Skip to content

One law instead of several individual amendments

With its decision of 25 September 2026, the Federal Council is reorganising Switzerland’s cyber regulation framework. The Federal Department of Defence, Civil Protection and Sport (DDPS) has been tasked with drawing up, by June 2027, a consultation draft for a standalone federal law on cyber security (Cyber Security Act, CSA).

This is more than just a redrafting of existing provisions. Three legislative projects, which had previously been dealt with separately, are to be consolidated into a single piece of legislation: the cyber resilience of products containing digital elements, the protection of particularly important digital data, and the role of hosting and cloud providers in the event of cyber threats. Added to this is the obligation to report cyber-attacks on critical infrastructure, which has been in force since April 2025 and is to be transferred from the Information Security Act to the new CSG.

The reasoning behind this is clear: products, data and digital infrastructure are closely interlinked from a technical perspective. Current regulation only partially takes these interdependencies into account. Precisely for this reason, however, the new Act will have to be judged on whether it actually links these areas coherently – or merely brings together several existing and planned obligations under a new legislative title.

From the protection of critical infrastructure to the regulation of the digital supply chain

Until now, Switzerland’s cross-sector cyber regulation has focused in particular on critical infrastructure. We have already reported on this: From 1 April 2025, operators covered by the legislation must, in principle, report certain cyber-attacks to the Federal Office for Cyber Security (BACS) within 24 hours of their discovery. If not all the necessary details can be provided immediately, there is a 14-day deadline to complete the report.

The new CSG is set to have a significantly broader scope. In particular, it aims to establish binding requirements for manufacturers, importers and distributors of software and hardware products. Based on the key details known so far, the legislation is also intended to lay the foundations for market surveillance and the possibility of prohibiting the sale of insecure products.

This marks a shift in the regulatory focus: cyber security should no longer only become relevant when a particularly important company is attacked. It should begin as early as the development and deployment of digital products. For Swiss cyber regulation, this represents a significant shift in the regulatory approach: Cyber risks should, as far as possible, be addressed where they arise and can be influenced – that is to say, amongst other things, at the product manufacturer’s stage and not exclusively at the stage of the subsequent operator.

Alignment with the Cyber Resilience Act: Sensible – but only if there is genuine compatibility

When it comes to regulating digital products, Switzerland intends to align itself explicitly with the European Cyber Resilience Act (CRA). The CRA sets out horizontal cybersecurity requirements for products containing digital elements and covers, amongst other things, requirements relating to development, production and the handling of vulnerabilities.

Alignment with European law is of considerable importance from a business perspective. Many Swiss manufacturers market their products in the EU single market anyway and must therefore check whether they are subject to the CRA. Its reporting obligations for actively exploited vulnerabilities and serious security incidents have been in force since 11 September 2026; the CRA will, in principle, become fully applicable from 11 December 2027.

Against this background, little would be gained if Swiss companies were in future required to set up two compliance systems that are broadly similar but differ in detail. It will therefore be crucial to determine what ‘alignment with the CRA’ actually means in practice. A regulation that is merely similar in substance is not necessarily sufficient. For companies, differences in definitions, product categories, compliance requirements, documentation, reporting channels or deadlines are particularly costly. The more the Swiss requirements are compatible with the European system in terms of substance and procedure, the more likely it is that companies will be able to avoid having to establish parallel processes for the same product. However, substantive alignment alone is not necessarily sufficient. For companies operating internationally, it will be equally important whether technical standards, evidence of conformity and documentation can be reused as widely as possible. Otherwise, additional formal compliance processes could arise despite largely identical security requirements. The Federal Council also explicitly cites the reduction of administrative burdens as an objective. It is precisely against this that the subsequent draft legislation must be measured.

A dedicated Cyber Security Act can bring order – or create new overlaps

The decision in favour of a standalone Cybersecurity Act (CSG) has a structural advantage: cyber regulation becomes more visible as a distinct area of law. At the same time, however, this gives rise to a key legislative challenge: cyber incidents do not adhere to the boundaries of individual areas of law.

A single incident, for example, can simultaneously raise issues relating to cyber security law, data protection law and sector-specific supervisory regulations. Even when the current cyber incident reporting obligation was introduced, harmonisation with other reporting obligations was a key concern for the parties affected. The BACS has therefore provided that, upon request, reports may in some cases be forwarded to other competent authorities.

However, the aim of consolidation must not obscure the fact that the CSG is not intended to completely replace existing sector-specific regulation. According to the plans communicated so far, existing regulations in telecommunications law, electricity supply law and in the area of telecommunications installations, amongst others, are to remain in force. For regulated companies, it will therefore be crucial to understand how the new horizontal requirements of the CSG interact with existing sector-specific obligations. The practical challenge thus lies less in the sheer number of laws than in avoiding conflicting obligations or those that must be fulfilled multiple times.

The new CSG now offers an opportunity to take this idea further. From a compliance perspective, the aim should not be to create as many parallel reporting obligations as possible. Rather, it is crucial that companies are able to clearly determine:

  • which incident
  • within what timeframe
  • with what content
  • to which authority

must be reported.

Where several obligations apply simultaneously, processes should be coordinated technically and legally as far as possible. Otherwise, there is a risk of considerable administrative burden arising precisely during the first few hours of a serious cyber-attack – that is, at exactly the time when resources for technical containment, communication and recovery are needed and are typically limited.

‘The most important digital data’: The legislator needs clear criteria

Regulating particularly important digital data is likely to prove a particularly challenging task. Motion 23.3002 calls for criteria to be established to determine which data held by the Confederation, cantons and municipalities, as well as by operators of critical infrastructure, is subject to special protection. In addition, guidelines for the security management of this data are to be laid down.

The BACS has held workshops on this topic with representatives of critical infrastructure operators. These revealed, amongst other things, that the criticality of data can vary significantly depending on the sector and the specific scenario. Particular focus was placed on the question of which data is necessary in a crisis situation to ensure the continuation of essential services.

This is precisely where the regulatory problem lies. A definition that is too narrow could overlook data whose significance only becomes apparent from its function within a specific supply chain. A very broad or vague definition, on the other hand, would create considerable legal uncertainty.

It must be clear to businesses as early as possible which data sets are subject to specific requirements and why. Furthermore, the new concept should be clearly distinguished from data protection law. The need for protection under data protection law depends, in particular, on the connection to natural persons and the resulting risks to their privacy and fundamental rights. The criticality of a dataset for the functioning of an infrastructure is a separate issue. A dataset may therefore be of great importance to national or operational resilience without containing personal data requiring special protection – and vice versa.

The CSG should clearly distinguish between these different aspects of protection.

Cloud and hosting providers: obligations need clear boundaries

Another key focus concerns hosting and cloud providers. The planned legislation is intended, amongst other things, to impose obligations on them to cooperate and defend against cyber threats.

The rationale is understandable: cloud and hosting infrastructures play a central role in the digital economy and can, at the same time, be misused by third parties for cyberattacks. However, the crucial questions only arise when it comes to the specific details of the legislation. What must a provider do if its infrastructure is suspected of being used for an attack? What checks can be required of them? When is there a duty to intervene? What information may or must be shared with the authorities? And how can such duties be reconciled with contractual obligations, as well as data protection and data security? Such questions cannot yet be answered on the basis of the announcement made so far.

From the perspective of the rule of law and in practical terms, however, it will be crucial that obligations to cooperate are clearly defined and proportionate. Hosting and cloud providers should not, through vague general clauses, effectively become comprehensive private surveillance bodies for all their customers’ activities. At the same time, the law must enable effective action to be taken where there is evidence that infrastructure is being used for cyber-attacks.

Striking a balance between these two concerns is likely to be one of the most challenging aspects of the forthcoming consultation.

Product safety becomes an ongoing task

Product-related regulation also deserves particular attention. Traditional product safety is often associated with the condition of a product when it is placed on the market. In the case of software and connected products, such a one-off approach is insufficient: new vulnerabilities may only come to light months or years later.

The CRA addresses this problem by not only setting out requirements for design and development, but also mandating processes for vulnerability management throughout the product’s expected lifespan. If the Swiss model is to be based on the CRA, the question of how manufacturers identify, assess and remedy security vulnerabilities after a product has entered the market is likely to become increasingly important here too.

For companies, cyber resilience is therefore no longer just a matter for the IT department. Product development, legal, compliance, procurement, support and management must work closely together.

Open source also raises questions of demarcation

Particular attention should also be paid to the handling of open-source software. The Federal Council explicitly cites open source as an area that could be regulated more specifically in the new CSG. It is precisely here that the legislator must make a careful distinction: not everyone who develops or publishes software free of charge should be subject to the same obligations as a commercial manufacturer marketing a digital product.

On this point, too, the CRA provides an important framework of reference. For Swiss software companies, it will be crucial whether the CSG adopts comparable distinctions and thereby prevents open-source development from being hampered by disproportionate compliance requirements.

Regulation alone does not ensure cyber security

The CSG aims to strengthen national cyber security. However, a distinction should be made between legal compliance and actual resilience. Reporting forms, documentation and formal responsibilities can be useful management tools. However, they do not in themselves prevent an attack. This is precisely why future regulation should be focused as much as possible on concrete security outcomes and avoid unnecessary formalities. In this regard, the legislator will have to address a difficult question: what minimum requirements must be made mandatory – and where should companies be allowed sufficient flexibility to implement technical measures on a risk-based basis and in line with the state of the art? The faster attack methods and technologies change, the more problematic rigid technical requirements enshrined in the law itself can become.

Added to this is the question of proportionality. Not every digital product, provider or dataset presents the same potential risk. A viable regulatory framework should therefore be designed to be as risk-based as possible and take into account differences in function, corporate role and actual cyber risk. Otherwise, particularly for smaller providers, the burden of formal compliance requirements may be disproportionate to the additional security benefits gained.

What companies can do to prepare now

The draft bill is not due to be finalised until June 2027. Nevertheless, affected companies should not wait until the law is on the verge of being passed before beginning implementation.

  • Manufacturers of digital products should check whether cybersecurity is already systematically integrated into product development, testing, vulnerability management, update processes and product documentation. Companies with EU operations must already comply with the CRA’s requirements, regardless of the future Swiss CSG.
  • Cloud and hosting providers should document in a transparent manner how cyber threats are detected, escalated internally and addressed. Responsibilities and interfaces with customers also merit attention.
  • Operators of critical infrastructure must comply with the existing Swiss reporting obligation, irrespective of the new law, and must have their incident response processes structured accordingly.
  • Finally, organisations with particularly critical data sets should know which information is indispensable for maintaining their most important processes. Such classification forms part of robust resilience planning, even independently of any future legal obligation.
  • Software companies that develop, distribute or integrate open-source components into their own products should also document the role they play within the respective software supply chain. It is precisely this division of roles that could prove decisive for subsequent regulatory liability.

Six points against which the draft bill must be assessed

With the publication of the consultation draft, six questions in particular will need to be examined:

  1. Does the CSG bring about genuine harmonisation?
    The new law should systematically consolidate existing and new cyber obligations, rather than merely adding another regulatory area alongside data protection, product and sector-specific legislation.
  2. How compatible is Swiss product regulation actually with the CRA?
    For Swiss companies operating internationally, it is not just a similar set of objectives that is crucial. Differing definitions, evidence requirements and processes can result in significant additional costs.
  3. What constitutes ‘particularly important digital data’?
    The criteria must be sufficiently specific to enable companies to reliably determine their scope of application, whilst at the same time taking appropriate account of different types of critical infrastructure.
  4. How far do the obligations of cloud and hosting providers extend?
    Effective cooperation in the event of cyber threats requires clear legal requirements, responsibilities and boundaries.
  5. Will cyber compliance become more practicable in the event of an emergency?
    In particular, reporting obligations should be coordinated in such a way that, during a cyber incident, organisations do not have to submit the same information multiple times via different channels to different authorities.
  6. Are the obligations risk-based and proportionate?
    Not every digital product, data set or provider presents the same cyber risk. The decisive factor will be whether the CSG differentiates according to a company’s risk, function and role, and whether the regulatory burden is proportionate to the intended security gains.

Ultimately, these points are more crucial than the question of whether cyber security is regulated by a single federal act or by several specialised acts.

Conclusion: The CSG presents an opportunity for consolidation – provided it does not stop at a new label

The proposed Cyber Security Act marks an important next step in Swiss cyber regulation. Rather than considering individual risks in isolation, the Federal Council aims to bring together products, particularly important data, digital infrastructure and the existing cyber incident reporting obligation within a single legal framework. This is also the project’s real opportunity.

However, added value will only be created if the consolidation is also successful in substance: businesses need clear scopes of application, coordinated reporting channels and requirements that are as compatible as possible for the Swiss and European markets. The quality of the Act cannot be measured solely by how many regulatory areas are consolidated into a single piece of legislation. What is far more crucial is whether it works in tandem with existing sector-specific legislation and whether companies can utilise evidence, technical standards and compliance processes as efficiently as possible across different regulatory systems.

Cloud and hosting obligations must be effective, yet sufficiently well-defined. Clear and proportionate boundaries are also needed for open-source software. And additional compliance requirements should be introduced where they promise a tangible security benefit – not as a result of regulatory duplication.

Whether the CSG meets this requirement will only be possible to assess properly once the consultation draft is available. Until then, affected companies should monitor three developments in particular: the Swiss legislative process, the ongoing implementation of the European Cyber Resilience Act, and the experience gained from the Swiss cyber incident reporting obligation, which has been in force since April 2025.

Sources

Federal Council / Federal Office for Cyber Security

European Union

Existing HÄRTING articles

 

Contacts

Corinna Stubenvoll and Nicole Beranek Zanon