US incident-response planning is calibrated to clocks that leave room for judgment. CIRCIA's 72-hour duty for critical infrastructure will not bind until CISA finalizes its implementing rule, the SEC's four-business-day window opens only once a materiality determination has been made, and HIPAA's breach-notification rule runs to sixty days.1CIRCIA, 6 U.S.C. §§ 681–681g; proposed rule 89 Fed. Reg. 23644 (4 Apr 2024); no final rule as of publication. SEC Item 1.05 Form 8-K: four business days from the materiality determination. Switzerland has been running a harder clock since 1 April 2025: operators of critical infrastructures must report cyberattacks to the Bundesamt für Cybersicherheit (BACS) within 24 hours, counted not from a legal assessment but from discovery of the attack. The duty sits in the Informationssicherheitsgesetz (ISG), a statute most US legal departments have never opened, and its catalogue of covered operators reads nothing like the sector labels the American term suggests.
1. Who Counts as a Critical-Infrastructure Operator Under the ISG
The ISG does define critical infrastructure in its own terms, but the reporting duty does not run on that definition. Art. 74b(1) ISG enumerates twenty-one categories of authorities and organizations, lettered a–u, and membership follows from Swiss regulatory anchors rather than from what a group calls itself.2Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG) vom 18. Dezember 2020 (SR 128), Art. 74a–74h; reporting duty in force since 1 April 2025. Health institutions on a cantonal hospital list are covered, as are medical laboratories holding an epidemics-law authorization, companies authorized to manufacture, place on the market, or import medicinal products, registered providers of telecom and postal services, banks and insurers under Swiss financial-market supervision, energy suppliers and traders, transport concessionaires, and the federal, cantonal, and communal authorities themselves. For a US general counsel, the instinctive frame is CISA's sixteen critical-infrastructure sectors and the covered-entity logic of the pending CIRCIA rule. The Swiss catalogue behaves differently: whether a group is inside it is largely a function of which Swiss licenses, registrations, and concessions its subsidiaries happen to hold, information that lives in local regulatory files rather than in any parent-level inventory.
Two categories reach directly into the technology industry. Letter t covers providers and operators of cloud computing, search engines, digital security and trust services, and data centers, provided the provider has its seat in Switzerland; the Swiss subsidiary operating a US group's Zurich data center is a natural candidate. Letter u covers manufacturers of hardware or software whose products are used by critical infrastructures, where the product has remote-maintenance access or is deployed to control and monitor operational systems and processes or to ensure public safety. Letter u carries no Swiss-seat condition. How far it reaches toward a vendor incorporated in Delaware with no Swiss establishment is a question the statute does not answer, and the answer a group assumes will determine whether its product organization ever hears about the duty at all.
Whether a US group sits inside the Swiss catalogue is not decided by how the group describes itself; it is decided by licenses, registrations, seats, and product functions, several of which no parent-level inventory tracks.
The catalogue's edges are worked out in two places. The statute itself carves out attacks that affect exclusively activities falling outside the listed categories, and it extends the duty to cyberattacks that have effects in Switzerland even where the affected IT resources are located abroad, a rule with consequences for groups that run shared services from the United States: an intrusion into a US-hosted platform can become reportable in Switzerland because a Swiss plant or portfolio depends on it. The Cybersicherheitsverordnung (CSV), in force since 1 April 2025, then narrows the population through exemptions.3Verordnung über die Cybersicherheit (Cybersicherheitsverordnung, CSV) vom 7. März 2025 (SR 128.51), Art. 12: exemptions from the reporting duty. Higher-education institutions with fewer than 2,000 students fall out; medical laboratories, medicinal-product companies, postal providers, and suppliers of essential everyday goods fall out where they employ fewer than 50 persons in the affected area and their annual turnover or balance-sheet total in that area does not exceed CHF 10 million; letter t providers fall out where they render their services to third parties entirely without remuneration; several energy and transport categories carry technical thresholds of their own. What the ordinance conspicuously does not contain is a small-company exemption for letter u manufacturers. A twelve-person Swiss software house whose product monitors operational processes for utilities is, on the text, inside.
2. The 24-Hour Clock: Trigger, Content, and the BACS Channel
What starts the clock is a list, not a materiality standard. Art. 74d ISG makes a cyberattack reportable if any of four gates opens: the attack jeopardizes the functioning of the affected critical infrastructure; it has led to a manipulation or leak of information; it remained undetected for an extended period, in particular where there are indications that it was carried out to prepare further attacks; or it is combined with blackmail, threats, or coercion.4ISG (n 2), Art. 74d–74f; CSV (n 3), Art. 14, 15 and 16: reportable attacks, required content, 24-hour deadline from discovery, secure transmission system, 14-day completion period. The gates are alternatives, and they are operational rather than legal in character. The second is backward-looking and carries no severity floor: a confirmed leak of business-relevant information triggers the duty without any of the harm-threshold analysis a US lawyer would run under a materiality standard. The fourth captures ransomware as such, extortion being its business model. The instinct to ask how bad an incident has to be, trained by Item 1.05 of Form 8-K and by state breach statutes, has no purchase here.
The mechanics compound the compression. The report must be filed within 24 hours of discovery of the attack, and it must identify the reporting organization and describe the nature and execution of the attack, its effects, the measures taken and, so far as known, the further steps planned; the ordinance adds further items, among them the date and time of detection and of the attack itself, information on the attacker, and whether a criminal complaint has been filed. The BACS makes a secure transmission system available, in practice a form on its Cyber Security Hub; organizations without access to that platform report instead by emailed form, and the ordinance then requires the report to carry the entity's name and address and the reporting person's contact details on top of the standard content. Where not everything is known within 24 hours, the BACS grants fourteen days to complete the report. That window appears to defuse the deadline, and it does defuse the content problem. It does not touch the detection problem. The clock runs from discovery (Entdeckung), and the statute does not say whose discovery counts inside a multinational: the group security operations center in Denver that triages the alert at 03:00 Swiss time, the managed security provider contractually obliged to no one but the parent, or the Swiss licensee that will sign the report. In practice, the 24 hours are spent not on drafting but on escalation.
3. The ISG Against NIS2 and the CER Directive
Switzerland is not an EU Member State, and neither NIS2 nor the CER Directive applies to it. A US group that files Switzerland under Europe and Europe under NIS2 has made two mistakes at once, and the second is subtler than the first. NIS2 stages its reporting: an early warning to the CSIRT or competent authority without undue delay and in any event within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report no later than one month after that notification.5Directive (EU) 2022/2555 (NIS2), Art. 23(3): significant-incident definition; Art. 23(4): 24-hour early warning, 72-hour incident notification, one-month final report. Its trigger is a defined significant incident, one that has caused or is capable of causing severe operational disruption or financial loss, or that has affected or is capable of affecting other persons through considerable damage. The Swiss regime compresses all of this into a single 24-hour report against a list of operational gates, with completion within the fourteen days the BACS grants where information is missing. An organization that simply reuses its NIS2 early-warning template at hour 24 files a report the Swiss requirements treat as incomplete; an organization that waits for its NIS2-style 72-hour notification is two days late.
The CER Directive adds a further layer for physical resilience: critical entities identified under it must notify incidents without undue delay, with an initial notification within 24 hours of becoming aware unless operationally unable to submit one, followed where relevant by a detailed report within a month; Member States had until 17 July 2026 to complete the identification of critical entities, a deadline that was still open at publication.6Directive (EU) 2022/2557 (CER Directive), Art. 15(1): initial notification within 24 hours of becoming aware; detailed report within one month where relevant. The architectures do not align in scope either. NIS2 works through sector annexes and a size-cap rule, capturing essential and important entities by classification; the ISG works through its enumerated catalogue and the CSV's exemptions. A group can be an essential entity in Germany, a critical entity under the CER Directive in France, and a letter t operator in Switzerland, for the same activity, with three different reporting formats, deadlines, and authorities, and with NIS2 requiring Member States to provide for fines of up to at least EUR 10 million or 2 percent of worldwide turnover for essential entities, whichever is higher.
The coordination questions multiply faster than the regimes. Whose awareness starts which clock when the first detection sits with a shared group SOC that serves the German, French, and Swiss entities alike? Can a single incident narrative be drafted at hour 24 that satisfies the Swiss content requirements without prejudging the significance assessment NIS2 requires at hour 72, and without committing the group to facts a later forensic image will contradict? Which of the parallel reports may be shared with which authority, when the confidentiality and onward-transmission rules attached to each channel differ? For connected-device manufacturers the same event can additionally engage GDPR, the Swiss Datenschutzgesetz (DSG), and contractual notification channels, a coordination problem examined in Insight 19. None of these questions has a template answer, because the regimes were not drafted with each other in mind.
4. Sanctions Since October 2025 and the Compliance Build
The sanction architecture is easy to misread from a US vantage point, in both directions. There is no automatic fine for a late or missing report. Art. 74g ISG obliges the BACS, where there are indications that the duty was breached, first to inform the organization and set it a reasonable deadline to comply; only if that deadline lapses does the BACS issue a formal order (Verfügung), with a new deadline and an express reference to the penal provision. The fine, up to CHF 100,000, attaches under Art. 74h ISG to willful non-compliance with that order once final, or with the decision of an appellate authority. Read against NIS2's turnover-based ceilings, this looks almost gentle. The gentleness is structural, not practical: the order mechanism converts a missed 24-hour window into a documented, escalating correspondence with a federal authority about a compliance failure, conducted while the underlying incident is still being remediated.
The personal dimension is the part US boards hear last. For violations committed in a business, Art. 74h(2) ISG applies Art. 6 VStrR, the attribution rule under which the fine lands on the natural persons who committed the act and can extend to management that failed in its duty to prevent it.7Bundesgesetz über das Verwaltungsstrafrecht (VStrR) vom 22. März 1974 (SR 313.0), Art. 6: attribution of an administrative-penal fine within a business. The organization itself pays only in the narrow case where the fine at stake does not exceed CHF 20,000 and identifying the responsible individuals would require disproportionate investigative effort. Prosecution and judgment belong to the cantons, which means the counterparty in a contested case is a cantonal prosecution authority, not the BACS. For a US parent whose officers sit on the Swiss subsidiary's board, the exposure this creates is personal, foreign, and penal in character, a combination that standard D&O programs handle unevenly and that no indemnification clause can simply absorb.
Practice since the duty took effect says the regime is live. In its first six months the BACS received 164 mandatory reports, with distributed-denial-of-service attacks the most frequently reported category and finance the most represented sector; by the end of 2025 the count had reached 222.8BACS, 'Sechs Monate Meldepflicht für Cyberangriffe auf kritische Infrastrukturen' (Medienmitteilung, 29 September 2025): 164 mandatory reports in the first six months. BACS, Jahresbericht 2025 (February 2026): 222 mandatory reports to the end of 2025. Sanctions have applied only since 1 October 2025, after a deliberate six-month running-in period, and no enforcement practice under Art. 74g and 74h ISG had become publicly visible as of publication. The asymmetry with the United States is the strategic point: as of publication in June 2026, CISA's CIRCIA rule remained unfinalized, the statutory deadline for the final rule, eighteen months after the April 2024 proposed rule, having lapsed in October 2025 and the agency's May 2026 target having passed without a published final rule, while the SEC clock turns on materiality rather than discovery. For many US-headquartered groups, the Swiss duty is therefore the first legally binding 24-hour cyber clock anywhere in the organization; for groups already running NIS2 early warnings in the EU, it is the first that demands a substantive report at that hour. The build it quietly presupposes, detection that surfaces attacks within a day, escalation that reaches the Swiss entity's counsel in hours, vendor contracts under which a provider's detection actually reaches the operator, is a build most groups have scoped for headquarters, not for a subsidiary in Basel.
5. Strategic Considerations
The questions that remain are the ones only a specific group can answer. The first is inventory: which entities in the structure hold which Swiss licenses, registrations, concessions, or seats, and which products in the portfolio have remote-maintenance access to, or control and monitoring functions inside, a customer that is itself a Swiss critical infrastructure? For letter u the analysis runs on facts about deployments at customer sites, facts a vendor may not systematically collect and a parent almost never sees. The second is discovery: where in the group's actual detection architecture does knowledge of an attack first arise, whose knowledge is attributed to the Swiss operator, and what has to be true of the escalation path for a report to be filed within 24 hours of that moment rather than within 24 hours of the moment Basel found out? The third is the interlock: whether one incident narrative can serve the BACS report at hour 24, the NIS2 notifications where EU entities are affected, the data-protection notifications, and a possible Item 1.05 disclosure, without any of them prejudicing the others, and who in the group decides the sequencing when the answers conflict. The fourth is the perimeter the statute leaves open: whether and how the duty reaches a US vendor with no Swiss establishment whose software sits inside Swiss critical infrastructure, an issue no published authority had resolved as of publication, and one where the commercially exposed party may turn out to be the Swiss customer through whose systems the attack propagates. The fifth is governance: whether the personal reach of the sanction regime is reflected anywhere in board mandates, indemnities, and insurance for the individuals who sit between the US parent and the Swiss subsidiary. These questions require analysis tailored to the specific group structure, product set, and commercial context.