Compare with different regulatory event:

Description

Parliament adopts amendments to Information Security Act including cyberattack reporting obligation

On 29 September 2023, the Swiss parliament adopted the revision of the Information Security Act including a reporting obligation for cyber attacks on critical infrastructures. The obligation applies to a a list of enumerated operators of critical infrastructure. The list includes providers of cloud computing, search engines, digital security and trust services and data centers based in Switzerland. In addition, the list includes manufacturers of hardware or software whose products are used in critical infrastructures, if the hardware or software enables remote maintenance access or it is used for the control and monitoring of operational systems and processes or for ensuring public safety. The implementation timeline of the amendments is yet to be determined.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
other service provider
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2022-01-12
in consultation

On 12 January 2022, the Swiss Federal Council opened a public consultation on a proposal to introdu…

2022-04-14
processing consultation

On 14 April 2022, the Swiss Federal Council closed the public consultation on potential amendments …

2022-12-02
under deliberation

On 2 December 2022, the Federal Council published its explanatory draft of the proposed revision of…

2023-09-29
adopted

On 29 September 2023, the Swiss parliament adopted the revision of the Information Security Act inc…