NIS in Switzerland
Current legislation
Switzerland is not an EU member state and has no obligation to transpose EU directives into national law. The Swiss Information Security Act ISG was adopted in December 2020, four years after the passing of the EU NIS Directive, and has been in force since January 2024. However, as its scope, which predominantly focused on federal bodies rather than private-sector critical infrastructure, was assessed as too narrow in light of the evolving threat landscape, it was revised in 2023.
Information Security Act (ISG)
The 2025 ISG revision introduced a mandatory 24-hour cyberattack reporting obligation Art. 74a-74f for entities listed under an exhaustive sector list Art. 74b, which entered into force on 1 April 2025. The new Cybersecurity Ordinance CSV specifies in detail which categories of incidents are subject to this reporting obligation, what information must be submitted, and through which channel. For example via BACS’s Cyber Security Hub.
Since 1 October 2025, these obligations are underpinned by a comparatively light sanction regime. Art. 74g-74h All in all, the revision brings the ISG closer to the NIS Directives. Since May 2026, a further revision of the ISG has been in preparation; however, this does not concern operators of critical infrastructure, but chiefly the federal classification system.
Cyber Resilience
Separate from that, a legislative proposal on cyber resilience for digital products, mirroring the EU Cyber Resilience Act, is currently under way and expected by autumn 2026 (see below).
Authorities
In Switzerland, the following authorities play a role in implementing and enforcing cyber resilience:
BACS
The Federal Office for Cyber Security (BACS) is the central operative body: it receives cyberattack reports from critical infrastructure operators, provides support tools (secure communications, threat intelligence, detection instruments), and pursues sanctions for reporting-duty violations. Art. 74g-74h
It also handles individual clarification requests (Auskunftsgesuche) from organisations uncertain whether they fall within an existing exemption or threshold category.
Federal Council
The Federal Council (Bundesrat) is relevant at the rule-setting level. Beyond initiating the foundational legislation and its revisions, it adopts implementing ordinances such as the CSV, which fixes the sector-specific thresholds and exemptions narrowing the Art. 74b ISG list. Art. 74c
Federal Intelligence Service
The Federal Intelligence Service (NDB) contributes strategic threat assessments that inform BACS’s operative work. Its annual report dedicates a standalone chapter to (cyber) threats against critical infrastructure.
Scope of the Swiss Regulation
Entities
The Swiss ISG stipulates broader obligations for state entities, and, since 2025, narrower reporting obligations for a separate set of entities, among them now also private-sector organisations. These tracks are not mutually exclusive, meaning that state authorities carry both obligations. (simplified)
Entities subject to core obligations
The ISG’s core obligations Art. 6-26 are targeted at the state entities defined as follows:
- The federal administration itself (Federal Assembly, Federal Council, federal courts, army, administrative units). Art. 2
- Cantons, if they access federal classified information or federal IT resources. Art. 3
- Third-party contractors performing security-sensitive federal work. Art. 49-50
Entities subject to the reporting obligation
The ISG sets out an exhaustive list Art. 74b of reporting-obligated authorities and organisations, grounded in their affiliation to specific categories.
In defining entities, the ISG follows a reverse approach to EU NIS2. NIS2 sets off at the entire economy — any entity surpassing the size threshold (50+ employees or EUR 10m turnover) is classified as “essential” or “important” entity, with corresponding obligation and sanction regimes. In other words, under NIS2 no entity, even if operating in a sector NIS2 covers, is generally regulated (there are exceptions) unless it meets the defined threshold marking it as large and critical enough.
Switzerland, by contrast, covers entities tied to several specific categories rather than the economy at large. The difference lies in how exemptions apply: depending on size and materiality thresholds, entities can be exempted under the Cybersecurity Ordinance (CSV). Put differently, all entities affiliated with the listed categories are regulated, except where their size permits exemption.
The following table matches each entity on the exhaustive Art. 74b ISG list with its exemption status under Art. 12 CSV where one exists.
| ISG | Entity type Art. 74b (1) |
Exemption Art. 12 |
|---|---|---|
| a | Universities | Exempt if fewer than 2,000 students. Art. 12 (1) a. |
| b | Federal, cantonal and municipal authorities as well as inter-cantonal, cantonal and inter-communal organisations | No exemption. (Except the Defence Group during assistance/active service under Art. 67/76 Militärgesetz.) |
| c | Organisations with public-law tasks in safety and rescue, drinking water supply, waste water treatment, waste disposal | Not addressed in CSV. |
| d | Energy supply, trading, metering, and control: electricity, gas pipelines, oil pipelines, district heating, refineries, wood/coal energy | Exempt below sector-specific thresholds: electricity below Schutzniveau C (StromVV); gas pipelines below 400 GWh/year throughput end consumers; other energy companies below thresholds in Art. 12 para. 2. Nuclear-plant licence holders are exempt at ISG level itself. Service providers, network operators, producers, storage operators share the exemption; hardware, software manufacturers are explicitly excluded. Art. 12 (1) b |
| e | Financial entities subject to Banking Act, Insurance Supervision Act or Financial Market Infrastructure Act | No exemption |
| f | Health facilities on the cantonal hospital list (KVG Art. 39) | No exemption |
| g | Medical laboratories licensed under Art. 16 para. 1 Epidemiengesetz | Exempt under the general cross-sector SME threshold Art. 12: fewer than 50 employees and CHF 10m annual turnover/balance sheet. |
| h | Therapeutic Products Act for the manufacture, marketing, and import of medicinal products | Exempt under the general SME threshold Art. 12 |
| i | Organisations providing benefits against illness, accident, incapacity, old age, disability, and helplessness | No exemption |
| j | Swiss Broadcasting Corporation (SRG) | No exemption |
| k | News agencies of national significance | No exemption |
| l | Postal service providers registered with the Postal Commission (Postgesetz Art. 4) | Exempt under the general SME threshold Art. 12 (2) |
| m | Railways under Art. 5 or 8c Eisenbahngesetz; cableway, trolleybus, bus, and shipping companies holding a concession under Art. 6 Personenbeförderungsgesetz | Exempt unless BAV-supervised with public-interest system tasks essential to welfare/economy. Art. 12 (1) c |
| n | Civil aviation licensed by the Federal Office of Civil Aviation (BAZL); national airports per Sachplan Infrastruktur der Luftfahrt | Exempt if not subject to EU aviation information security requirements (Regulations 2023/203, 2022/1645) or EU aviation security program requirements (Regulations 2015/1998, 300/2008). Art. 12 (1) d |
| o | Transporting goods on the Rhine under the Seeschifffahrtsgesetz (maritime shipping law), and operating registration, loading, or unloading at Basel harbour | Not addressed. |
| p | Essential daily goods, where disruption would cause significant supply shortages | Exempt under the general SME threshold Art. 12 (2) |
| q | Telecommunications service providers registered with BAKOM (FMG Art. 4) | Not addressed. |
| r | Registry operators and registrars of internet domains under Art. 28b FMG | Not addressed. |
| s | Providers of services and infrastructure serving the exercise of political rights | No exemption. |
| t | Providers of cloud computing, search engines, and data centres domiciled in Switzerland; digital trust and digital security service providers | Cloud, search-engine, data-centre providers exempt only if they do not provide services to third parties for payment (self-use only is exempt). Digital trust and digital security services offered to third parties are not exempted. Art. 12 (1) e |
| u | Manufacturers of hardware, software used by critical infrastructure with remote maintenance access, OT, process control, public-safety | No exemption Art. 12 (1) b |
Sectors
Both ISG and CSV contain no sector taxonomy in the statute itself. Art. 74b (1) is simply an enumerated list of entity types (letters a to u, as depicted in the table above). Nonetheless, a sector construct exists operationally, since Art. 8 (2) CSV requires BACS to assign each registered operator to one or more sectors for information exchange, though this taxonomy is unpublished.
It may draw on the following nine sectors and 27 sub-sectors of the Federal Office for Civil Protection’s (BABS) national critical infrastructure strategy (SKI), though this link is unconfirmed.
- Authorities: Research and education; Cultural assets; Parliament, government, judiciary, administration
- Energy: Electricity supply; Oil supply; Gas supply; District and process heat
- Waste management: Waste; Wastewater
- Finance: Financial services; Insurance services
- Health: Chemicals and medicinal products; Laboratory services; Medical care
- Information and communication: IT services; Telecommunications; Media; Postal services
- Food: Food supply; Water supply
- Public safety: Armed forces; Emergency services (“blue light organisations” — police, fire, ambulance); Civil protection
- Transport: Air transport; Rail transport; Shipping; Road transport
Security and obligations
Core obligations for state entities
- Assess and protect information’s confidentiality, availability, integrity, and traceability, with risk management and objectives set at top-management level Art. 6-8
- Write security requirements into third-party contracts; detect and handle breaches, with contingency planning for critical ones Art. 9-10
- Classify information and apply corresponding IT security, personnel, and physical protection measures, including personnel security checks for security-sensitive roles Art. 11-48
- Cantons: only classification/IT-security duties, and only for federal data or IT resources Art. 3
- Security-cleared contractors: security concept, personnel screening, incident reporting, inspections Art. 49-73
Reporting obligation for entities on the exhaustive list
- Report cyberattacks to BACS within 24 hours of discovery (functionality threat, data manipulation or exfiltration, long-undetected attack, or extortion, threat, coercion) Art. 74a, 74d-74e
- Include required content (nature, effects, attacker information) and contact details if not already registered Art. 74e Art. 15
- Supplement missing information within 14 days Art. 74e Art. 16
- Submit via BACS’s secure system or another channel Art. 74f Art. 17
- Provide documents on request to clarify reporting-duty status Art. 74a Art. 13
Sanctions
Entities subject to core obligations
The ISG itself contains no fine or penalty provision for violations of Art. 6–26.
Entities subject to the reporting obligation
- Non-compliance triggers a two-step warning process: BACS sets a deadline, then issues a binding order with a penalty warning if that deadline is missed Art. 74g
- Wilful disregard of that order carries a fine of up to CHF 100,000, reduced to CHF 20,000 for minor cases, addressed to the responsible individual rather than the organisation Art. 74h