NIS2 in Switzerland

Switzerland

As a non-EU member state, Switzerland has no obligation to transpose NIS2, and instead developed its own Information Security Act (ISG), adopted in 2020. Since its initial focus on federal bodies proved insufficient, the ISG was revised, gradually bringing it closer to NIS2. Notably, Swiss companies were already subject to NIS2 in practice based on EU subsidiaries and clients.

  1. EU NIS in Switzerland
  2. Scope
  3. Cyber Resilience
  4. EU Context and NIS2
  5. in German

The ISG 2025 revision introduced a mandatory 24-hour reporting obligation for an extensive list of entities. Separately, a legislative proposal on cyber resilience for digital products, mirroring the EU Cyber Resilience Act, is expected by autumn 2026. Prospectively, the extent to which the evolving threat landscape, market forces, and a preference for limited bureaucracy — Switzerland sources roughly 70% of its imports from the EU and sends about half its exports there — will nudge Swiss policymakers further toward convergence with fast-moving EU cyber resilience regulation remains to be seen.

NIS in Switzerland

Current legislation

Switzerland is not an EU member state and has no obligation to transpose EU directives into national law. The Swiss Information Security Act ISG was adopted in December 2020, four years after the passing of the EU NIS Directive, and has been in force since January 2024. However, as its scope, which predominantly focused on federal bodies rather than private-sector critical infrastructure, was assessed as too narrow in light of the evolving threat landscape, it was revised in 2023.

Information Security Act (ISG)

The 2025 ISG revision introduced a mandatory 24-hour cyberattack reporting obligation Art. 74a-74f for entities listed under an exhaustive sector list Art. 74b, which entered into force on 1 April 2025. The new Cybersecurity Ordinance CSV specifies in detail which categories of incidents are subject to this reporting obligation, what information must be submitted, and through which channel. For example via BACS’s Cyber Security Hub.

Since 1 October 2025, these obligations are underpinned by a comparatively light sanction regime. Art. 74g-74h All in all, the revision brings the ISG closer to the NIS Directives. Since May 2026, a further revision of the ISG has been in preparation; however, this does not concern operators of critical infrastructure, but chiefly the federal classification system.

Cyber Resilience

Separate from that, a legislative proposal on cyber resilience for digital products, mirroring the EU Cyber Resilience Act, is currently under way and expected by autumn 2026 (see below).

up

Authorities

In Switzerland, the following authorities play a role in implementing and enforcing cyber resilience:

BACS

The Federal Office for Cyber Security (BACS) is the central operative body: it receives cyberattack reports from critical infrastructure operators, provides support tools (secure communications, threat intelligence, detection instruments), and pursues sanctions for reporting-duty violations. Art. 74g-74h

It also handles individual clarification requests (Auskunftsgesuche) from organisations uncertain whether they fall within an existing exemption or threshold category.

Federal Council

The Federal Council (Bundesrat) is relevant at the rule-setting level. Beyond initiating the foundational legislation and its revisions, it adopts implementing ordinances such as the CSV, which fixes the sector-specific thresholds and exemptions narrowing the Art. 74b ISG list. Art. 74c

Federal Intelligence Service

The Federal Intelligence Service (NDB) contributes strategic threat assessments that inform BACS’s operative work. Its annual report dedicates a standalone chapter to (cyber) threats against critical infrastructure.

up

Scope of the Swiss Regulation

Entities

The Swiss ISG stipulates broader obligations for state entities, and, since 2025, narrower reporting obligations for a separate set of entities, among them now also private-sector organisations. These tracks are not mutually exclusive, meaning that state authorities carry both obligations. (simplified)

Entities subject to core obligations

The ISG’s core obligations Art. 6-26 are targeted at the state entities defined as follows:

  • The federal administration itself (Federal Assembly, Federal Council, federal courts, army, administrative units). Art. 2
  • Cantons, if they access federal classified information or federal IT resources. Art. 3
  • Third-party contractors performing security-sensitive federal work. Art. 49-50

Entities subject to the reporting obligation

The ISG sets out an exhaustive list Art. 74b of reporting-obligated authorities and organisations, grounded in their affiliation to specific categories.

In defining entities, the ISG follows a reverse approach to EU NIS2. NIS2 sets off at the entire economy — any entity surpassing the size threshold (50+ employees or EUR 10m turnover) is classified as “essential” or “important” entity, with corresponding obligation and sanction regimes. In other words, under NIS2 no entity, even if operating in a sector NIS2 covers, is generally regulated (there are exceptions) unless it meets the defined threshold marking it as large and critical enough.

Switzerland, by contrast, covers entities tied to several specific categories rather than the economy at large. The difference lies in how exemptions apply: depending on size and materiality thresholds, entities can be exempted under the Cybersecurity Ordinance (CSV). Put differently, all entities affiliated with the listed categories are regulated, except where their size permits exemption.

The following table matches each entity on the exhaustive Art. 74b ISG list with its exemption status under Art. 12 CSV where one exists.

ISG Entity type
Art. 74b (1)
Exemption
Art. 12
a Universities Exempt if fewer than 2,000 students. Art. 12 (1) a.
b Federal, cantonal and municipal authorities as well as inter-cantonal, cantonal and inter-communal organisations No exemption. (Except the Defence Group during assistance/active service under Art. 67/76 Militärgesetz.)
c Organisations with public-law tasks in safety and rescue, drinking water supply, waste water treatment, waste disposal Not addressed in CSV.
d Energy supply, trading, metering, and control: electricity, gas pipelines, oil pipelines, district heating, refineries, wood/coal energy Exempt below sector-specific thresholds: electricity below Schutzniveau C (StromVV); gas pipelines below 400 GWh/year throughput end consumers; other energy companies below thresholds in Art. 12 para. 2. Nuclear-plant licence holders are exempt at ISG level itself. Service providers, network operators, producers, storage operators share the exemption; hardware, software manufacturers are explicitly excluded. Art. 12 (1) b
e Financial entities subject to Banking Act, Insurance Supervision Act or Financial Market Infrastructure Act No exemption
f Health facilities on the cantonal hospital list (KVG Art. 39) No exemption
g Medical laboratories licensed under Art. 16 para. 1 Epidemiengesetz Exempt under the general cross-sector SME threshold Art. 12: fewer than 50 employees and CHF 10m annual turnover/balance sheet.
h Therapeutic Products Act for the manufacture, marketing, and import of medicinal products Exempt under the general SME threshold Art. 12
i Organisations providing benefits against illness, accident, incapacity, old age, disability, and helplessness No exemption
j Swiss Broadcasting Corporation (SRG) No exemption
k News agencies of national significance No exemption
l Postal service providers registered with the Postal Commission (Postgesetz Art. 4) Exempt under the general SME threshold Art. 12 (2)
m Railways under Art. 5 or 8c Eisenbahngesetz; cableway, trolleybus, bus, and shipping companies holding a concession under Art. 6 Personen­beförderungs­gesetz Exempt unless BAV-supervised with public-interest system tasks essential to welfare/economy. Art. 12 (1) c
n Civil aviation licensed by the Federal Office of Civil Aviation (BAZL); national airports per Sachplan Infrastruktur der Luftfahrt Exempt if not subject to EU aviation information security requirements (Regulations 2023/203, 2022/1645) or EU aviation security program requirements (Regulations 2015/1998, 300/2008). Art. 12 (1) d
o Transporting goods on the Rhine under the Seeschiff­fahrtsgesetz (maritime shipping law), and operating registration, loading, or unloading at Basel harbour Not addressed.
p Essential daily goods, where disruption would cause significant supply shortages Exempt under the general SME threshold Art. 12 (2)
q Telecommunications service providers registered with BAKOM (FMG Art. 4) Not addressed.
r Registry operators and registrars of internet domains under Art. 28b FMG Not addressed.
s Providers of services and infrastructure serving the exercise of political rights No exemption.
t Providers of cloud computing, search engines, and data centres domiciled in Switzerland; digital trust and digital security service providers Cloud, search-engine, data-centre providers exempt only if they do not provide services to third parties for payment (self-use only is exempt). Digital trust and digital security services offered to third parties are not exempted. Art. 12 (1) e
u Manufacturers of hardware, software used by critical infrastructure with remote maintenance access, OT, process control, public-safety No exemption Art. 12 (1) b

up

Sectors

Both ISG and CSV contain no sector taxonomy in the statute itself. Art. 74b (1) is simply an enumerated list of entity types (letters a to u, as depicted in the table above). Nonetheless, a sector construct exists operationally, since Art. 8 (2) CSV requires BACS to assign each registered operator to one or more sectors for information exchange, though this taxonomy is unpublished.

It may draw on the following nine sectors and 27 sub-sectors of the Federal Office for Civil Protection’s (BABS) national critical infrastructure strategy (SKI), though this link is unconfirmed.

  • Authorities: Research and education; Cultural assets; Parliament, government, judiciary, administration
  • Energy: Electricity supply; Oil supply; Gas supply; District and process heat
  • Waste management: Waste; Wastewater
  • Finance: Financial services; Insurance services
  • Health: Chemicals and medicinal products; Laboratory services; Medical care
  • Information and communication: IT services; Telecommunications; Media; Postal services
  • Food: Food supply; Water supply
  • Public safety: Armed forces; Emergency services (“blue light organisations” — police, fire, ambulance); Civil protection
  • Transport: Air transport; Rail transport; Shipping; Road transport

up

Security and obligations

Core obligations for state entities

  • Assess and protect information’s confidentiality, availability, integrity, and traceability, with risk management and objectives set at top-management level Art. 6-8
  • Write security requirements into third-party contracts; detect and handle breaches, with contingency planning for critical ones Art. 9-10
  • Classify information and apply corresponding IT security, personnel, and physical protection measures, including personnel security checks for security-sensitive roles Art. 11-48
  • Cantons: only classification/IT-security duties, and only for federal data or IT resources Art. 3
  • Security-cleared contractors: security concept, personnel screening, incident reporting, inspections Art. 49-73

Reporting obligation for entities on the exhaustive list

  • Report cyberattacks to BACS within 24 hours of discovery (functionality threat, data manipulation or exfiltration, long-undetected attack, or extortion, threat, coercion) Art. 74a, 74d-74e
  • Include required content (nature, effects, attacker information) and contact details if not already registered Art. 74e Art. 15
  • Supplement missing information within 14 days Art. 74e Art. 16
  • Submit via BACS’s secure system or another channel Art. 74f Art. 17
  • Provide documents on request to clarify reporting-duty status Art. 74a Art. 13

up

Sanctions

Entities subject to core obligations

The ISG itself contains no fine or penalty provision for violations of Art. 6–26.

Entities subject to the reporting obligation

  • Non-compliance triggers a two-step warning process: BACS sets a deadline, then issues a binding order with a penalty warning if that deadline is missed Art. 74g
  • Wilful disregard of that order carries a fine of up to CHF 100,000, reduced to CHF 20,000 for minor cases, addressed to the responsible individual rather than the organisation Art. 74h

up

Cyber Resilience of Digital Products

Switzerland currently has almost no specific legal requirements governing the cybersecurity of digital products. In practice, many Swiss manufacturers already comply with EU standards under the EU Cyber Resilience Act (CRA), in force since December 2024.

Acting on Motion 24.3810 from the Council of States’ Security Policy Committee, the Federal Council tasked BACS, together with the Federal Office of Communications (BAKOM) and the State Secretariat for Economic Affairs (SECO), with preparing a consultation draft for a “Cyberresilienz von digitalen Produkten” law by autumn 2026.

This new legislation will set out cybersecurity requirements for the development and commercialisation of products with digital components, establish rules for market surveillance of these products, and lay the groundwork for banning the import and sale of insecure devices.

In mirroring EU CRA, the aim is to create legislation tailored to Switzerland’s economic landscape, while keeping the administrative burden on companies to a minimum and ensuring that Swiss companies operating internationally are not burdened by conflicting requirements. Notably, this legislative file on the cyber resilience of digital products is treated as a separate track from the ISG revision.

up

EU

Context and NIS2

National transposition laws capture EU subsidiaries of Swiss companies, NIS2’s territoriality clause Art. 26 reaches Swiss providers of cloud, DNS, or managed services serving EU customers, regardless of where they are domiciled. Third, EU customers pass NIS2’s supply-chain security requirements down to their Swiss suppliers.

Notwithstanding legislative efforts to converge with NIS2, the EU regulatory regime remains considerably broader than the ISG in both scope and severity. NIS2 applies to a wider cross-section of the economy, classifying “essential” and “important” entities across 18 sectors rather than the ISG’s 9. NIS2 also imposes substantially higher sanctions with fines of up to €10 million or 2% of global annual turnover, coupled with personal liability for management.

The EU framework further extends across several adjacent legislative instruments. Beyond the EU-CRA, which Switzerland’s forthcoming digital-products law is designed to mirror, the stack includes the EU Digital Operational Resilience Act (EU-DORA), governing ICT risk management in the financial sector, and the Critical Entities Resilience (EU-CER) Directive on physical resilience, for which no domestic Swiss equivalent currently exists.

up

Further Information

Sources

  1. Federal Act on Information Security (Information Security Act, ISG), Fedlex, 2022
  2. Ordinance on Cybersecurity (Cybersecurity Ordinance, CSV), Fedlex, 2025
  3. Strengthening Information Security at the Federal Level: Federal Council Initiates Legislative Revision, DDPS, 2026