Switzerland: Reporting obligation for cyber attacks on critical infrastructures under amended Information Security Act comes into effect

Description

Reporting obligation for cyber attacks on critical infrastructures under amended Information Security Act comes into effect

On 1 April 2025, the reporting obligation for cyber attacks on critical infrastructures included in 2023 amendments to the Information Security Act comes into effect. This follows the adopted amendment of the law on 29 September 2023 and the official approval of these obligations by the Federal Council on 7 March 2025. The obligation applies to critical infrastructure operators including providers of cloud computing, search engines, digital security and trust services and data centres based in Switzerland. Critical infrastructure includes energy and water supply, transportation, and administration of municipalities or cantons. These operators must report any cyber attacks that threaten infrastructure functionality, cause data leaks or manipulation, or involve threats or coercion through the Federal Office for Cyber Security (BACS) platform within 24 hours of discovery.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
other service provider
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2022-01-12
in consultation

On 12 January 2022, the Swiss Federal Council opened a public consultation on a proposal to introdu…

2022-04-14
processing consultation

On 14 April 2022, the Swiss Federal Council closed the public consultation on potential amendments …

2022-12-02
under deliberation

On 2 December 2022, the Federal Council published its explanatory draft of the proposed revision of…

2023-09-29
adopted

On 29 September 2023, the Swiss parliament adopted the revision of the Information Security Act inc…

2025-04-01
in force

On 1 April 2025, the reporting obligation for cyber attacks on critical infrastructures included in…

2025-10-01
in force

On 1 October 2025, the enforcement of fines under the amended Information Security Act begins. Sinc…

We use cookies and other technologies to perform analytics on our website. By opting in, you consent to the use by us and our third-party partners of cookies and data gathered from your use of our platform. See our Privacy Policy to learn more about the use of data and your rights.