CybersecuritySunday, July 19, 2026· Fresh today

Switzerland’s ISA: New Cyberattack Reporting for Critical Infra

Switzerland's Information Security Act (ISA) now enforces mandatory cyberattack reporting for critical infrastructure operators, alongside existing data protection obligations under the revised Federal Act on Data Protection (FADP).

Written by the Technology Tutor editorial pipeline from 1 primary source. How we source →

Switzerland's Information Security Act (ISA), or Informationssicherheitsgesetz (ISG), has transitioned from a legislative concept to an active compliance regime. Mandatory reporting obligations for cyberattacks affecting critical infrastructure are now in effect as of April 1, 2025 Source.

This development creates a dual compliance landscape for businesses in or serving the Swiss market. The ISA focuses on the security of federal information and critical infrastructure protection, while the revised Federal Act on Data Protection (FADP), effective September 1, 2023, addresses personal data handling.

Immediate Actions for Businesses

Businesses need to undertake several crucial steps. This includes scoping their ISA exposure to determine if they qualify as critical infrastructure operators, federal authorities, or suppliers to these categories. A gap assessment mapping existing security controls against ISA’s technical and organizational measures (TOMs) and FADP guidance is also essential.

Furthermore, all vendor and cloud contracts require review to ensure data-processing agreements include audit rights, encryption commitments, subprocessor controls, and ISA-aligned breach-notification clauses. Businesses must also establish a 24-hour incident-response capability, especially for critical infrastructure operators who must notify the National Cyber Security Centre (NCSC) within that timeframe upon discovering a qualifying cyberattack Source. Documentation of policies, risk assessments, training records, and incident logs is critical for demonstrating compliance.

Understanding ISA's Scope and Definitions

The ISA applies to federal authorities, cantonal authorities (when accessing federal systems), and most significantly, operators of critical infrastructure. These include sectors like energy, transport, water supply, healthcare, finance, telecommunications, and digital infrastructure. Private businesses not directly operating critical infrastructure may still be affected indirectly through contracts with federal bodies or critical infrastructure operators Source.

Key definitions under ISA include:

  • Operator of critical infrastructure: An entity whose systems are vital for public life, the economy, or public safety in Switzerland.
  • Critical infrastructure: Infrastructure whose disruption would severely impact national security, the economy, or public welfare.
  • Cyberattack (reportable): An attack threatening critical infrastructure functionality, leading to data manipulation or leaks, or remaining undetected for a long period, affecting availability, integrity, or confidentiality of critical systems/data Source.

ISA and FADP: Overlap and Compliance Priorities

While distinct, ISA and FADP share the common requirement for implementing appropriate technical and organizational measures (TOMs) to protect data and systems. Compliance teams should aim to build an integrated TOM framework that satisfies both regulatory frameworks simultaneously.

The ISA focuses on federal information and critical infrastructure protection, while FADP centers on personal data protection, including breach notifications to the Federal Data Protection and Information Commissioner (EDÖB) and, if required, to affected individuals. The interaction between these acts is evident in TOM scope, breach reporting triggers, and cross-border data transfer rules.

Differentiating Data Breaches and ISA Incidents

It's crucial to distinguish between an ISA-reportable cyberattack and an FADP data breach, as each has different reporting channels and timelines:

  • ISA incident only: If a cyberattack disrupts critical infrastructure but no personal data is compromised, report to the NCSC within 24 hours.
  • FADP breach only: If a database exposes personal data but the system isn't critical infrastructure, notify the EDÖB as soon as possible. Data subjects may also need notification.
  • Dual-trigger event: A ransomware attack on critical infrastructure that encrypts systems and exfiltrates personal data requires notification to both the NCSC (within 24 hours under ISA) and the EDÖB (as soon as possible under FADP). Incident response plans must include parallel notification tracks Source.

Cross-border data transfer implications, especially with cloud services hosted outside Switzerland, must also be considered within ISA compliance programs.

Key takeaways

  • 01Switzerland's ISA mandates 24-hour cyberattack reporting for critical infrastructure operators, effective April 1, 2025.
  • 02Businesses must conduct gap assessments and implement robust Technical and Organizational Measures (TOMs) to meet both ISA and FADP requirements.
  • 03Review all vendor and cloud contracts to ensure compliance with ISA-aligned security clauses and audit rights.
  • 04Establish clear incident response plans to differentiate and manage dual reporting obligations to NCSC (ISA) and EDÖB (FADP).
  • 05Comprehensive documentation of security policies, risk assessments, and incident logs is essential for demonstrating compliance.

Frequently asked

What is the primary impact of Switzerland's ISA on my business?+

If your business operates critical infrastructure or handles federal data in Switzerland, you are now legally required to establish specific cybersecurity measures and report cyberattacks within 24 hours to the NCSC.

Does the ISA replace existing data protection laws like FADP?+

No, the ISA does not replace FADP. Both acts are in force, and businesses must comply with both. The ISA focuses on critical infrastructure and federal data security, while FADP addresses personal data protection.

What should I do if my company uses cloud services or third-party vendors?+

You must review all vendor and cloud contracts to ensure they include audit rights, encryption guarantees, subprocessor controls, and breach-notification clauses that align with ISA requirements. Due diligence is crucial.

How quickly do I need to report a cyber incident?+

For critical infrastructure operators, a qualifying cyberattack must be reported to the National Cyber Security Centre (NCSC) within 24 hours. If personal data is involved, a separate notification to the EDÖB under FADP is also required 'as soon as possible'.

My business isn't 'critical infrastructure.' Do I still need to worry about ISA?+

While not directly subject to ISA reporting, you may be affected indirectly if you contract with federal bodies or critical infrastructure operators. Compliance with FADP's security requirements remains mandatory for all businesses handling personal data.

Sources

Every briefing is drafted from primary sources — official announcements, vendor blogs, and reputable industry reporting — then edited by our pipeline.

#switzerland#isa#cybersecurity#critical infrastructure#fadp#compliance
See all →

Free account

Want to go deeper?

Sign up free to unlock the full daily industry feed, save posts and articles to your library, and chat with the AI tutor about anything you read.