Requirement to Report Cyberattacks: Who Is Affected in Switzerland—and Who Is Not?
The requirement to report a cyberattack to the OFCS within 24 hours depends neither on the size of the company nor on its revenue, but on its line of business. Who is subject to this requirement under the law, who is not, and what the report must include.
As of April 1, 2025, operators of critical infrastructure are required to report cyberattacks to the Federal Office for Cybersecurity (FOCS) within 24 hours of their detection. The two sections governing the penalty—Sections 74g and 74h of the Information Security Act—took effect on October 1, 2025.
To find out if your company is subject to the law, you must review the text. Section 74b of the law provides a list of authorities and organizations, and inclusion on this list depends neither on size, nor on revenue, nor on whether the entity processes personal data: it depends on the nature of its business.
What the law requires: a report to the OFCS within 24 hours
The Information Security Act (LSI, RS 128) stipulates that a report must be filed within 24 hours of the detection of a cyberattack. The report must include information on the affected organization, the type and execution of the cyberattack, its effects, the measures taken, and, if known, the planned measures.
The Cybersecurity Ordinance (OCyS, RS 128.51) supplements this list. It requires the date and time of detection, the date and time of the attack, and information about the attacker. The report must also indicate whether the attack is linked to an act of blackmail, threats, or coercion and whether it has been the subject of a criminal complaint. Finally, it must specify the severity of the impact on the availability, integrity, and confidentiality of the information, as well as the effects the attack had on the organization’s operations.
This 24-hour period does not require a complete report. If all the necessary information is not available within this timeframe, the OFCS grants 14 days to complete the report. It specifies that this is indeed 14 days, including Saturdays and Sundays, and that an initial report is expected within 24 hours even if no information is yet available. It also gives the example of a system that goes down on a Friday evening, but it is not discovered until Monday that it was the result of an attack: the deadline begins from the time of discovery, i.e., Monday morning.
The law includes a provision for the person drafting the report: a person who is required to report to an authority or organization is not obligated, in that context, to provide information that would expose them to criminal prosecution.
The report is submitted via a form on the Cyber Security Hub, the information-sharing platform that the OFCS makes available to operators of critical infrastructure. Organizations that do not have an account there can use the reporting button on the OFCS website or the email template provided by the OFCS. The same form can be used, upon request, to forward the report to other authorities to which a reporting obligation also applies, such as the Swiss Financial Market Supervisory Authority (FINMA) or the Federal Data Protection and Information Commissioner (FDPIC).
The law specifies the purpose of the requirement to report cyberattacks: to enable the OFCS to detect, at an early stage, the methods used in attacks targeting critical infrastructure, in order to warn potential victims and recommend the necessary preventive and responsive measures. The organization that reports the incident is also entitled to support from the OFCS in managing the incident.
Who Is Subject to This Provision: The List in Section 74b of the LSI
Article 74b, paragraph 1, lists twenty-one categories of authorities and organizations, from letter a through letter u.
| Letter | Target Organizations |
|---|---|
| a | institutions of higher education as defined by the Act on the Promotion and Coordination of Higher Education |
| b | federal, cantonal, and municipal authorities, as well as intercantonal, cantonal, and intermunicipal organizations, with the exception of the Defense Group when the armed forces are performing support duties or active duty |
| c | organizations responsible for public-law duties in the areas of safety and rescue, drinking water supply, wastewater treatment, and waste disposal |
| d | companies in the energy supply sector, as well as those involved in energy trading, metering, and management, excluding attacks targeting a nuclear facility |
| e | companies subject to the Banking Act, the Insurance Supervision Act, or the Financial Market Infrastructure Act |
| f | health care facilities listed on the cantonal hospital list |
| g | medical laboratories that hold a license under the Epidemic Act |
| h | companies that hold an authorization to manufacture, market, or import drugs |
| i | organizations that provide benefits intended to cover the consequences of illness, accidents, inability to work or earn an income, old age, disability, and loss of self-care ability |
| j | the Swiss Broadcasting Corporation |
| k | nationally significant news agencies |
| l | postal service providers registered with the Postal Commission |
| m | railroad companies and concessionaires of cable car, trolleybus, bus, and water transportation systems |
| n | civil aviation companies authorized by the Federal Office of Civil Aviation and the national airports listed in the Sectoral Plan for Aviation Infrastructure |
| o | companies that transport goods on the Rhine and those that handle, load, or unload goods at the Port of Basel |
| p | businesses that supply the public with essential everyday goods and whose partial or complete failure would result in serious supply difficulties |
| q | telecommunications service providers registered with the Federal Communications Office |
| r | Internet domain registries and registrars |
| s | providers and operators of services and infrastructure used to exercise political rights |
| t | service providers and operators cloud, search engines, digital security or trust services, and data centers, if they have their headquarters in Switzerland |
| u | manufacturers of computer hardware or software used in critical infrastructure, when such products have remote maintenance access or are used to control and monitor technical systems or to ensure public safety |
The law clarifies two points. An organization that also engages in activities outside these categories is not required to report cyberattacks that affect only those other activities. Furthermore, the reporting requirement applies to cyberattacks that have an impact in Switzerland, even when the affected IT systems are located abroad.
The law requires the OFCS to inform the relevant authorities and organizations of their potential subjection to the law and, upon request, to issue a decision on this matter.
What the ordinance exempts, and what is not covered by these exemptions
Article 74c of the LSI mandates that the Federal Council grant exemptions to authorities and organizations when disruptions caused by cyberattacks have only a limited impact on the functioning of the economy or the well-being of the population. The Cybersecurity Ordinance governs these exceptions in Article 12 and lists them one by one.
The first paragraph lists five cases:
- colleges with fewer than 2,000 students;
- certain energy companies, depending on the level of protection required of them, or, in the case of natural gas pipeline operators, those with an annual energy transmission volume of less than 400 GWh on average over the past five years;
- certain transportation companies, depending on the systemic responsibilities assigned to them and the type of concession they hold;
- certain civil aviation companies, in accordance with the information security requirements that apply to them;
- Service providers listed under the letter "t" who do not provide services to third parties for a fee.
The second paragraph sets the size threshold. The organizations referred to in subparagraphs (g), (h), (l), and (p) are exempt if they employ fewer than 50 people in the relevant field and their annual revenue or the total assets reported on their annual balance sheet do not exceed 10 million francs.
This threshold therefore covers only four of the twenty-one categories: medical laboratories, pharmaceutical companies, postal service providers, and suppliers of everyday goods. A municipality, a hospital on the cantonal list, or a telecommunications service provider remains subject to the tax regardless of its size.

Why a company that is not on the list is not affected
The OFCS states: For companies that are not part of critical infrastructure, there is currently no legal obligation to report cyberincidents. None of the twenty-one categories applies to a company based on its size, revenue, or the fact that it processes personal data. A Swiss SME—such as a tax advisory firm, a law firm, or an engineering firm—does not fall under any of these categories based on its business activities.
However, there is another reporting requirement under Swiss law, and it is not based on the same criteria. Article 24 of the Data Protection Act stipulates that the data controller must report to the FDPIC as soon as possible any data security breaches that are likely to pose a high risk to the privacy or fundamental rights of the data subject. This provision does not refer to any list of activities: it is triggered by the risk to the data subject, not by the criticality of the infrastructure. The two texts overlap, since the Cybersecurity Ordinance considers that a data breach or information leak has occurred when a data security breach is reported under Article 24.
Additional sector-specific requirements apply to certain regulated entities. The OFCS notes that an institution also subject to the LSI may submit its initial 24-hour report using the OFCS form, but that the detailed 72-hour report must always be submitted through the FINMA platform.
The Case of Swiss IT Service Providers and Municipalities
A letter directly targets IT companies. The letter covers providers and operators of cloud, search engines, digital security or trust services, and data centers headquartered in Switzerland. The exemption provided for in this letter applies only to those who do not provide services to third parties for a fee. Letter q adds telecommunications service providers registered with the Federal Office of Communications, and letter u adds certain hardware and software manufacturers.
The obligation remains with the organization affected by the attack, even when a third party manages the systems. The OFCS states this and provides an example: in the case of a municipality, the service provider may file the report on behalf of the affected municipality, but this must then be documented. It also addresses the issue of shared networks: when a municipality uses the canton’s IT services and network, it is the network operator—in this case, the canton—who files the report. Determining who will be the first to become aware of the incident ties into the question of who controls your environment Microsoft 365.
What Triggers the Announcement
Article 74d of the LSI identifies four scenarios. A cyberattack must be reported when it jeopardizes the operation of the critical infrastructure in question, when it has resulted in the manipulation or leakage of information, when it has gone undetected for an extended period, or when it is accompanied by acts of blackmail, threats, or coercion.
The ordinance defines each of these terms. Operations are jeopardized when employees or third parties experience system outages, or when the organization maintains its activities solely through contingency plans. Tampering or a data breach occurs when unauthorized individuals access, modify, or disclose business-critical information. An attack is considered undetected for an extended period if it occurred more than 90 days ago. Finally, extortion counts as such when it targets the regulated organization or the people who work for it.
Not all incidents are therefore reported, and the OFCS makes this clear using specific examples. A denial-of-service attack on an application that is not critical to the business does not automatically trigger a reporting obligation: what matters is whether the attack jeopardizes the operation of the critical infrastructure as a whole. And according to the OFCS, a hacker attack on an employee’s personal device does not constitute an attack on critical infrastructure, although it does recommend having a specialist assess the situation.
Penalties, and the procedure leading to them
The fine is not imposed for the failure to report itself. When there are indications of a violation of this obligation, the OFCS notifies the organization and sets a deadline for it to comply. If the organization fails to do so, the OFCS issues a decision setting a new deadline and informing the organization that it faces a fine. It is the intentional refusal to comply with this final decision that is punishable by a fine of up to 100,000 francs. Prosecution and adjudication are the responsibility of the cantons.
The OFCS also states that there will be no active monitoring of compliance with this requirement: it can only bring an incident to an organization’s attention when it becomes aware of it on its own.
Voluntary reporting, open to all companies
A company that is not subject to the reporting requirement may report a cyber incident to the OFCS, and the OFCS recommends doing so: this contributes to overall cybersecurity and helps detect threats at an early stage. The form is publicly available at report.ncsc.admin.ch. Private individuals are not subject to this requirement, and their voluntary reports enable the OFCS to identify trends and take countermeasures.
The two systems do not have the same volume. In the first half of 2026, the OFCS received 27,128 voluntary reports and 200 reports filed under the mandatory reporting requirement. Of these 200, the two most represented sectors were the public sector (19.4%) and the IT and telecommunications sector (18.6%).
The OFCS specifies what it provides next: first-level technical assistance—which is not intended to compete with services offered by the private sector—and a recommendation to seek help from specialized companies depending on the scale of the attack. It does not negotiate with extortionists; legal proceedings and negotiations are the responsibility of the police and criminal prosecution authorities.
Our Reading
We conclude: For a company that does not fall into any of the twenty-one categories, there is no project to initiate under this requirement, and nothing to purchase for this reason. The OFCS itself states that companies outside the critical infrastructure sector are under no legal obligation to report.
What determines inclusion on the list is the nature of the business. Size is a secondary factor, and applies only to four out of twenty-one categories. A company that sells IT services, security services, or data center capacity from a headquarters in Switzerland, that is registered with the Federal Office of Communications, or that operates a public entity’s network, falls into a category where this question truly arises. This question cannot be resolved simply by reading the law: the law entrusts the OFCS with the responsibility to respond and issue a decision upon request.
We have two reservations. The first concerns the text itself: Article 74b refers to other federal laws—ranging from the promotion of higher education to passenger transportation, epidemics, and therapeutic products—and no one can draw conclusions based solely on the LSI. This is frustrating, and it is also why the legislature provided for the decision-making process. The second reservation concerns the threshold in Article 12, paragraph 2, which exempts organizations employing fewer than 50 people whose revenue or balance sheet total does not exceed 10 million francs: it covers only four out of twenty-one categories and says nothing about municipalities, hospitals on the cantonal list, or telecommunications service providers.
What remains is what matters regardless of any regulatory requirements—and costs nothing: knowing who in your organization would detect an attack, who would be contacted next, and in what order. An organization under a service agreement has 24 hours to file a report, which assumes that this chain of command is in place before the incident occurs. An organization that is not under such an agreement has just as much reason not to improvise it when the time comes. When this chain of command involves a service provider, it is established in the managed services agreement—not on the day of the incident.
What You Can Check Yourself
- Read Article 74b, paragraph 1, of the LSI and look for the letter that describes your activity. The text is publicly available, and the list is short.
- If a letter might apply, read Article 12 of the Cybersecurity Ordinance: the exemptions are listed by name, letter by letter.
- If you have any questions, please contact the OFCS. The law requires the OFCS to provide information to interested organizations and to issue a decision upon request.
- Check to see if your organization has an account on the Cyber Security Hub. The OFCS recommends that all subject organizations register there; accounts are personal and do not include a group address.
- Consider who in your organization would detect the attack and who would file the report. The responsibility still lies with the affected organization, even when a service provider manages the systems.
- If your organization is not subject to this requirement, write down the address for the voluntary reporting form next to your emergency numbers.
None of these items require a service provider.
Official sources
- Federal Act on Information Security (LSI, RS 128)
- Cybersecurity Ordinance (OCyS, RS 128.51)
- Federal Data Protection Act (FDPA, RS 235.1)
- OFCS — Information on the Reporting Requirement
- OFCS — How should incidents be reported?
- OFCS — Frequently Asked Questions About the Reporting Requirement
- OFCS — Press Release dated August 24, 2026, and 2026/1 Semiannual Report
- OFCS — Notification Form
What an article Can't Know
An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.
You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.
Check what is still true
Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.
Search for a topic in the blogIn the same issue
Three articles on the same topic. The blog has 136 articles, all of which are freely available.

