Summary

  • The Federal Council has directed DDPS to draft a standalone Cybersecurity Act by June 2027, combining mandates on digital products, important data, and hosting/cloud providers.
  • The proposed act would take over the critical-infrastructure cyberattack reporting duty already in force, while the ISA would continue to cover information security inside federal authorities. No bill text or new duties have been published.

Switzerland has chosen a new legal container for cybersecurity rules that reach beyond the federal administration. On 25 September, the Federal Council instructed the Federal Department of Defence, Civil Protection and Sport (DDPS) to prepare a consultation draft for a Federal Act on Cybersecurity by June 2027. The government announced the decision on 28 September. That is a drafting mandate, not the start date of a new law: the proposed duties still have to appear in a bill, go through consultation and receive further decisions.

The decision joins three mandates that were originally expected to be implemented as amendments to the Information Security Act (ISA). Motion 24.3810 asks for legal foundations to close gaps in cybersecurity testing for digital products. Motion 23.3002 concerns protection for the most important digital data held by federal, cantonal and municipal authorities and by critical-infrastructure operators. Motion 25.3011 seeks a legal basis for the role of hosting and cloud providers in addressing cyberthreats and misuse of their services. The Federal Council describes these as complementary layers: products, data and digital infrastructure.

The government’s outline places obligations at each layer. Manufacturers, importers and distributors of software and hardware products would face binding cybersecurity requirements, with market surveillance and a power to prohibit insecure products. The draft would also establish requirements for protecting important digital data and duties for hosting and cloud providers, including cooperation and defence against cyberthreats. Those descriptions indicate the intended direction; they do not tell providers or manufacturers what to do today.

The bill must still define covered products, which data are “important,” and which providers fall within scope.

One part of the proposed transfer concerns an obligation that is already operational. Since 1 April 2025, covered authorities and critical-infrastructure operators have had to report specified cyberattacks to the National Cyber Security Centre (NCSC), initially within 24 hours of discovery and with up to 14 days to complete the report. The Federal Council says this duty will move from the ISA into the new act. The ISA itself is to remain the framework for information security within federal authorities. Existing sector-specific rules, including those governing telecommunications and electricity, are also meant to remain in force.

That arrangement matters because a single statute would sit alongside, rather than replace, sector rules. It could give Switzerland one legislative home for cross-cutting obligations that otherwise require amendments across several laws. But the boundaries will determine whether the result is coherent: the draft must show how a national standard applies to cantonal and municipal data, how product-market surveillance relates to sector regulators, and how duties for providers fit with the rules that already govern their customers and infrastructure.

The Federal Council says the planned framework should spare internationally active firms already subject to the EU Cyber Resilience Act (CRA) from additional Swiss compliance requirements. That is the government’s stated design objective before a bill exists. The announcement does not explain how equivalence, exemptions or supervision would work, or how a firm could challenge a conflicting requirement.

The date to watch is June 2027, when DDPS is tasked with delivering a consultation draft. Until that text appears, the announcement supports a change in legislative architecture, not a claim that new product bans or cloud-provider powers are already in force. The draft’s definitions, enforcement authority, remedies, costs and treatment of sector-specific rules will show how far the planned consolidation actually reaches.

Sources