What are the instruments actually called?
Three names, each with two local abbreviations, and English coverage tends to mix them up. The Information Security Act (ISA) of 18 December 2020 — Informationssicherheitsgesetz (ISG) in German, loi sur la sécurité de l'information (LSI) in French, SR/RS 128 — carries the cyber-incident reporting duty in art. 74a et seq., inserted by the amendment of 29 September 2023. The reporting authority is the National Cyber Security Centre (NCSC), which is Bundesamt für Cybersicherheit (BACS) in German and Office fédéral de la cybersécurité (OFCS) in French; the same office, three names, and Swiss-German material will say BACS where the English pages say NCSC. Data protection sits in the revised Federal Act on Data Protection (revFADP) — Datenschutzgesetz (DSG), loi fédérale sur la protection des données (LPD), SR/RS 235.1 — supervised by the Federal Data Protection and Information Commissioner (FDPIC), the EDÖB or PFPDT. The exemptions from the reporting duty live in the Cybersecurity Ordinance of 7 March 2025 (CSV in German, OCyS in French, RS 128.51), in force since 1 April 2025.
Which entities in a group are actually caught?
Chapter 5 of the ISA covers federal measures to protect Switzerland against cyberthreats; its section 2 is the reporting obligation. Art. 74a para. 1 requires the authorities and organisations listed in art. 74b to ensure that cyberattacks on their IT resources are reported to the NCSC. Art. 74b is therefore the scoping provision, and it is a list, not a test of size or impact: operators of critical infrastructure in energy, drinking water, transport, finance, health, telecommunications, post, media, food supply and IT, plus federal authorities and cantonal and communal administrations. Letter e of that list covers banks, insurers and financial market infrastructures, which is why a Swiss banking or insurance subsidiary is in scope while its Frankfurt-based manufacturing sister company is not.
An entity outside the list is not caught by the ISA at all, however serious the incident. This is the single most useful correction for a group function building a global incident matrix: Switzerland has not introduced a general cyber-reporting duty for business — it has introduced a sectoral one.
Sector membership does not settle it either. Art. 74c, on exceptions to the reporting duty, hands the detail to the Cybersecurity Ordinance. That is where an exemption has to be checked, and not in a summary: the flat thresholds that circulate in the market — a headcount, a turnover figure — should not be adopted without reading the ordinance itself.
Two structural points follow for a multinational. First, the duty attaches to the Swiss entity that operates the infrastructure, not to the group parent, not to a shared security operations centre in London or Frankfurt, and not to the managed-services provider running the estate. Outsourcing the operation does not outsource the duty. Second, foreign establishment is irrelevant in the other direction too: a foreign company is not brought into the ISA by having Swiss customers. The question is whether the listed Swiss organisation is yours.
Does NIS2 apply to a Swiss entity?
No. Directive (EU) 2022/2555 is an EU instrument, and Switzerland belongs to neither the EU nor the EEA. There is no direct effect and no Swiss transposition. Anyone mapping a group estate should mark the Swiss entities as outside NIS2 and inside the ISA, and stop there as a matter of law.
As a matter of commercial reality, NIS2 arrives anyway — through the contract rather than through the statute. EU customers who are themselves in scope pass their supply-chain obligations down: reporting windows, evidence duties, audit rights. A Swiss provider serving EU clients will often find itself committed to the NIS2 staged pattern — an early warning within 24 hours of becoming aware, a full incident notification within 72 hours, a final report within a month — because a customer wrote it into a master agreement, not because Swiss law says so. That distinction matters when the terms conflict: a contractual 72-hour notification to a customer and a statutory 24-hour report to the NCSC are separate obligations with separate recipients, and neither discharges the other.
Which duty is the 24-hour clock, and which is not?
Switzerland has two incident duties. They are genuinely independent — different addressees, different triggers, different clocks, different sanctions — and a single incident can trigger both.
| ISA, art. 74a et seq. | revFADP, art. 24 | |
|---|---|---|
| Who is bound | Only the authorities and organisations listed in art. 74b: critical-infrastructure operators, federal authorities, cantonal and communal administrations | Every controller within the scope of the revFADP |
| Authority | NCSC (BACS / OFCS), through the Cyber Security Hub | FDPIC (EDÖB / PFPDT) |
| Trigger | A cyberattack that endangers the functioning of the critical infrastructure, has led to manipulation or leakage of data, or involves extortion, threat or coercion | A breach of data security likely to result in a high risk to the data subject's personality or fundamental rights |
| Deadline | 24 hours from discovery; an incomplete initial report to be completed within 14 days | As soon as possible — no fixed number of hours. There is no 72-hour deadline in Swiss law. |
| Sanction | Fines to CHF 100,000, applicable since 1 October 2025 | Failure to notify is not in itself punishable; exposure arises indirectly through an FDPIC ruling |
The practical instruction is to run the two paths separately in the incident plan. They answer different questions: the NCSC wants to know what happened to the infrastructure, the FDPIC what happened to the individuals. The related duty to inform data subjects, and the review right that sits alongside it, are set out under automated decisions under art. 21 revFADP; supervised institutions have a further layer in the FINMA guidance 08/2024.
The verb is not a stylistic detail
Easy to miss in translation, expensive to miss in an incident. The two Swiss texts use different verbs: the revFADP has the controller annonce (French) or meldet (German) the breach to the FDPIC, rendered in the Fedlex English translation as notify … as quickly as possible, while the ISA uses signaler for the report to the NCSC. Reaching for notify, the GDPR word, for both is a reliable sign that neither text has been read — and it has an operational consequence: teams that use one word build one process for two duties, and that process runs on the longer clock.
Which incidents have to be reported, and what happens after the first 24 hours?
Not every attack. An attack with any one of three characteristics:
- It endangers the functioning of the critical infrastructure.
- It has led to the manipulation or leakage of data.
- It is connected with extortion, threat or coercion.
The criteria are alternatives; one is enough. The third does more work than it looks. A ransomware demand triggers the duty even where there has been no service interruption and even where exfiltration has not been established.
The report goes to the NCSC through the Cyber Security Hub within 24 hours of discovery — from discovery of the attack, not from completion of the analysis — and an incomplete initial report must be completed within 14 days. The two-stage design is a relief and a trap at once. You are not required to have understood the incident within 24 hours. You are required to report it within 24 hours, and then to explain it within a fortnight.
What does non-compliance cost, and who pays?
On the ISA side, a six-month transitional period ran until 1 October 2025. Since that date the ISA sanctions apply, with fines up to CHF 100,000. The grace period is over.
The data-protection side is structurally different, and English-language coverage routinely gets it wrong by importing the GDPR's administrative-fine model. Swiss revFADP sanctions are criminal, and they fall on natural persons. Art. 60 to 63 provide for fines of up to CHF 250,000 against private persons acting wilfully; art. 61 in particular reaches wilful failure to comply with the minimum data security requirements the Federal Council sets under art. 8 para. 3. Under art. 64 para. 2, where a fine of no more than CHF 50,000 is in contemplation and identifying the individual would require disproportionate effort, the authority may instead order the undertaking to pay — subsidiary, capped, and the exception rather than the rule. And the FDPIC does not impose these fines at all: it issues rulings, and the fines are pronounced by cantonal criminal prosecution authorities. A board paper that budgets a CHF 250,000 corporate fine payable to the FDPIC is describing a regime that does not exist.
Why are 24 hours short when automated systems are acting?
The operational difficulty is not sending the report. It is establishing within a single day what actually happened.
Where automated or agentic processes act continuously — releasing payments, exporting data sets, changing access rights — the incident is not an event but a chain. The first day's question is which links in that chain were authorised and which were not. An organisation that cannot answer files on an uncertain basis, and the 14-day completion becomes a forensic exercise under time pressure, usually running in parallel with recovery.
Reconstruction speed therefore determines the quality of the report. It does not depend on how much is logged. It depends on whether a single action can be tied to its authorisation: which process, on which model and configuration version, on the strength of which approval, at what moment. Where that link is missing, all that remains is reconstruction from scattered system logs — days of work, not hours. The field-level detail is set out in AI-agent traceability under Swiss law and, in general terms, in AI agent audit trails.
What do the first six months show?
The NCSC received 164 reports in the first six months of the duty, according to its evaluation published on 29 September 2025. By sector, finance leads with 19 per cent, ahead of IT at 8.7 per cent and energy at 7.6 per cent.
For an entire country over half a year that is a low number. It says nothing on its own about whether reporting is too sparse or the scope is simply narrow. What is more striking is the concentration: a duty written across ten sectors is being exercised, in practice, by a handful of them.
What does a group security function have to do differently?
A Swiss domestic operator and a multinational face the same statute and different operational problems. Four differences are worth planning for.
The clock runs in Swiss local time and does not wait for group governance. Twenty-four hours from discovery gives no room for a decision that has to travel to a group CISO in another time zone and back. Name a Swiss-side owner and a deputy with authority to file, and make filing the default rather than an escalation.
Cyber Security Hub access belongs to the entity. Registration is not something a group security function can hold generically on behalf of everyone. Set it up before it is needed; registering mid-incident consumes hours the deadline does not have.
Scope has to be decided per entity and written down. Including a reasoned negative. A group inventory that records Swiss entities as in scope for NIS2, or as subject to a 72-hour deadline, will generate the wrong runbook and the wrong training.
The German and French texts govern. A group incident policy in English is a translation of the obligation, not the obligation. Where this page and the statute differ, the statute wins; where your Swiss counsel and this page differ, counsel wins. The glossary gives the vocabulary — ISG, LSI, BACS, OFCS, EDÖB, PFPDT — and the corrections list tracks the claims we have had to correct.
How do you set the two reporting paths up before an incident?
- Settle scope in writing, per entity. Does it fall within a sector listed in art. 74b, and does an exemption in the Cybersecurity Ordinance apply? Record the reasoning, including a reasoned no.
- Register for the Cyber Security Hub in advance. The registration belongs to the Swiss entity.
- Name the person who owns the 24-hour clock, with a deputy, in Swiss time, and without dependence on a management decision that will not be taken on a Sunday.
- Run the two duties as separate processes: the ISA report to the NCSC, the revFADP notification to the FDPIC — different triggers, thresholds, forms and deadlines.
- Rehearse reconstruction, not just recovery. An exercise that only tests bringing services back up does not prepare the report or the 14-day completion.
In practice
For the automated part of the estate, the control that decides whether step five is answerable is where the record is written. BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts, recording the trigger, the parameters, the policy version and the approver before the action leaves the system. Approval checkpoints in governed workflow automation serve the same end for cross-system processes.
Frequently asked questions
Does the 24-hour duty apply to an ordinary Swiss company?
No. It binds the authorities and organisations listed in art. 74b ISA — critical-infrastructure operators in the listed sectors, federal authorities, cantonal and communal administrations. Outside that list there is no general 24-hour cyber-reporting duty. Whether a company inside a listed sector is exempt is governed by the Cybersecurity Ordinance.
Is there a 72-hour deadline in Swiss law?
No. Art. 24 revFADP requires notification to the FDPIC as soon as possible, with no fixed number of hours. The 72-hour figure comes from Article 33 GDPR. The only fixed Swiss clock is the 24 hours owed to the NCSC under the ISA, and it binds a much narrower population.
Does the NCSC report replace the notification to the FDPIC?
No. The two duties are independent. The same incident can require a report to the NCSC within 24 hours and a notification to the FDPIC as soon as possible, where a high risk to the individuals concerned also exists.
Does NIS2 apply to Swiss entities?
Not directly. Switzerland is a member of neither the EU nor the EEA. NIS2 requirements nevertheless reach Swiss suppliers contractually, through the supply-chain obligations of EU customers.
Who pays a Swiss data-protection fine?
A natural person, in criminal proceedings, up to CHF 250,000. The undertaking is liable only subsidiarily and only up to CHF 50,000 under art. 64 para. 2. The FDPIC issues rulings; the fines are pronounced by cantonal prosecuting authorities.
What has to be in the first report?
Enough to report the attack within 24 hours of discovery. Completeness is not required at that point: an incomplete initial report is completed within 14 days.
Related reading
- AI-agent traceability: what Swiss law actually requires
- Automated individual decisions under art. 21 revFADP
- Data protection impact assessments for AI under art. 22 revFADP
- FINMA guidance 08/2024 on AI governance
- AI agent governance — the library index
- Human in the loop: what the control has to produce
In practice
Contain the incident first, prove what happened second — inside the reporting window.
Reporting clocks run in hours, and management liability turns on whether controls were implemented and supervised, not merely approved. Barzel isolates credentials, cuts an agent off in one action and keeps signed receipts of what ran — the material a notification and a board report are written from.
In force24-hour reporting duty to the NCSC in force since 1 April 2025; fines since 1 October 2025
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
Barzel Central Gateway
The AI governance control plane: one inventory and one policy layer across every MCP server and agent.
- Registers and synchronises every tool; enforces identity, policy, region, cost and health per tool.
- Identity mapping through OIDC, Entra ID, Okta, SAML and SPIFFE, with credential brokerage.
- Trace and SIEM export (W3C trace context, OTLP) for the security team and the regulator.
Free tier: 1,000 calls a monthPaid plans from $10 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Sources
- Informationssicherheitsgesetz (ISG), SR 128 — Information Security Act of 18 December 2020, art. 74a et seq.; amendment of 29 September 2023. French text: LSI, RS 128, chapter 5 section 2, art. 74a to 74c — fedlex.admin.ch.
- Verordnung vom 7. März 2025 über die Cybersicherheit (CSV) — Cybersecurity Ordinance, in force since 1 April 2025; exemptions from the reporting duty — fedlex.admin.ch.
- NCSC, Information on the reporting obligation — 24 hours from discovery, 14 days to complete, Cyber Security Hub.
- NCSC, Legal basis for the reporting obligation — ISA and Cybersecurity Ordinance, in force 1 April 2025.
- Six-month reporting obligation for cyberattacks on critical infrastructures, 29 September 2025 — 164 reports; finance 19%, IT 8.7%, energy 7.6%.
- Federal Act on Data Protection (FADP), SR 235.1, art. 21, 24, 60–64 — fedlex.admin.ch English translation; binding German and French texts at DSG and LPD.
- FDPIC, Update: current data protection legislation is directly applicable to AI, 8 May 2025.
- Directive (EU) 2022/2555 (NIS2), 14 December 2022 — not applicable in Switzerland; cited for delimitation.
This article is for information and does not constitute legal advice. The German and French texts of the instruments cited are the binding ones. Position as at 3 September 2026.