CTIPilot

Canton Bern Gesetz über Informations- und Cybersicherheit (ICSG) and IDSV ordinance

policy · policy:bern-icsg-cybersecurity-law-2026

Cantonal cybersecurity/information-security law for Canton Bern, passed 12 June 2025, entering into force 1 November 2026 alongside its implementing ordinance (IDSV); introduces 24h/72h incident-reporting duties, ICT-asset classification, rules on personal security screening and designated security-accountability roles for cantonal administrative units (Kanton Bern KAIO, 2026-09-09; Regierungsrat announcement relayed via headtopics.com, 2026-09-10).

Aliases: ICSG, IDSV, Informations- und Datensicherheitsverordnung Bern

Coverage timeline
1
first 2026-09-11 → last 2026-09-11
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Tags

Story timeline

  1. 2026-09-11Canton of Bern confirms 1 November 2026 entry-into-force for its new cybersecurity law (ICSG): 24h/72h mandatory incident reporting and named security accountability for every cantonal administrative unit
    researchBern's cantonal administration gets a fixed incident-reporting clock and a named accountable officer per agency ahead of its 1 November 2026 go-live

Where this entity is cited

  • research1

Source distribution

  • ch.headtopics.com1 (50%)
  • kaio.fin.be.ch1 (50%)

explore in graph

Entries about Canton Bern Gesetz über Informations- und Cybersicherheit (ICSG) and IDSV ordinance (1)

2026-09-11 · view entry permalink →

NOTABLENATOA2

Canton of Bern confirms 1 November 2026 entry-into-force for its new cybersecurity law (ICSG): 24h/72h mandatory incident reporting and named security accountability for every cantonal administrative unit

Canton Bern's government council (Regierungsrat) confirmed on 2026-09-10 that the cantonal Gesetz über Informations- und Cybersicherheit (ICSG), passed by the Grand Council on 12 June 2025 (Kanton Bern KAIO, 2026-09-09), and its implementing Verordnung über die Informations- und Datensicherheit (IDSV) enter into force on 1 November 2026 (headtopics.com / Kanton Bern Regierungsrat, 2026-09-10), a date also carried on KAIO's own page. From that date, every cantonal administrative unit must report cyberattacks and security incidents within 24 hours; where personal data is affected, a 72-hour deadline applies instead (headtopics.com / Kanton Bern Regierungsrat, 2026-09-10). The law introduces a graduated procedure for ICT assets: depending on protection need, either uniform baseline minimum measures apply or a detailed security-and-data-protection concept is required, and the canton classifies information as "intern", "vertraulich" or "geheim" only where unauthorised disclosure would harm its interests (headtopics.com / Kanton Bern Regierungsrat, 2026-09-10). New obligations include rules on personal security screening (Personensicherheitsprüfung) and, from 1 November 2026, explicit accountability assigned to each agency's or directorate's own top leadership as the designated security officer, supported by security officers and a new central advisory unit inside KAIO that also runs the cantonal information-security management system (Kanton Bern KAIO, 2026-09-09). The ICSG/IDSV explicitly satisfies the security requirements for cooperation with the federal government under the national Informationssicherheitsgesetz (Kanton Bern KAIO, 2026-09-09).

Municipal bodies and other public-task carriers in the canton are bound by the ICSG/IDSV only to the extent they process cantonal or federal information, use cantonal or federal ICT resources, or handle personal data on the canton's behalf; the cantonal rules otherwise apply to them only as a recommendation (Kanton Bern KAIO, 2026-09-09). The canton is also standing up a dedicated platform for reporting security incidents, vulnerabilities and data-security breaches, not yet published as of this writing, ahead of the 1 November 2026 go-live (Kanton Bern KAIO, 2026-09-09). Transition periods of two to three years apply for administrative units to fully implement the new requirements (headtopics.com / Kanton Bern Regierungsrat, 2026-09-10), and this complements rather than duplicates the revised cantonal data-protection law, already in force since 1 September 2026 (Kanton Bern KAIO, 2026-09-09).

Agencies will in future have to report cyberattacks and security incidents within 24 hours. Where personal data is affected, a 72-hour deadline applies, the cantonal government council wrote in a statement on Thursday. (translated from German)

headtopics.com, relaying a Kanton Bern Regierungsrat press statement 2026-09-10

The ICSG enters into force on 1 November 2026. (translated from German)

From 1 November 2026, responsibility for security lies with each agency's or directorate's top leadership as the designated security-responsible officer (SIVE DIR/Amt). (translated from German)

Kanton Bern, Amt für Informatik und Organisation (KAIO), official cantonal source 2026-09-09
policy11 Sep 04:37Zmulti-sourceOpen finding ↗