CTIPilot

Switzerland's planned standalone federal Cybersecurity Act (Cybersicherheitsgesetz, CSG)

policy · policy:switzerland-cybersecurity-act-csg-2026 single-source-national-cert

Federal Council mandate of 2026-09-25 tasking the Federal Department of Defence, Civil Protection and Sport (VBS) to draft, by June 2027, a consultation proposal for a new standalone federal law consolidating CRA-aligned digital-product cyber-resilience rules, protection duties for important digital data, hosting/cloud-provider cybersecurity obligations, and the critical-infrastructure incident-reporting duty currently anchored in the Information Security Act (ISG) (Bundesamt für Cybersicherheit, 2026-09-25).

Aliases: Cybersicherheitsgesetz, CSG, Bundesgesetz über die Cybersicherheit

Coverage timeline
1
first 2026-09-26 → last 2026-09-26
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
research
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Tags

Story timeline

  1. 2026-09-26Switzerland's Federal Council orders drafting of a standalone Cybersecurity Act (CSG), relocating the critical-infrastructure incident-reporting duty out of the Information Security Act
    researchBern moves the critical-infrastructure breach-reporting duty into a new, standalone Cybersecurity Act

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • research1

Source distribution

  • bacs.admin.ch1 (33%)
  • netzwoche.ch1 (33%)
  • swisscybersecurity.net1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Switzerland's planned standalone federal Cybersecurity Act (Cybersicherheitsgesetz, CSG) (1)

2026-09-26 · view entry permalink →

NOTABLENATOA2

Switzerland's Federal Council orders drafting of a standalone Cybersecurity Act (CSG), relocating the critical-infrastructure incident-reporting duty out of the Information Security Act

Switzerland's Federal Council decided at its session of 2026-09-25 to task the Federal Department of Defence, Civil Protection and Sport (VBS) with drafting, by June 2027, a consultation proposal for a new, standalone federal Cybersecurity Act (Bundesgesetz über die Cybersicherheit, CSG) (Bundesamt für Cybersicherheit, 2026-09-25). The CSG folds together three previously separate parliamentary mandates the Federal Office for Cybersecurity (BACS) had been developing as amendments to the existing Information Security Act (ISG): binding cyber-resilience requirements for manufacturers, importers and retailers of hardware and software products, explicitly modeled on the EU Cyber Resilience Act to ease compliance for internationally active firms already subject to it; strengthened protection duties for particularly important digital data; and participation and defense obligations for hosting and cloud providers (Bundesamt für Cybersicherheit, 2026-09-25).

Most consequential for the constituency this brief serves: the existing mandatory cyber-incident reporting duty for critical-infrastructure operators, in effect under the ISG since April 2025, is being relocated out of the ISG and into the new CSG; the ISG itself will continue to govern only the information security of federal authorities (Bundesamt für Cybersicherheit, 2026-09-25). Sector-specific rules under the Telecommunications Act, the Electricity Supply Ordinance and the Telecommunications Installations Ordinance are left untouched, with the CSG framed as supplementing them with cross-cutting duties. No operational obligation changes today: this is a drafting mandate with a June 2027 consultation-draft deadline, not yet a bill, but it settles the future statutory home of the incident-reporting duty that federal, cantonal and communal critical-infrastructure operators already comply with, and signals that product-cyber-resilience and hosting/cloud-provider obligations comparable to the EU CRA are coming to Switzerland as a dedicated instrument rather than an ISG amendment.

"The Federal Council, at its session of 25 September 2026, tasked the Federal Department of Defence, Civil Protection and Sport (VBS), for the purpose of strengthening national cybersecurity, with drafting, by June 2027, a consultation proposal for a new, standalone federal Cybersecurity Act." # (translated from German)

"a standalone federal Cybersecurity Act (Cybersicherheitsgesetz, CSG) is to be created, into which the cyber-incident reporting duty for critical infrastructure operators, in effect under the ISG since April 2025, will also be transferred. The ISG will continue to govern the information security of federal authorities." # (translated from German)

"The Federal Council has tasked the VBS with drafting a consultation proposal by June 2027 and submitting it for decision." # (translated from German)

Bundesamt für Cybersicherheit (BACS) 2026-09-25
policy26 Sep 04:04Zsingle-source · national CERTOpen finding ↗