2026-09-11 · view entry permalink →
Canton of Bern confirms 1 November 2026 entry-into-force for its new cybersecurity law (ICSG): 24h/72h mandatory incident reporting and named security accountability for every cantonal administrative unit
Canton Bern's government council (Regierungsrat) confirmed on 2026-09-10 that the cantonal Gesetz über Informations- und Cybersicherheit (ICSG), passed by the Grand Council on 12 June 2025 (Kanton Bern KAIO, 2026-09-09), and its implementing Verordnung über die Informations- und Datensicherheit (IDSV) enter into force on 1 November 2026 (headtopics.com / Kanton Bern Regierungsrat, 2026-09-10), a date also carried on KAIO's own page. From that date, every cantonal administrative unit must report cyberattacks and security incidents within 24 hours; where personal data is affected, a 72-hour deadline applies instead (headtopics.com / Kanton Bern Regierungsrat, 2026-09-10). The law introduces a graduated procedure for ICT assets: depending on protection need, either uniform baseline minimum measures apply or a detailed security-and-data-protection concept is required, and the canton classifies information as "intern", "vertraulich" or "geheim" only where unauthorised disclosure would harm its interests (headtopics.com / Kanton Bern Regierungsrat, 2026-09-10). New obligations include rules on personal security screening (Personensicherheitsprüfung) and, from 1 November 2026, explicit accountability assigned to each agency's or directorate's own top leadership as the designated security officer, supported by security officers and a new central advisory unit inside KAIO that also runs the cantonal information-security management system (Kanton Bern KAIO, 2026-09-09). The ICSG/IDSV explicitly satisfies the security requirements for cooperation with the federal government under the national Informationssicherheitsgesetz (Kanton Bern KAIO, 2026-09-09).
Municipal bodies and other public-task carriers in the canton are bound by the ICSG/IDSV only to the extent they process cantonal or federal information, use cantonal or federal ICT resources, or handle personal data on the canton's behalf; the cantonal rules otherwise apply to them only as a recommendation (Kanton Bern KAIO, 2026-09-09). The canton is also standing up a dedicated platform for reporting security incidents, vulnerabilities and data-security breaches, not yet published as of this writing, ahead of the 1 November 2026 go-live (Kanton Bern KAIO, 2026-09-09). Transition periods of two to three years apply for administrative units to fully implement the new requirements (headtopics.com / Kanton Bern Regierungsrat, 2026-09-10), and this complements rather than duplicates the revised cantonal data-protection law, already in force since 1 September 2026 (Kanton Bern KAIO, 2026-09-09).
Agencies will in future have to report cyberattacks and security incidents within 24 hours. Where personal data is affected, a 72-hour deadline applies, the cantonal government council wrote in a statement on Thursday. (translated from German)
The ICSG enters into force on 1 November 2026. (translated from German)
From 1 November 2026, responsibility for security lies with each agency's or directorate's top leadership as the designated security-responsible officer (SIVE DIR/Amt). (translated from German)