Switzerland plans new Federal Cybersecurity Act

The Swiss Federal Council has announced plans to create a new standalone Federal Cybersecurity Act, consolidating several ongoing legislative projects into a single regulatory framework. The Federal Department of Defence, Civil Protection and Sport (DDPS) has been instructed to prepare a consultation draft.

The new legislation aims combine three areas currently being addressed through separate legislative projects: the cyber resilience of products with digital elements, the protection of particularly important digital data, and the cybersecurity responsibilities of hosting and cloud service providers. In addition, the existing obligation for critical infrastructure operators to report cyberattacks, which has been in force under the Information Security Act since April 2025, will be transferred to the new Cybersecurity Act.

Among other measures, the planned legislation is expected to introduce binding cybersecurity requirements for manufacturers, importers and distributors of software and hardware products, together with a market surveillance framework and the possibility of prohibiting the distribution of insecure products. The regulatory approach will be aligned with the EU Cyber Resilience Act (CRA), with the aim of limiting additional compliance burdens for companies operating internationally.

The new Act will also establish specific cybersecurity obligations concerning important digital data and hosting and cloud providers, including duties to cooperate in responding to cyber threats. Existing sector-specific cybersecurity requirements, including those applicable to telecommunications and electricity supply, will remain in place.

By consolidating cross-sector cybersecurity requirements in a single piece of legislation, the Federal Council declared it aims to create a coherent framework covering products, data and digital infrastructure while facilitating future adaptation to technological and European regulatory developments. The DDPS is expected to submit the draft Cybersecurity Act to the Federal Council for consultation by June 2027.

The Swiss Federal Council has announced plans to create a new standalone Federal Cybersecurity Act, consolidating several ongoing legislative projects into a single regulatory framework. The Federal Department of Defence, Civil Protection and Sport (DDPS) has been instructed to prepare a consultation draft.

The new legislation aims combine three areas currently being addressed through separate legislative projects: the cyber resilience of products with digital elements, the protection of particularly important digital data, and the cybersecurity responsibilities of hosting and cloud service providers. In addition, the existing obligation for critical infrastructure operators to report cyberattacks, which has been in force under the Information Security Act since April 2025, will be transferred to the new Cybersecurity Act.

Among other measures, the planned legislation is expected to introduce binding cybersecurity requirements for manufacturers, importers and distributors of software and hardware products, together with a market surveillance framework and the possibility of prohibiting the distribution of insecure products. The regulatory approach will be aligned with the EU Cyber Resilience Act (CRA), with the aim of limiting additional compliance burdens for companies operating internationally.

The new Act will also establish specific cybersecurity obligations concerning important digital data and hosting and cloud providers, including duties to cooperate in responding to cyber threats. Existing sector-specific cybersecurity requirements, including those applicable to telecommunications and electricity supply, will remain in place.

By consolidating cross-sector cybersecurity requirements in a single piece of legislation, the Federal Council declared it aims to create a coherent framework covering products, data and digital infrastructure while facilitating future adaptation to technological and European regulatory developments. The DDPS is expected to submit the draft Cybersecurity Act to the Federal Council for consultation by June 2027.

These are the upcoming dates for our Annual General Meetings:

Thursday, 18 March 2027

Thursday, 16 March 2028

If you are an ECS member, you are cordially invited to our Annual General Meetings! Each AGM is followed by discussion on current compliance topics and an networking Apèro.

*****

If you have registered  for an event and you can no longer make it, please cancel your registration from the dashboard if your user profile.