Switzerland’s ISA: New Cyberattack Reporting for Critical Infra
Switzerland's Information Security Act (ISA) now enforces mandatory cyberattack reporting for critical infrastructure operators, alongside existing data protection obligations under the revised Federal Act on Data Protection (FADP).
Written by the Technology Tutor editorial pipeline from 1 primary source. How we source →
Switzerland's Information Security Act (ISA), or Informationssicherheitsgesetz (ISG), has transitioned from a legislative concept to an active compliance regime. Mandatory reporting obligations for cyberattacks affecting critical infrastructure are now in effect as of April 1, 2025 Source.
This development creates a dual compliance landscape for businesses in or serving the Swiss market. The ISA focuses on the security of federal information and critical infrastructure protection, while the revised Federal Act on Data Protection (FADP), effective September 1, 2023, addresses personal data handling.
Immediate Actions for Businesses
Businesses need to undertake several crucial steps. This includes scoping their ISA exposure to determine if they qualify as critical infrastructure operators, federal authorities, or suppliers to these categories. A gap assessment mapping existing security controls against ISA’s technical and organizational measures (TOMs) and FADP guidance is also essential.
Furthermore, all vendor and cloud contracts require review to ensure data-processing agreements include audit rights, encryption commitments, subprocessor controls, and ISA-aligned breach-notification clauses. Businesses must also establish a 24-hour incident-response capability, especially for critical infrastructure operators who must notify the National Cyber Security Centre (NCSC) within that timeframe upon discovering a qualifying cyberattack Source. Documentation of policies, risk assessments, training records, and incident logs is critical for demonstrating compliance.
Understanding ISA's Scope and Definitions
The ISA applies to federal authorities, cantonal authorities (when accessing federal systems), and most significantly, operators of critical infrastructure. These include sectors like energy, transport, water supply, healthcare, finance, telecommunications, and digital infrastructure. Private businesses not directly operating critical infrastructure may still be affected indirectly through contracts with federal bodies or critical infrastructure operators Source.
Key definitions under ISA include:
- Operator of critical infrastructure: An entity whose systems are vital for public life, the economy, or public safety in Switzerland.
- Critical infrastructure: Infrastructure whose disruption would severely impact national security, the economy, or public welfare.
- Cyberattack (reportable): An attack threatening critical infrastructure functionality, leading to data manipulation or leaks, or remaining undetected for a long period, affecting availability, integrity, or confidentiality of critical systems/data Source.
ISA and FADP: Overlap and Compliance Priorities
While distinct, ISA and FADP share the common requirement for implementing appropriate technical and organizational measures (TOMs) to protect data and systems. Compliance teams should aim to build an integrated TOM framework that satisfies both regulatory frameworks simultaneously.
The ISA focuses on federal information and critical infrastructure protection, while FADP centers on personal data protection, including breach notifications to the Federal Data Protection and Information Commissioner (EDÖB) and, if required, to affected individuals. The interaction between these acts is evident in TOM scope, breach reporting triggers, and cross-border data transfer rules.
Differentiating Data Breaches and ISA Incidents
It's crucial to distinguish between an ISA-reportable cyberattack and an FADP data breach, as each has different reporting channels and timelines:
- ISA incident only: If a cyberattack disrupts critical infrastructure but no personal data is compromised, report to the NCSC within 24 hours.
- FADP breach only: If a database exposes personal data but the system isn't critical infrastructure, notify the EDÖB as soon as possible. Data subjects may also need notification.
- Dual-trigger event: A ransomware attack on critical infrastructure that encrypts systems and exfiltrates personal data requires notification to both the NCSC (within 24 hours under ISA) and the EDÖB (as soon as possible under FADP). Incident response plans must include parallel notification tracks Source.
Cross-border data transfer implications, especially with cloud services hosted outside Switzerland, must also be considered within ISA compliance programs.
Key takeaways
- 01Switzerland's ISA mandates 24-hour cyberattack reporting for critical infrastructure operators, effective April 1, 2025.
- 02Businesses must conduct gap assessments and implement robust Technical and Organizational Measures (TOMs) to meet both ISA and FADP requirements.
- 03Review all vendor and cloud contracts to ensure compliance with ISA-aligned security clauses and audit rights.
- 04Establish clear incident response plans to differentiate and manage dual reporting obligations to NCSC (ISA) and EDÖB (FADP).
- 05Comprehensive documentation of security policies, risk assessments, and incident logs is essential for demonstrating compliance.
Frequently asked
What is the primary impact of Switzerland's ISA on my business?+
If your business operates critical infrastructure or handles federal data in Switzerland, you are now legally required to establish specific cybersecurity measures and report cyberattacks within 24 hours to the NCSC.
Does the ISA replace existing data protection laws like FADP?+
No, the ISA does not replace FADP. Both acts are in force, and businesses must comply with both. The ISA focuses on critical infrastructure and federal data security, while FADP addresses personal data protection.
What should I do if my company uses cloud services or third-party vendors?+
You must review all vendor and cloud contracts to ensure they include audit rights, encryption guarantees, subprocessor controls, and breach-notification clauses that align with ISA requirements. Due diligence is crucial.
How quickly do I need to report a cyber incident?+
For critical infrastructure operators, a qualifying cyberattack must be reported to the National Cyber Security Centre (NCSC) within 24 hours. If personal data is involved, a separate notification to the EDÖB under FADP is also required 'as soon as possible'.
My business isn't 'critical infrastructure.' Do I still need to worry about ISA?+
While not directly subject to ISA reporting, you may be affected indirectly if you contract with federal bodies or critical infrastructure operators. Compliance with FADP's security requirements remains mandatory for all businesses handling personal data.
Sources
Every briefing is drafted from primary sources — official announcements, vendor blogs, and reputable industry reporting — then edited by our pipeline.
Filed today
All briefings →Policy & Regulation
Google, Apple Clash with EU Over AI Assistant Regulations
The European Commission is mandating Google and Apple open their mobile operating systems to third-party AI assistants, citing competition concerns, while tech giants warn of privacy risks.
Enterprise IT
Google Cloud Run Sandboxes: Free AI Code Execution Isolation
Google Cloud Run Sandboxes, now in public preview since July 10, 2026, allow developers to safely execute AI-generated code within existing Cloud Run services at no additional infrastructure cost.
Data & Analytics
Databricks & Snowflake 2026 Summits: Key AI & Data Platform Updates
Databricks and Snowflake unveiled new capabilities at their 2026 summits, focusing on advanced AI agents, enhanced semantic context layers, and real-time data processing for their respective data platforms.
More on Cybersecurity
See all →Jul 18, 2026
New macOS Malware, Supply Chain Attacks, and AI Vulnerability
New reporting highlights a macOS info-stealer, ongoing supply chain attacks impacting major companies like Lidl and Nihon Kotsu, and a critical AI vulnerability that allows arbitrary code execution via WhatsApp.
Jul 17, 2026
Today Show Intruder Incident Raises Physical Security Questions
A security breach at 30 Rockefeller Center saw an intruder approach "Today" show co-host Craig Melvin on air, highlighting potential vulnerabilities in physical security protocols at high-profile locations.
Jul 16, 2026
Email Attacks Drive Ransomware, MFA Fails 97% of the Time
Email-based attacks are now the leading cause of ransomware, overtaking exploits, with multifactor authentication (MFA) proving ineffective in preventing compromise in 97% of credential-based breaches where it was deployed.
Jul 7, 2026
AssuranceAmerica Data Breach Exposes 6.9 Million Driver's Licenses
Insurance provider AssuranceAmerica reported a data breach impacting 6.9 million individuals, exposing personal information and driver's license numbers, marking the largest such breach this year.
Free account
Want to go deeper?
Sign up free to unlock the full daily industry feed, save posts and articles to your library, and chat with the AI tutor about anything you read.