Compliance
Cyberattack Reporting in Switzerland: The Fine Regime Has Been Active Since October 2025
The duty to report cyberattacks against critical infrastructure entered into force on 1 April 2025 under the Federal Act on Information Security. A six-month grace period without sanctions ended in October 2025. Here is who is bound, what must be reported, and within what deadline.
On 7 March 2025, the Federal Council decided to bring into force, on 1 April 2025, the amendment to the Federal Act on Information Security (Informationssicherheitsgesetz, ISG), adopted by Parliament on 29 September 2023. Since that date, operators of critical infrastructure must report cyberattacks against their IT resources to the Federal Office for Cyber Security (OFCS) within 24 hours of detection.
The scope is defined by Article 74b of the Act and covers authorities and organisations active in sectors such as energy supply, drinking water supply, transport, and cantonal or communal authorities. It is a narrower list than the EU's NIS2, but the reporting logic is close: detection, deadline, escalation.
What must be reported, and when
- A cyberattack must be reported when it endangers the operation of the critical infrastructure concerned, has caused manipulation or leakage of information, or is accompanied by blackmail, threats or coercion.
- The first report is due within 24 hours of detection. If not all required information is available at that point, the report can be completed within 14 days.
- Reports go through the Cyber Security Hub (CSH), the OFCS's dedicated exchange platform, or through a standard email template for organisations without platform access.
Six months of tolerance, then a fine regime
The Federal Council chose a gradual entry into application. Failing to report was not sanctioned during the first six months, until early October 2025. Since then, non-compliance with the reporting duty is subject to fines under the Act. As of this writing, that fine regime has been in force for close to a year.
1 avr. 2025
entry into force of the mandatory reporting duty
24h
deadline to submit the initial report after detection
14 j
deadline to complete the report if information is missing
oct. 2025
start of the fine regime for non-compliance
A narrower law, but the same governance question
The ISG's scope is narrower than NIS2's, both in the sectors covered and in the size of the affected population. But the underlying question a board has to answer is identical to the one raised by NIS2 or DORA: does the organisation know, today, how it would detect, classify and report a significant cyberattack within 24 hours, and can it prove that capability rather than merely claim it. For groups operating in France or elsewhere in the EU alongside Switzerland, the two regimes now run in parallel, with different scopes and different deadlines, and both need a coordinated incident response plan rather than two separate improvised ones.
“A 24-hour reporting deadline is not a paperwork exercise. It is a test of whether incident detection actually works, run for the first time during a real incident.”
— Aegryn
Aegryn Advisory supports Swiss and European organisations in documenting incident detection and reporting readiness across NIS2, DORA and the Swiss ISG, and certifies the outcome under the CIFSO Security & Sovereignty dimension, ahead of the moment an auditor, an insurer or a regulator asks for proof.
This article was written with the assistance of artificial intelligence and reviewed under Aegryn editorial responsibility. In accordance with Article 50 of the EU AI Act, we assume editorial responsibility for this content.
Insights Aegryn
Recevez chaque semaine les analyses Aegryn — M&A, valorisation, tech, CIFSO.
Ready to submit your asset or access the catalogue?
