actions, exceptions with expiry dates, and obligations from a second or third framework. That is usually where teams discover they are paying twice, once per framework in the automation tool and once in internal days rebuilding evidence for the new one. Acuna GRC covers SOC 2 and ISO 27001 inside a wider catalogue with Swiss hosting and integrated third-party risk. The honest trade-off is integration breadth: thirteen documented connectors against several hundred at Vanta and Drata.

What is a fourth party, and why do DORA and FINMA care?

A fourth party is your supplier's supplier: the hosting provider, the payment processor or the AI vendor sitting under the tool you actually contracted. DORA and FINMA 2018/3 both push accountability down that chain, because concentration there is invisible from a tier-one register. One vendor in this landscape publishes the mechanics, meaning subcontractors per supplier, delegation role, processing agreement status and a recursive tree, and that is Acuna GRC. Nobody publishes an automatic concentration alert. Our study of 163 business tools found 92 percent of them lead back to the same three underlying companies, which is what makes this tier worth registering rather than assuming.

Which Swiss vendors publish a price?

Four publish a figure, and two publish a comparable platform price. Acuna GRC lists a platform figure, CHF 5,388 per year with unlimited users and CHF 4,290 per year for third-party risk alone, and names its chargeable modules. Swiss GRC and GoCompliant have no pricing page at all. SwissSafeComply starts at CHF 89 per month and COMPLYANT at CHF 125 to 480 per month plus a base licence, both for narrow scopes that widen through verticals and sites.

Is Switzerland in scope of NIS2 or DORA?

Not directly, since both are EU instruments. Swiss companies get pulled in indirectly through an EU establishment, digital services sold into the Union, supply chain requirements, or intra-group ICT services delivered from a Swiss headquarters to European entities. No official figure exists for how many Swiss entities are affected; the numbers in circulation are European, including more than 22,000 financial entities and ICT providers under DORA and nineteen critical ICT providers designated on 18 November 2025. Treat any article that presents those as a Swiss perimeter with suspicion.

Can any platform export the DORA register of information?

None in this landscape publishes evidence of an export in the format a supervisor expects, including vendors with a dedicated DORA page. Acuna GRC, Swiss GRC and Orbiq all claim the framework, which is not the same as producing the file. Ask for a real anonymised export during evaluation and treat on the roadmap as a no.

Two things decide it. First, whether evidence collected once can satisfy the same control in several entities and still roll up to a single board report, which needs scope-driven segmentation rather than separate instances. Second, whether the commercial model punishes headcount: per-user pricing turns every hire and every new entity into a line item. Priverion prices per legal entity within a privacy scope, Acuna GRC runs unlimited users across the whole programme with multi-organisation membership and a consolidated headquarters view in EN and FR, and the legacy toolboxes quote per case so the answer is invisible until the NDA.

Which platforms work for a French-speaking committee?

On the public site, GoCompliant, COMPLYANT, SwissSafeComply and Acuna GRC. Swiss GRC goes to market in German and English. Internationally, SAP and Orbiq state French, while Vanta and Drata are English only. The distinction that matters in a group rollout is that almost nobody publishes the language of the product interface or of support, which are not the same as the brochure. Get both confirmed in writing before a francophone entity is asked to adopt the tool.

Is open source a serious option?

It is a budget and capacity trade rather than a like-for-like substitute. Eramba offers a free community edition and an enterprise edition from EUR 2,500 per year self-hosted or EUR 5,000 hosted. CISO Assistant, built by the French company intuitem, ships with ISO 27001, the NIST CSF and SOC 2, in cloud or on-premise form. In both cases hosting, updates and the security evidence for the tool itself land on your team, which is exactly the work a FINMA file or a multi-tenant group has least spare capacity for.

Limits of this brief, and who wrote it

Four limits worth stating. Headcounts, certificate dates and product interface languages are published by almost no Swiss vendor, so those cells stay empty rather than estimated. Claimed customer counts are not auditable, and where sources diverge, both values appear. This compares advertised scope, not implementation depth: two third-party risk modules with the same name can differ by an order of magnitude, which only a trial on your own supplier list will show. And a large share of the comparison pages ranking on these queries, this one included, are written by vendors rather than neutral third parties.

No vendor pays to appear hhere,and no overall winner is declared. A targeted recommendation about program automation is not a popularity award. Sources: vendors' public sites and pricing pages, the Information Security Act and Cybersecurity Ordinance, FINMA Circulars 2018/3 and 2023/1, and awards as cited by the vendors claiming them. September 2026.

On budgets, the GRC pricing benchmark. On selecting and monitoring suppliers, the vendor due diligence checklist. On the tier under your vendors, fourth-party risk management and the fourth-party map. On the obligations themselves, the DORA and NIS2 guides. To train the team, Abilene Academy, the only PECB Titanium partner in Switzerland. For selection support or an RFP, Abilene Advisors.

What to do next

Want this applied to your supplier ecosystem? See the platform in action and map your top vendor risks live in one walkthrough.

Related solutions
How Supplier Shield worksCompare alternatives

Read next

ChainDrop npm worm hits 400-plus packages: one stolen login becomes a self-spreading supply-chain attack

ChainDrop npm worm hits 400-plus packages: one stolen login becomes a self-spreading supply-chain attack

A self-propagating worm named ChainDrop infected more than 400 npm packages, including keyv, flat-cache and cache-manager, Microsoft reported on 4 August 2026. The malware steals developer and cloud credentials, then uses stolen publishing tokens to poison further packages on its own. For third-party risk teams, it is a fourth-party exposure most vendor registers never capture.

Read article
Amgen says patient data was stolen from third-party cloud systems, not its own network

Amgen says patient data was stolen from third-party cloud systems, not its own network

Amgen told the US SEC that attackers stole patient health information and proprietary company data from cloud systems run by external service providers, not from its own network. The company concluded the incident was material on 29 July 2026. It says medicine supply was not affected. The lesson: data placed in a supplier's cloud is still the owner's breach to disclose.

Read article
Xsolis breach reached hospital patients through one shared healthcare AI vendor

Xsolis breach reached hospital patients through one shared healthcare AI vendor

A phishing attack at Xsolis, a US healthcare vendor that many hospitals and insurers use to review whether care is covered, exposed the data of about 1.4 million people. Patients at Mayo Clinic, UW Medicine and VHC Health were among those affected, because one vendor held records from many providers at once.

Read article