CTIPilot

Swiss E-ID trust infrastructure

policy · policy:swiss-e-id-trust-infrastructure single-source

The technical infrastructure (Basisregister, Vertrauensregister) underpinning Switzerland's electronic identity (E-ID), operated by the Federal Office of Justice and the Federal Office of Informatics and Telecommunications. In spring 2026 officials planned to award part of its operation to Amazon Web Services; Justice Minister Beat Jans vetoed the award in mid-February 2026 on digital-sovereignty grounds, with one of three reporting outlets also tying the decision to Amazon's exposure under the US CLOUD Act, a decision reported for the first time by Republik on 2026-09-01.

Coverage timeline
1
first 2026-09-02 → last 2026-09-02
Peak priority
notable
1 notable
Sources cited
4
4 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Story timeline

  1. 2026-09-02Swiss federal offices planned to outsource part of the E-ID trust infrastructure to Amazon Web Services; a ministerial veto stopped it in February 2026 on CLOUD Act and digital-sovereignty grounds
    researchBern almost handed a hyperscaler the register that verifies whether a Swiss digital identity is genuine

Where this entity is cited

  • research1

Source distribution

  • eid.admin.ch1 (25%)
  • heise.de1 (25%)
  • inside-it.ch1 (25%)
  • republik.ch1 (25%)

explore in graph

Entries about Swiss E-ID trust infrastructure (1)

2026-09-02 · view entry permalink →

NOTABLEupdatedNATOB2

Swiss federal offices planned to outsource part of the E-ID trust infrastructure to Amazon Web Services; a ministerial veto stopped it in February 2026 on CLOUD Act and digital-sovereignty grounds

Republik's investigation, published 2026-09-01, reveals that Switzerland's Federal Office of Justice (Bundesamt für Justiz) and Federal Office of Informatics and Telecommunications (BIT) planned in spring 2026 to award Amazon Web Services a contract covering core components of the Swiss E-ID's "Vertrauensinfrastruktur"; the trust infrastructure that confirms whether a digital identity is genuine and whether a requesting organization is authorized to verify it (Republik, 2026-09-01). The scope covered the Basisregister, which anonymously tracks whether a given E-ID is still valid, and the publicly queryable Vertrauensregister listing every authorized issuer and verifier, from federal, cantonal and communal authorities to private organizations such as banks. AWS was favored chiefly for its around-the-clock data-centre availability, which officials wanted as a fallback given delays in the Confederation's own planned government cloud; the Federal Office of Justice confirmed to Republik that "im Rahmen der Projektarbeiten wurden aus technischer Sicht sämtliche Optionen geprüft" (all options were reviewed from a technical standpoint as part of the project work, translated from German) (Republik, 2026-09-01).

Federal Councillor Beat Jans, the SP minister responsible for approving major federal IT procurements, vetoed the award in mid-February 2026: "an award to Amazon was out of the question," per Republik's sources close to the Federal Council, because handing the task to the American company would directly contradict the Federal Council's own objectives for greater Swiss digital sovereignty (Republik, 2026-09-01). The specific legal exposure behind that reasoning, per Inside IT's own relay of the same insider sourcing, is that Amazon as a US company is subject to the US CLOUD Act (Inside IT Switzerland, 2026-09-01); Republik's and heise's own reporting present the CLOUD Act point as their own explanatory framing rather than folding it into the insider-confirmed statement, so the sourcing on whether Jans's own confirmed rationale explicitly named the CLOUD Act, or only digital sovereignty in general, is not fully consistent across the three outlets. Republik's review of the Confederation's existing 2021 AWS framework contract (obtained after the outlet won a Federal Administrative Court case for disclosure) found a standardized commercial template rather than terms negotiated for state use: Amazon reserves the unilateral right to change the technical basis of the service, liability for outages is minimal, and on contract termination the administration has only 90 days to migrate all its data before Amazon irrevocably deletes it (Republik, 2026-09-01). An expert in decentralized trust architectures quoted by Republik frames the underlying risk independent of the vendor's home jurisdiction: "it becomes questionable when the state makes itself dependent, for critical infrastructure, on a single commercial provider that can discontinue operations, change terms, or impair availability" (translated from German) (Republik, 2026-09-01).

The E-ID's public launch is already delayed from end-2026 to the first half of 2027 for unrelated reasons, open questions on AHV-number lookups, AI-driven deepfake risk to online enrollment, and incompatibility with the EU's own eID system in its first version (Republik, 2026-09-01).

An award to Amazon was out of the question. (translated from German)

Republik 2026-09-01

It becomes questionable when the state makes itself dependent, for critical infrastructure, on a single commercial provider that can discontinue operations, change terms, or impair availability. (translated from German)

Republik, quoting Martina Kolpondinos (decentralized-trust-architecture expert)

If the cloud contract is terminated, the federal administration has only 90 days to withdraw its data before Amazon irrevocably deletes everything. (translated from German)

Republik 2026-09-01

In light of the latest developments in the field of artificial intelligence, security in the online issuance process for the E-ID is currently being further strengthened. In particular, through the use of additional technical safeguards, it should become harder to introduce malware onto end devices, and the detection of deepfakes should be strengthened.

Worth mentioning in particular are transparency through open source, the conducting of penetration tests, and bug bounty programmes.

Federal Office of Justice / eid.admin.ch (official) 2026-09-03
Updaterun 2026-09-05T0409Z-intelupdated_atsourcesevidencebody

At the 3 September 2026 meeting of the Advisory Council Digital Switzerland, chaired by Justice Minister Beat Jans with Federal Chancellor Viktor Rossi participating, the Federal Department of Justice and Police stated that security in the E-ID's online issuance process is currently being further strengthened in light of recent AI developments: "in particular, through the use of additional technical safeguards, it should become harder to introduce malware onto end devices, and the detection of deepfakes should be strengthened" (eid.admin.ch, 2026-09-03). The release, attributing the emphasis on learning from mistakes to Jans, names the programme's standing security controls as the mechanism for finding such gaps: "transparency through open source, the conducting of penetration tests, and bug bounty programmes" (eid.admin.ch, 2026-09-03). No technical specification of the "additional technical safeguards" (an attestation mechanism, device-integrity check or liveness-detection method) has been published; this is a policy-level commitment, not yet an implementation detail defenders can act on.

policy02 Sep 05:10Zsingle-sourceOpen finding ↗