INSIGHT // 58 Critical Compliance

Switzerland's 24-Hour Cyberattack-Reporting Duty: The ISG Obligation for US Operators of Swiss Critical Infrastructure

Abstract: Since 1 April 2025, operators of critical infrastructures in Switzerland must report cyberattacks to the BACS within 24 hours of discovery; since 1 October 2025, defying a BACS order in the aftermath can cost up to CHF 100,000. The statutory catalogue reaches deeper into US-headquartered groups than its label suggests, and incident-response architectures built around CIRCIA and SEC clocks do not map onto it.
Plain Language Summary

This article examines Switzerland's cyberattack-reporting duty under the Informationssicherheitsgesetz (ISG), the Swiss federal information-security act. Since 1 April 2025, operators of critical infrastructures must report cyberattacks to the Bundesamt für Cybersicherheit (BACS), the federal cybersecurity office, within 24 hours of discovering them. The covered operators are defined by a statutory list. The list includes hospitals, energy and telecom companies, banks, licensed pharmaceutical companies, data centers, and certain makers of hardware and software, among them Swiss subsidiaries of US groups. The article compares the Swiss duty with the EU's NIS2 and CER Directives and with US federal reporting rules, and describes the fines that apply since 1 October 2025. It does not assess any specific company's obligations.

Table of Contents
  1. Who Counts as a Critical-Infrastructure Operator Under the ISG
  2. The 24-Hour Clock: Trigger, Content, and the BACS Channel
  3. The ISG Against NIS2 and the CER Directive
  4. Sanctions Since October 2025 and the Compliance Build
  5. Strategic Considerations

US incident-response planning is calibrated to clocks that leave room for judgment. CIRCIA's 72-hour duty for critical infrastructure will not bind until CISA finalizes its implementing rule, the SEC's four-business-day window opens only once a materiality determination has been made, and HIPAA's breach-notification rule runs to sixty days.1CIRCIA, 6 U.S.C. §§ 681–681g; proposed rule 89 Fed. Reg. 23644 (4 Apr 2024); no final rule as of publication. SEC Item 1.05 Form 8-K: four business days from the materiality determination. Switzerland has been running a harder clock since 1 April 2025: operators of critical infrastructures must report cyberattacks to the Bundesamt für Cybersicherheit (BACS) within 24 hours, counted not from a legal assessment but from discovery of the attack. The duty sits in the Informationssicherheitsgesetz (ISG), a statute most US legal departments have never opened, and its catalogue of covered operators reads nothing like the sector labels the American term suggests.

1. Who Counts as a Critical-Infrastructure Operator Under the ISG

The ISG does define critical infrastructure in its own terms, but the reporting duty does not run on that definition. Art. 74b(1) ISG enumerates twenty-one categories of authorities and organizations, lettered a–u, and membership follows from Swiss regulatory anchors rather than from what a group calls itself.2Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG) vom 18. Dezember 2020 (SR 128), Art. 74a–74h; reporting duty in force since 1 April 2025. Health institutions on a cantonal hospital list are covered, as are medical laboratories holding an epidemics-law authorization, companies authorized to manufacture, place on the market, or import medicinal products, registered providers of telecom and postal services, banks and insurers under Swiss financial-market supervision, energy suppliers and traders, transport concessionaires, and the federal, cantonal, and communal authorities themselves. For a US general counsel, the instinctive frame is CISA's sixteen critical-infrastructure sectors and the covered-entity logic of the pending CIRCIA rule. The Swiss catalogue behaves differently: whether a group is inside it is largely a function of which Swiss licenses, registrations, and concessions its subsidiaries happen to hold, information that lives in local regulatory files rather than in any parent-level inventory.

Two categories reach directly into the technology industry. Letter t covers providers and operators of cloud computing, search engines, digital security and trust services, and data centers, provided the provider has its seat in Switzerland; the Swiss subsidiary operating a US group's Zurich data center is a natural candidate. Letter u covers manufacturers of hardware or software whose products are used by critical infrastructures, where the product has remote-maintenance access or is deployed to control and monitor operational systems and processes or to ensure public safety. Letter u carries no Swiss-seat condition. How far it reaches toward a vendor incorporated in Delaware with no Swiss establishment is a question the statute does not answer, and the answer a group assumes will determine whether its product organization ever hears about the duty at all.

Whether a US group sits inside the Swiss catalogue is not decided by how the group describes itself; it is decided by licenses, registrations, seats, and product functions, several of which no parent-level inventory tracks.

The catalogue's edges are worked out in two places. The statute itself carves out attacks that affect exclusively activities falling outside the listed categories, and it extends the duty to cyberattacks that have effects in Switzerland even where the affected IT resources are located abroad, a rule with consequences for groups that run shared services from the United States: an intrusion into a US-hosted platform can become reportable in Switzerland because a Swiss plant or portfolio depends on it. The Cybersicherheitsverordnung (CSV), in force since 1 April 2025, then narrows the population through exemptions.3Verordnung über die Cybersicherheit (Cybersicherheitsverordnung, CSV) vom 7. März 2025 (SR 128.51), Art. 12: exemptions from the reporting duty. Higher-education institutions with fewer than 2,000 students fall out; medical laboratories, medicinal-product companies, postal providers, and suppliers of essential everyday goods fall out where they employ fewer than 50 persons in the affected area and their annual turnover or balance-sheet total in that area does not exceed CHF 10 million; letter t providers fall out where they render their services to third parties entirely without remuneration; several energy and transport categories carry technical thresholds of their own. What the ordinance conspicuously does not contain is a small-company exemption for letter u manufacturers. A twelve-person Swiss software house whose product monitors operational processes for utilities is, on the text, inside.

2. The 24-Hour Clock: Trigger, Content, and the BACS Channel

What starts the clock is a list, not a materiality standard. Art. 74d ISG makes a cyberattack reportable if any of four gates opens: the attack jeopardizes the functioning of the affected critical infrastructure; it has led to a manipulation or leak of information; it remained undetected for an extended period, in particular where there are indications that it was carried out to prepare further attacks; or it is combined with blackmail, threats, or coercion.4ISG (n 2), Art. 74d–74f; CSV (n 3), Art. 14, 15 and 16: reportable attacks, required content, 24-hour deadline from discovery, secure transmission system, 14-day completion period. The gates are alternatives, and they are operational rather than legal in character. The second is backward-looking and carries no severity floor: a confirmed leak of business-relevant information triggers the duty without any of the harm-threshold analysis a US lawyer would run under a materiality standard. The fourth captures ransomware as such, extortion being its business model. The instinct to ask how bad an incident has to be, trained by Item 1.05 of Form 8-K and by state breach statutes, has no purchase here.

The mechanics compound the compression. The report must be filed within 24 hours of discovery of the attack, and it must identify the reporting organization and describe the nature and execution of the attack, its effects, the measures taken and, so far as known, the further steps planned; the ordinance adds further items, among them the date and time of detection and of the attack itself, information on the attacker, and whether a criminal complaint has been filed. The BACS makes a secure transmission system available, in practice a form on its Cyber Security Hub; organizations without access to that platform report instead by emailed form, and the ordinance then requires the report to carry the entity's name and address and the reporting person's contact details on top of the standard content. Where not everything is known within 24 hours, the BACS grants fourteen days to complete the report. That window appears to defuse the deadline, and it does defuse the content problem. It does not touch the detection problem. The clock runs from discovery (Entdeckung), and the statute does not say whose discovery counts inside a multinational: the group security operations center in Denver that triages the alert at 03:00 Swiss time, the managed security provider contractually obliged to no one but the parent, or the Swiss licensee that will sign the report. In practice, the 24 hours are spent not on drafting but on escalation.

3. The ISG Against NIS2 and the CER Directive

Switzerland is not an EU Member State, and neither NIS2 nor the CER Directive applies to it. A US group that files Switzerland under Europe and Europe under NIS2 has made two mistakes at once, and the second is subtler than the first. NIS2 stages its reporting: an early warning to the CSIRT or competent authority without undue delay and in any event within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report no later than one month after that notification.5Directive (EU) 2022/2555 (NIS2), Art. 23(3): significant-incident definition; Art. 23(4): 24-hour early warning, 72-hour incident notification, one-month final report. Its trigger is a defined significant incident, one that has caused or is capable of causing severe operational disruption or financial loss, or that has affected or is capable of affecting other persons through considerable damage. The Swiss regime compresses all of this into a single 24-hour report against a list of operational gates, with completion within the fourteen days the BACS grants where information is missing. An organization that simply reuses its NIS2 early-warning template at hour 24 files a report the Swiss requirements treat as incomplete; an organization that waits for its NIS2-style 72-hour notification is two days late.

The CER Directive adds a further layer for physical resilience: critical entities identified under it must notify incidents without undue delay, with an initial notification within 24 hours of becoming aware unless operationally unable to submit one, followed where relevant by a detailed report within a month; Member States had until 17 July 2026 to complete the identification of critical entities, a deadline that was still open at publication.6Directive (EU) 2022/2557 (CER Directive), Art. 15(1): initial notification within 24 hours of becoming aware; detailed report within one month where relevant. The architectures do not align in scope either. NIS2 works through sector annexes and a size-cap rule, capturing essential and important entities by classification; the ISG works through its enumerated catalogue and the CSV's exemptions. A group can be an essential entity in Germany, a critical entity under the CER Directive in France, and a letter t operator in Switzerland, for the same activity, with three different reporting formats, deadlines, and authorities, and with NIS2 requiring Member States to provide for fines of up to at least EUR 10 million or 2 percent of worldwide turnover for essential entities, whichever is higher.

The coordination questions multiply faster than the regimes. Whose awareness starts which clock when the first detection sits with a shared group SOC that serves the German, French, and Swiss entities alike? Can a single incident narrative be drafted at hour 24 that satisfies the Swiss content requirements without prejudging the significance assessment NIS2 requires at hour 72, and without committing the group to facts a later forensic image will contradict? Which of the parallel reports may be shared with which authority, when the confidentiality and onward-transmission rules attached to each channel differ? For connected-device manufacturers the same event can additionally engage GDPR, the Swiss Datenschutzgesetz (DSG), and contractual notification channels, a coordination problem examined in Insight 19. None of these questions has a template answer, because the regimes were not drafted with each other in mind.

4. Sanctions Since October 2025 and the Compliance Build

The sanction architecture is easy to misread from a US vantage point, in both directions. There is no automatic fine for a late or missing report. Art. 74g ISG obliges the BACS, where there are indications that the duty was breached, first to inform the organization and set it a reasonable deadline to comply; only if that deadline lapses does the BACS issue a formal order (Verfügung), with a new deadline and an express reference to the penal provision. The fine, up to CHF 100,000, attaches under Art. 74h ISG to willful non-compliance with that order once final, or with the decision of an appellate authority. Read against NIS2's turnover-based ceilings, this looks almost gentle. The gentleness is structural, not practical: the order mechanism converts a missed 24-hour window into a documented, escalating correspondence with a federal authority about a compliance failure, conducted while the underlying incident is still being remediated.

The personal dimension is the part US boards hear last. For violations committed in a business, Art. 74h(2) ISG applies Art. 6 VStrR, the attribution rule under which the fine lands on the natural persons who committed the act and can extend to management that failed in its duty to prevent it.7Bundesgesetz über das Verwaltungsstrafrecht (VStrR) vom 22. März 1974 (SR 313.0), Art. 6: attribution of an administrative-penal fine within a business. The organization itself pays only in the narrow case where the fine at stake does not exceed CHF 20,000 and identifying the responsible individuals would require disproportionate investigative effort. Prosecution and judgment belong to the cantons, which means the counterparty in a contested case is a cantonal prosecution authority, not the BACS. For a US parent whose officers sit on the Swiss subsidiary's board, the exposure this creates is personal, foreign, and penal in character, a combination that standard D&O programs handle unevenly and that no indemnification clause can simply absorb.

Practice since the duty took effect says the regime is live. In its first six months the BACS received 164 mandatory reports, with distributed-denial-of-service attacks the most frequently reported category and finance the most represented sector; by the end of 2025 the count had reached 222.8BACS, 'Sechs Monate Meldepflicht für Cyberangriffe auf kritische Infrastrukturen' (Medienmitteilung, 29 September 2025): 164 mandatory reports in the first six months. BACS, Jahresbericht 2025 (February 2026): 222 mandatory reports to the end of 2025. Sanctions have applied only since 1 October 2025, after a deliberate six-month running-in period, and no enforcement practice under Art. 74g and 74h ISG had become publicly visible as of publication. The asymmetry with the United States is the strategic point: as of publication in June 2026, CISA's CIRCIA rule remained unfinalized, the statutory deadline for the final rule, eighteen months after the April 2024 proposed rule, having lapsed in October 2025 and the agency's May 2026 target having passed without a published final rule, while the SEC clock turns on materiality rather than discovery. For many US-headquartered groups, the Swiss duty is therefore the first legally binding 24-hour cyber clock anywhere in the organization; for groups already running NIS2 early warnings in the EU, it is the first that demands a substantive report at that hour. The build it quietly presupposes, detection that surfaces attacks within a day, escalation that reaches the Swiss entity's counsel in hours, vendor contracts under which a provider's detection actually reaches the operator, is a build most groups have scoped for headquarters, not for a subsidiary in Basel.

5. Strategic Considerations

The questions that remain are the ones only a specific group can answer. The first is inventory: which entities in the structure hold which Swiss licenses, registrations, concessions, or seats, and which products in the portfolio have remote-maintenance access to, or control and monitoring functions inside, a customer that is itself a Swiss critical infrastructure? For letter u the analysis runs on facts about deployments at customer sites, facts a vendor may not systematically collect and a parent almost never sees. The second is discovery: where in the group's actual detection architecture does knowledge of an attack first arise, whose knowledge is attributed to the Swiss operator, and what has to be true of the escalation path for a report to be filed within 24 hours of that moment rather than within 24 hours of the moment Basel found out? The third is the interlock: whether one incident narrative can serve the BACS report at hour 24, the NIS2 notifications where EU entities are affected, the data-protection notifications, and a possible Item 1.05 disclosure, without any of them prejudicing the others, and who in the group decides the sequencing when the answers conflict. The fourth is the perimeter the statute leaves open: whether and how the duty reaches a US vendor with no Swiss establishment whose software sits inside Swiss critical infrastructure, an issue no published authority had resolved as of publication, and one where the commercially exposed party may turn out to be the Swiss customer through whose systems the attack propagates. The fifth is governance: whether the personal reach of the sanction regime is reflected anywhere in board mandates, indemnities, and insurance for the individuals who sit between the US parent and the Swiss subsidiary. These questions require analysis tailored to the specific group structure, product set, and commercial context.

REFERENCES

01
Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), 6 U.S.C. §§ 681–681g; Cybersecurity and Infrastructure Security Agency, 'Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements' (proposed rule), 89 Fed. Reg. 23644 (4 April 2024). The 72-hour covered-incident and 24-hour ransom-payment duties bind only once the final rule takes effect; the statutory deadline for final action lapsed in October 2025, CISA communicated in September 2025 that it targeted final action by May 2026, and no final rule had been published as of publication. On the US disclosure side: SEC, 'Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure', Release Nos. 33-11216, 34-97989 (26 July 2023) (Item 1.05 Form 8-K: disclosure within four business days of the materiality determination); HIPAA Breach Notification Rule, 45 C.F.R. §§ 164.400–414 (notification without unreasonable delay and no later than 60 days after discovery).
02
Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG) vom 18. Dezember 2020 (SR 128), Art. 74a–74h, inserted by the Bundesgesetz vom 29. September 2023 (AS 2024 257), which also struck 'beim Bund' from the long title with effect from 1 April 2025. The reporting duty (Art. 74a–74f) has been in force since 1 April 2025; the enforcement and penal provisions (Art. 74g and 74h) since 1 October 2025. Art. 74b(1) ISG carries the catalogue of covered authorities and organizations in letters a–u; Art. 74b(2) ISG excludes attacks that affect exclusively activities outside the catalogue; Art. 74b(3) ISG extends the duty to attacks with effects in Switzerland even where the affected IT resources are located abroad. Art. 5(c) ISG defines critical infrastructures as drinking-water and energy supply, information, communication, and transport infrastructures, together with further processes, systems, and facilities essential to the functioning of the economy or the well-being of the population; the reporting duty nevertheless operates through the Art. 74b(1) catalogue, the functional criterion resurfacing only in the Art. 74c ISG delegation to exempt.
03
Verordnung über die Cybersicherheit (Cybersicherheitsverordnung, CSV) vom 7. März 2025 (SR 128.51), in force since 1 April 2025. Art. 12 CSV carries the exemptions from the reporting duty, including the small-organization threshold (fewer than 50 persons employed in the affected area and annual turnover or balance-sheet total in that area not exceeding CHF 10 million) for the categories of Art. 74b(1)(g), (h), (l), and (p) ISG, the exemption for higher-education institutions with fewer than 2,000 students, technical thresholds for individual energy and transport categories, and the exemption for letter t providers rendering services to third parties entirely without remuneration. No size-based exemption attaches to letter u manufacturers.
04
ISG (n 2), Art. 74d (reportable cyberattacks), Art. 74e (24-hour deadline from discovery; required content; Art. 74e(4) ISG relieves the person discharging the duty on the organization's behalf from making statements that would incriminate them), Art. 74f (secure transmission system provided by the BACS; the provision obliges the BACS to make the system available and does not oblige the reporting organization to use it); CSV (n 3), Art. 14 (concretization of the four gates of Art. 74d ISG: a manipulation or leak is made out where business-relevant information is accessed, altered, or disclosed by unauthorized persons, or where a data-security-breach report under Art. 24 of the Datenschutzgesetz vom 25. September 2020 (SR 235.1) has been filed; an attack counts as undetected over an extended period where the incident lies more than 90 days back), Art. 15 (additional content: date and time of detection and of the attack, information on the attacker; whether the attack was combined with extortion, threat, or coercion and whether a criminal complaint was filed; the severity of the impairment to availability, integrity, and confidentiality and the effect on the organization's functioning; and, where the report is not made through the BACS communication system, the entity's name and address and the reporting person's contact details) and Art. 16 (14-day period, granted by the BACS, to complete an initially incomplete report). On the reporting channels in practice (Cyber Security Hub form; emailed form for organizations without access to the platform): BACS, 'Merkblatt zur Meldepflicht für Cyberangriffe auf kritische Infrastrukturen' (1 April 2025).
05
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union [2022] OJ L333/80 (NIS2), Art. 23(3) (significant-incident definition, disjunctive and forward-looking), Art. 23(4)(a), (b), and (d) (early warning without undue delay and in any event within 24 hours of becoming aware; incident notification without undue delay and in any event within 72 hours; final report not later than one month after the incident notification), Art. 34(4) and (5) (administrative fines: maximums of at least EUR 10 million or 2% of total worldwide annual turnover for essential entities, EUR 7 million or 1.4% for important entities, whichever is higher in each case); transposition deadline 17 October 2024 (Art. 41).
06
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC [2022] OJ L333/164 (CER Directive), Art. 15(1) (notification without undue delay; unless operationally unable, an initial notification no later than 24 hours after becoming aware of the incident, followed, where relevant, by a detailed report no later than one month thereafter); Art. 6 (identification of critical entities by 17 July 2026).
07
Bundesgesetz über das Verwaltungsstrafrecht (VStrR) vom 22. März 1974 (SR 313.0), Art. 6, applied to the ISG by Art. 74h(2) ISG. Art. 6(1) VStrR applies the penal provisions to the natural persons who committed the act; Art. 6(2) VStrR extends them to the principal, employer, mandator, or represented person who, intentionally or negligently and in breach of a legal duty, fails to avert a subordinate's, mandatary's, or representative's violation or to remedy its effects; and Art. 6(3) VStrR applies Art. 6(2) VStrR, where that principal is a legal person, a general or limited partnership, a sole proprietorship, or an association of persons without legal personality, to the culpable governing bodies, members of those bodies, managing partners, persons in fact directing the business, or liquidators. Art. 74h(3) ISG permits the authority to refrain from prosecuting those persons and to sentence the business itself to pay the fine where no more than CHF 20,000 is at stake and identifying them would require investigative measures disproportionate to the penalty; Art. 74h(4) ISG assigns prosecution and adjudication to the cantons.
08
BACS, 'Sechs Monate Meldepflicht für Cyberangriffe auf kritische Infrastrukturen' (Medienmitteilung, 29 September 2025): 164 mandatory reports received in the first six months of the duty (running from 1 April 2025), with distributed-denial-of-service attacks the most frequently reported category, at 18.1 percent, and the financial sector the most represented reporting sector, at 19 percent. For the calendar-year figure: BACS, Jahresbericht 2025 (published February 2026): 222 mandatory reports from operators of critical infrastructures to the end of 2025.

Whether a Swiss subsidiary, facility, or product line sits inside the ISG catalogue, and whether a defensible report can reach the BACS within 24 hours of discovery, are questions better settled before the clock starts.

Get in Touch