Switzerland plans new Federal Cybersecurity Act
The Swiss Federal Council has announced plans to create a new standalone Federal Cybersecurity Act, consolidating several ongoing legislative projects into a single regulatory framework. The Federal Department of Defence, Civil Protection and Sport (DDPS) has been instructed to prepare a consultation draft.
The new legislation aims combine three areas currently being addressed through separate legislative projects: the cyber resilience of products with digital elements, the protection of particularly important digital data, and the cybersecurity responsibilities of hosting and cloud service providers. In addition, the existing obligation for critical infrastructure operators to report cyberattacks, which has been in force under the Information Security Act since April 2025, will be transferred to the new Cybersecurity Act.
Among other measures, the planned legislation is expected to introduce binding cybersecurity requirements for manufacturers, importers and distributors of software and hardware products, together with a market surveillance framework and the possibility of prohibiting the distribution of insecure products. The regulatory approach will be aligned with the EU Cyber Resilience Act (CRA), with the aim of limiting additional compliance burdens for companies operating internationally.
The new Act will also establish specific cybersecurity obligations concerning important digital data and hosting and cloud providers, including duties to cooperate in responding to cyber threats. Existing sector-specific cybersecurity requirements, including those applicable to telecommunications and electricity supply, will remain in place.
By consolidating cross-sector cybersecurity requirements in a single piece of legislation, the Federal Council declared it aims to create a coherent framework covering products, data and digital infrastructure while facilitating future adaptation to technological and European regulatory developments. The DDPS is expected to submit the draft Cybersecurity Act to the Federal Council for consultation by June 2027.
The Swiss Federal Council has announced plans to create a new standalone Federal Cybersecurity Act, consolidating several ongoing legislative projects into a single regulatory framework. The Federal Department of Defence, Civil Protection and Sport (DDPS) has been instructed to prepare a consultation draft.
The new legislation aims combine three areas currently being addressed through separate legislative projects: the cyber resilience of products with digital elements, the protection of particularly important digital data, and the cybersecurity responsibilities of hosting and cloud service providers. In addition, the existing obligation for critical infrastructure operators to report cyberattacks, which has been in force under the Information Security Act since April 2025, will be transferred to the new Cybersecurity Act.
Among other measures, the planned legislation is expected to introduce binding cybersecurity requirements for manufacturers, importers and distributors of software and hardware products, together with a market surveillance framework and the possibility of prohibiting the distribution of insecure products. The regulatory approach will be aligned with the EU Cyber Resilience Act (CRA), with the aim of limiting additional compliance burdens for companies operating internationally.
The new Act will also establish specific cybersecurity obligations concerning important digital data and hosting and cloud providers, including duties to cooperate in responding to cyber threats. Existing sector-specific cybersecurity requirements, including those applicable to telecommunications and electricity supply, will remain in place.
By consolidating cross-sector cybersecurity requirements in a single piece of legislation, the Federal Council declared it aims to create a coherent framework covering products, data and digital infrastructure while facilitating future adaptation to technological and European regulatory developments. The DDPS is expected to submit the draft Cybersecurity Act to the Federal Council for consultation by June 2027.