Two obligations, two recipients
- The Information Security Act (ISA): since 1 April 2025, operators of critical infrastructure report cyberattacks to the National Cyber Security Centre (NCSC).
- The Federal Act on Data Protection (FADP): any business that processes personal data reports to the Federal Data Protection and Information Commissioner (FDPIC) any breach that poses a high risk to the people concerned.
Both can apply to the same incident. A bank whose customer data leaks after an attack reports to the NCSC and to the FDPIC.
Who falls under the ISA
Art. 74b ISA lists twenty-one categories. Among them:
- federal, cantonal and communal authorities as well as universities;
- energy and drinking water supply, wastewater treatment and waste disposal;
- banks, insurers and financial market infrastructures;
- hospitals on a cantonal hospital list, medical laboratories and drug manufacturers;
- telecommunications providers, public transport and civil aviation;
- cloud computing and data centre providers with a registered office in Switzerland.
One category concerns software vendors directly: manufacturers of software used by critical infrastructure, where that software has remote maintenance access or controls technical processes (Art. 74b para. 1 let. u). The Cybersecurity Ordinance (CSO), on the other hand, exempts organisations whose failure would only have a limited impact. When in doubt, the NCSC provides information and can issue a ruling on whether the obligation applies (Art. 74a para. 2).
Which attacks and how fast
A cyberattack must be reported when it (Art. 74d):
- jeopardises the functioning of the infrastructure;
- has led to information being manipulated or leaked;
- went undetected for a long time, especially if it seems to prepare further attacks;
- involves blackmail, threats or coercion.
The report is due within 24 hours of discovery, through the NCSC’s Cyber Security Hub or with a form sent by email. Anything not yet known is added later: the NCSC allows 14 days to complete the report.
The fine is not automatic. The NCSC first sets a deadline and then issues a ruling. Intentionally failing to comply can cost up to CHF 100,000 (Art. 74g and 74h). This sanction has applied since 1 October 2025.
In the first half of 2026, the NCSC received 200 reports under this obligation and 27,128 voluntary reports.
The FADP concerns almost everyone
An SME with nothing to do with critical infrastructure still keeps customer, supplier or employee records. If an attack exposes them, Art. 24 FADP applies:
- the report to the FDPIC is made as soon as possible once the risk to the people concerned is likely to be high;
- it states at least the nature of the breach, its consequences and the measures taken or planned;
- the people concerned are informed when this is necessary for their protection or when the FDPIC requires it;
- a processor, for example the provider that hosts or develops your software, must notify you of any breach as soon as possible.
Reports are filed on the FDPIC’s DataBreach portal. With your consent, the FDPIC can pass the report on to the NCSC for analysis.
Preparing for the day it happens
- 01Find out whether your organisation falls under the ISA. That is not a question to ask during an attack.
- 02Decide who reports, with a deputy. Twenty-four hours go by fast over a weekend.
- 03Keep access and error logs. Without them, you cannot say what happened or what leaked.
- 04Check that your contract with your IT providers requires them to inform you without delay.
- 05Test your backups: a report is easier to fill in when you already know the data can be recovered.
What this means for software
Software that logs nothing leaves a business in the dark at the very moment the law asks it to describe the attack, its effects and the measures taken. When we build software that processes personal data, these logs are part of the scope from the quote onwards. To talk it through, get in touch.