DDPS - Federal Department of Defence, Civil Protection and Sports of the Swiss Confederation

09/28/2026 | Press release | Distributed by Public on 09/28/2026 01:49

Federal Council plans to introduce new Cybersecurity Act

Press releasePublished on 28 September 2026

Federal Council plans to introduce new Cybersecurity Act

Bern, 25.09.2026 - With a view to strengthening national cybersecurity, at its 25 September meeting the Federal Council instructed the Federal Department of Defence, Civil Protection and Sport (DDPS) to draw up a consultation draft for a Federal Act on Cybersecurity by June 2027. The new, standalone Act is intended to implement three parliamentary motions in a single piece of legislation.

The National Cyber Security Centre (NCSC) is working on three legislative projects commissioned by Parliament: the cyber resilience of products containing digital elements (Mo. 24.3810), the protection of the most important digital data (Mo. 23.3002) and the role of hosting and cloud providers in cybersecurity (Mo. 25.3011). The three projects relate to complementary regulatory levels - products, data and digital infrastructure - and were originally intended to be implemented through amendments to the Information Security Act (ISA).

To ensure a consistent regulatory framework for cybersecurity involving third parties, the Federal Council is now combining the three projects into a single bill. To this end, a standalone Federal Act on Cybersecurity (Cybersecurity Act (CySA)) is to be introduced. The obligation to report cyberattacks on critical infrastructure, which has been in force since April 2025, will also be transferred from the ISA. The ISA will continue to govern information security within the federal authorities.

Specific obligations regarding the protection of digital data

The proposed Cybersecurity Act is intended to set out binding requirements for manufacturers, importers and distributors of software and hardware products, including provisions for market surveillance and a ban on the sale of products that are not secure. Modelled on the EU's Cyber Resilience Act (CRA), the legislation is designed to keep the administrative burden on businesses to a minimum. In addition, the Act sets out specific cybersecurity obligations for the protection of important digital data, as well as for hosting and cloud service providers, such as the obligations to cooperate and to defend against cyberthreats.

Existing sector-specific regulations, such as those in the Telecommunications Act, the Electricity Supply Ordinance and the Telecommunications Installations Ordinance, remain in force; the Cybersecurity Act supplements them by introducing obligations regarding cybersecurity as a related responsibility. Future technological or European developments can thus be incorporated in a single piece of legislation, without the need to amend several laws at the same time. Furthermore, specific issues, such as open-source software, can be covered more effectively.

Consolidation reduces the burden on businesses and public authorities

A standalone Cybersecurity Act brings together cross-cutting obligations in a single piece of legislation. This harmonised Swiss legislation will be of particular benefit to internationally active companies that are already subject to the EU's CRA, as it ensures that no additional compliance requirements will arise.

The DDPS has been tasked with drawing up a consultation draft by June 2027 and submitting it to the Federal Council for a decision.

DDPS - Federal Department of Defence, Civil Protection and Sports of the Swiss Confederation published this content on September 28, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 28, 2026 at 07:50 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]