Liechtenstein's Cyber-Sicherheitsgesetz (CSG) of 5 December 2024 (LGBl. 2025 Nr. 111), in force since 1 February 2025, transposes NIS2 (Directive (EU) 2022/2555) and Regulation (EU) 2021/887 (the European Cybersecurity Competence Centre) and its Article 27 repealed the prior Cyber-Sicherheitsgesetz of 4 May 2023 (LGBl. 2023 Nr. 269).
Article 1 binds a public or private entity listed in Annex 1 or Annex 2 that qualifies as a medium or large company under Article 1064(2) or (3) of the Personen- und Gesellschaftsrecht (Persons and Companies Act) and provides its services or carries out its activities in Liechtenstein, and, regardless of size, a narrower set of entities the Act names expressly, including providers of public electronic communications networks or services, trust service providers, top-level-domain registries and DNS service providers, the sole provider of an essential service, an entity a disruption of which would materially affect public order, safety or health or cause a systemic risk, a critical-sector entity, a public administration body of the country, an entity designated critical under the CER Directive (Directive (EU) 2022/2557), and a domain-name registration service provider.
Annex 1's Digital Infrastructure sector separately names cloud-computing-service providers, data-centre-service providers, content-delivery-network operators, top-level-domain registries, trust service providers and DNS service providers (other than root-name-server operators) as entities this Act reaches regardless of size.
Only the digital-provider slice Annex 2 Item 6 names expressly, an online-marketplace provider, an online-search-engine provider and a social-networking-platform provider, is flagged on this jurisdiction's rows; the wider sector classes the Act also reaches (critical infrastructure across energy, transport, banking, health and digital infrastructure, and public administration) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.
Article 4 requires an essential or important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems it uses and to prevent or minimise the impact of a security incident, covering at least ten baseline categories mirroring NIS2 Article 21, and Article 5 requires the entity's leadership body to approve and oversee those measures and attend, and offer staff, regular training.
Article 6 requires an essential or important entity to notify the Stabsstelle Cyber-Sicherheit (Cyber Security Office) of a significant security incident without delay, on a graduated clock mirroring NIS2 Article 23: an early warning within 24 hours of becoming aware, a full notification within 72 hours with an initial assessment and any indicators of compromise, an intermediate report on request, and a final report within one month of the 72-hour notification.
Article 23 sets the same two-tier fine structure NIS2 Article 34 specifies, denominated in Swiss francs: up to CHF 10,000,000 or 2 percent of worldwide group turnover, whichever is higher, for an essential entity's violation of Article 4 or Article 6, and up to CHF 7,000,000 or 1.4 percent for an important entity, imposed administratively by the Stabsstelle Cyber-Sicherheit where the conduct is not separately a criminal offence within the courts' jurisdiction.
The Stabsstelle Cyber-Sicherheit, under the Government's Prime Minister's Office, is the CSG's competent authority and hosts Liechtenstein's CSIRT.
The CSG's own Article 28 states that, until the EEA Joint Committee incorporates a listed EU act into the EEA Agreement, that act applies directly as national legislation, and names NIS2 (Directive (EU) 2022/2555) as the first such act; Article 29(2) accordingly holds back only Article 2(1)(a), the CSG's own formal declaration that it transposes NIS2, until that EEA Joint Committee decision, while the Article 4 and Article 6 duties documented here have applied as national law since 1 February 2025 regardless.
Whether the EEA Joint Committee has since adopted that incorporation decision is not confirmed in the primary text; the EFTA eea-lex tracker page for the directive is behind a Cloudflare CAPTCHA challenge, a stop rather than a wall to read past. The Cyber Resilience Act's incorporation into the EEA Agreement and implementation in Liechtenstein is likewise not confirmed.
Article 23(3) separately fines a manufacturer, provider or conformity-assessment body up to CHF 100,000 for violating Regulation (EU) 2019/881's European cybersecurity-certification framework (Articles 53, 55, 56 and 60), a voluntary certification scheme rather than a mandatory product-placement security duty, so no product_security_requirements instrument is coded from it.
No general reasonable-security or information-security-programme statute with no sector gate was found in the Liechtenstein law reviewed here. Liechtenstein's breach-notification duty for exposed personal data sits in the Datenschutzgesetz (DSG) and is documented as this jurisdiction's privacy-topic instrument rather than repeated here.