On 25 September 2026, Switzerland's Federal Council decided to merge three separate cyber mandates into a single Cybersecurity Act, with a consultation draft not due until June 2027 1. That consolidation is sound governance design. But it does not buy Swiss companies time: any manufacturer placing a connected product on the EU market already has to report actively exploited vulnerabilities within 24 hours, under a duty that has applied since 11 September 2026 35. The domestic clock and the one that actually binds Swiss exporters are running at very different speeds.
Bern folds three cyber mandates into one law
The Federal Council tasked the Department of Defence, Civil Protection and Sport (VBS) with drafting a consultation proposal, due by June 2027, for a standalone federal Cybersecurity Act (Cybersicherheitsgesetz, CSG) 1. The new law consolidates three parliamentary mandates that had been running as separate projects: cyber resilience of products with digital elements (Motion 24.3810), protection of particularly important digital data (Motion 23.3002), and the role of hosting and cloud providers in cybersecurity (Motion 25.3011) 1. It will also absorb the reporting duty that operators of critical infrastructure already carry under the Information Security Act (ISG): a report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a cyberattack, in force since 1 April 2025 16.
The CSG will set binding requirements for manufacturers, importers and distributors of hardware and software products, including grounds for market surveillance and a ban on distributing insecure devices 1. A year earlier, the Federal Council had commissioned only the product-security strand on its own, with a consultation draft targeted for autumn 2026 2. Folding in two further mandates has cost that plan roughly nine months before a draft even exists, and the CSG still needs to pass through consultation, parliamentary committees and plenary debate afterward.
Why the compliance clock that matters is not the Swiss one
While the CSG is still years from binding anyone, the EU's Cyber Resilience Act (CRA) already does. The CRA covers "hardware and software products" made available on the EU market, including components placed on the market separately, and its obligations fall on manufacturers regardless of where they are established: an importer established in the EU that places a product from a non-EU manufacturer on the market must ensure the manufacturer has met its duties, which is how the regulation reaches companies headquartered outside the Union 4. A Swiss maker of medical devices, industrial automation equipment or connected building technology that sells into the EU is therefore in scope today, independent of Bern's timeline.
Those duties are not abstract. Since 11 September 2026, manufacturers and open-source software stewards report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform: an early warning within 24 hours of becoming aware, a fuller notification with an initial assessment within 72 hours, and a final report within 14 days of a corrective measure becoming available (for severe incidents, within a month of the 72-hour notification) 35. The platform routes each report to the competent national CSIRT, which shares it with other CSIRTs wherever the product is also sold 5.
| Instrument | Status on 25 Sept 2026 | Who is bound | Deadline |
|---|---|---|---|
| EU Cyber Resilience Act | Reporting duty in force since 11 Sept 2026 | Manufacturers placing connected products on the EU market, wherever based | 24h early warning, 72h notification, 14-day final report 35 |
| Swiss Information Security Act | In force since 1 Apr 2025 | Operators of critical infrastructure | 24h report to BACS 6 |
| Swiss Cybersecurity Act (CSG) | Consultation draft due mid-2027 at the earliest | Hardware/software manufacturers, importers, distributors; hosting/cloud providers; holders of sensitive digital data | Not yet defined 1 |
Our estimate: given a consultation draft not due before June 2027, and the usual Swiss path of consultation, parliamentary committee work, plenary debate and an optional referendum period, binding obligations under the CSG are unlikely before 2029. That is a rough order of magnitude, not an official schedule, but it is enough to make one point clearly: for most security leaders, the compliance gap that is open right now is the EU one, not the domestic one. The Federal Council's own framing supports building toward that standard early, since it explicitly orients the CSG toward EU law to ease the burden on companies that already comply with the CRA 12.
What it means for Swiss manufacturers and infrastructure operators
For manufacturers, importers and distributors of connected devices established in Switzerland, the immediate task is not to wait for the CSG. Check now whether any product placed on the EU market meets the CRA's definition of a product with digital elements, and confirm operationally that the organization can meet the 24-hour early-warning deadline for actively exploited vulnerabilities. That capability, once built, should also satisfy whatever the CSG eventually requires domestically, since Bern intends to align with EU concepts 12.
For operators of critical infrastructure, the ISG's 24-hour reporting duty to BACS should sit with a single accountable owner rather than being split across IT and OT teams, because the CSG is set to inherit this obligation rather than replace it with something unrelated 16. For hosting and cloud providers, and for organizations that hold data the future law may classify as particularly important, the relevant work is different: Switzerland does not yet regulate either area, so Motions 23.3002 and 25.3011 chart genuinely new territory. Track them individually in a regulatory-change register rather than folding them into a single, undifferentiated "new Swiss cyber law" entry. For European groups with Swiss subsidiaries, the Federal Council's EU-oriented approach is a signal that Swiss and EU product-security compliance work can likely converge on shared definitions and evidence over time, which is worth flagging to group compliance functions now.
Questions for leadership
- Do we know which of our products qualify as "products with digital elements" placed on the EU market, and can we already meet the CRA's 24-hour early-warning deadline operationally, not just on paper?
- If we operate critical infrastructure, does our 24-hour ISG reporting workflow have one accountable owner who could absorb a broader Cybersecurity Act duty, or is it split across teams today?
- Are the three consolidated motions behind the CSG tracked individually in our regulatory-change register, or only as one future Swiss law — a likely source of blind spots given how much wider its scope now is?
- If the CSG consultation draft largely mirrors the CRA, how much of our EU compliance work would already satisfy it? Where, such as hosting and cloud obligations, is there no EU equivalent to build from?
- What signpost should trigger a reassessment: the VBS publishing its consultation draft, expected by June 2027, or an earlier signal that the timeline has shifted again?
Sources
- Der Bundesrat, “Bundesrat will neues Cybersicherheitsgesetz schaffen”, 25 September 2026. admin.ch
- Bundesamt für Cybersicherheit (BACS), “Der Bundesrat will die Cyberresilienz von digitalen Produkten stärken”, 20 August 2025. bacs.admin.ch
- European Commission, “Cyber Resilience Act - Reporting obligations”, 11 September 2026. digital-strategy.ec.europa.eu
- European Commission, “The Cyber Resilience Act - Summary of the legislative text”, 3 December 2025. digital-strategy.ec.europa.eu
- ENISA, “The CRA Single Reporting Platform is launched”, 11 September 2026. enisa.europa.eu
- Der Bundesrat, “Meldepflicht für Cyberangriffe auf kritische Infrastrukturen”, 7 March 2025. admin.ch