Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important Entities
Cyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 1, 3, 4, 5
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 February 2025.
A sector security regimes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds an essential or important entity under Article 1 and Annexes 1 and 2, which name an online-marketplace provider, an online-search-engine provider and a social-networking-platform provider (Annex 2 Item 6) among the digital-service providers it reaches expressly, generally at the medium-or-large-company threshold of Article 1064(2) or (3) of the Personen- und Gesellschaftsrecht (Persons and Companies Act); the wider sector classes Annexes 1 and 2 also reach (critical-infrastructure operators across energy, transport, banking, health and public administration, and the digital infrastructure sector's own DNS, top-level-domain, cloud-computing, data-centre and content-delivery-network providers, which Article 3 binds regardless of size) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
- Take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems you use for your operations or to provide your services, and to prevent or minimise the impact of a security incident on the recipients of your services and on other services.
- Cover at least: risk analysis and information-system-security policy; incident handling; business continuity, including backup management and disaster recovery, and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluating your measures' effectiveness; basic cyber-hygiene procedures and training; cryptography and, where appropriate, encryption; personnel security, access-control concepts and asset management; and multi-factor or continuous authentication, plus secured voice, video and text communication.
- Have your leadership body (Leitungsorgan) approve and oversee these measures and attend, and offer your staff, regular training on recognising and assessing cybersecurity risk and risk-management practice.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 23(1)'s penalty for an Article 4 or Article 6 infringement is an administrative fine (Busse) for an Übertretung (contravention), imposed by the Stabsstelle Cyber-Sicherheit only where the conduct does not itself constitute a criminal offence within the courts' jurisdiction; no provision reviewed here makes an Article 4 or Article 6 infringement itself a criminal offence.
Penalty structure
Article 23(2)(a) sets the fine for an essential entity's infringement, including a Article 4 or Article 6 infringement, at up to CHF 10,000,000 or up to 2 percent of the total worldwide turnover made in the preceding financial year by the undertaking to which the essential entity belongs, whichever amount is higher, mirroring NIS2 Article 34(4). Article 23(2)(b) sets an important entity's fine at up to CHF 7,000,000 or up to 1.4 percent of that turnover, whichever amount is higher, mirroring NIS2 Article 34(5).
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- CHF
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Stabsstelle Cyber-Sicherheit (Cyber Security Office), Liechtenstein's competent authority under the Cyber-Sicherheitsgesetz, which reviews compliance with Article 4's risk-management measures and Article 6's reporting duties and hosts Liechtenstein's CSIRT.
Settledness
- As of
- 15 September 2026
- Guidance link
- https://scs.llv.li
- Guidance body
- Stabsstelle Cyber-Sicherheit
- Open questions
- Has the EEA Joint Committee adopted the decision incorporating Directive (EU) 2022/2555 into the EEA Agreement, which Article 29(2) of the Cyber-Sicherheitsgesetz makes the trigger for Article 2(1)(a)'s own entry into force?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 binds a public or private entity listed in Annex 1 or Annex 2 that qualifies as a medium or large company under Article 1064(2) or (3) of the Personen- und Gesellschaftsrecht (Persons and Companies Act) and provides its services or carries out its activities in Liechtenstein.
Article 4 requires such an essential or important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems it uses for its operations or to provide its services, and to prevent or minimise the impact of a security incident on the recipients of its services and on other services.
These measures must cover at least ten baseline categories mirroring NIS2 Article 21: risk analysis and information-system-security policy, incident handling, business continuity (including backup management and disaster recovery) and crisis management, supply-chain security, security in the acquisition, development and maintenance of systems including vulnerability management and disclosure, evaluating the measures' effectiveness, basic cyber-hygiene procedures and training, cryptography and encryption, personnel security and access control, and multi-factor or continuous authentication.
Article 5 requires the entity's leadership body (Leitungsorgan) to approve and oversee those measures and to attend, and offer its staff, regular training on recognising and assessing cybersecurity risk. Annex 2 Item 6 names an online-marketplace provider, an online-search-engine provider and a social-networking-platform provider among the digital-service providers this duty reaches expressly.
When LexLint raises it
operates_social_platform
Read the law
Cyber-Sicherheitsgesetz (CSG), consolidated text, gesetze.li, Articles 1, 4 and 5