2026-09-26 · view entry permalink →
Switzerland's Federal Council orders drafting of a standalone Cybersecurity Act (CSG), relocating the critical-infrastructure incident-reporting duty out of the Information Security Act
Switzerland's Federal Council decided at its session of 2026-09-25 to task the Federal Department of Defence, Civil Protection and Sport (VBS) with drafting, by June 2027, a consultation proposal for a new, standalone federal Cybersecurity Act (Bundesgesetz über die Cybersicherheit, CSG) (Bundesamt für Cybersicherheit, 2026-09-25). The CSG folds together three previously separate parliamentary mandates the Federal Office for Cybersecurity (BACS) had been developing as amendments to the existing Information Security Act (ISG): binding cyber-resilience requirements for manufacturers, importers and retailers of hardware and software products, explicitly modeled on the EU Cyber Resilience Act to ease compliance for internationally active firms already subject to it; strengthened protection duties for particularly important digital data; and participation and defense obligations for hosting and cloud providers (Bundesamt für Cybersicherheit, 2026-09-25).
Most consequential for the constituency this brief serves: the existing mandatory cyber-incident reporting duty for critical-infrastructure operators, in effect under the ISG since April 2025, is being relocated out of the ISG and into the new CSG; the ISG itself will continue to govern only the information security of federal authorities (Bundesamt für Cybersicherheit, 2026-09-25). Sector-specific rules under the Telecommunications Act, the Electricity Supply Ordinance and the Telecommunications Installations Ordinance are left untouched, with the CSG framed as supplementing them with cross-cutting duties. No operational obligation changes today: this is a drafting mandate with a June 2027 consultation-draft deadline, not yet a bill, but it settles the future statutory home of the incident-reporting duty that federal, cantonal and communal critical-infrastructure operators already comply with, and signals that product-cyber-resilience and hosting/cloud-provider obligations comparable to the EU CRA are coming to Switzerland as a dedicated instrument rather than an ISG amendment.
"The Federal Council, at its session of 25 September 2026, tasked the Federal Department of Defence, Civil Protection and Sport (VBS), for the purpose of strengthening national cybersecurity, with drafting, by June 2027, a consultation proposal for a new, standalone federal Cybersecurity Act." # (translated from German)
"a standalone federal Cybersecurity Act (Cybersicherheitsgesetz, CSG) is to be created, into which the cyber-incident reporting duty for critical infrastructure operators, in effect under the ISG since April 2025, will also be transferred. The ISG will continue to govern the information security of federal authorities." # (translated from German)
"The Federal Council has tasked the VBS with drafting a consultation proposal by June 2027 and submitting it for decision." # (translated from German)