Switzerland's 24-hour reporting duty:
what every SME and commune should know.
A new Swiss legal obligation requires reporting cyberattacks within 24 hours. Today it applies only to critical infrastructure — but it changes the context for every SME and public body in French-speaking Switzerland.
2026-09 · 8 MIN READ
On 1 April 2025 a legal obligation entered into force in Switzerland: operators of critical infrastructure must now report any cyberattack to the Federal Office for Cybersecurity (OFCS) within a strict 24 hours of discovery. Set out in the Information Security Act (ISA) and its cybersecurity ordinance, the measure has, since 1 October 2025, carried fines of up to CHF 100,000 for non-compliance.
The numbers behind the measure
The context is stark. In its annual report published in February 2026, the OFCS recorded 64,733 reported cyber-incidents for 2025 — around 2,000 more than 2024, and nearly 15,000 more than 2023. Since the obligation took effect in April 2025, more than 260 attacks on critical infrastructure have been reported. By some telemetry, Switzerland records a cyber-incident every eight and a half minutes.
Am I in scope? The rule and its exemption
The duty covers nine sectors: authorities, energy, waste disposal, finance, health, information and communication, food, public safety, transport. But the lesser-known exemption matters for SMEs: organisations with fewer than 50 staff and under CHF 10 million in turnover or balance-sheet total in the critical-infrastructure-related activity are exempt — both conditions being cumulative. In practice, a 60-person energy subcontractor is in scope; a small commune or health provider may be, depending on size and role.
Most SMEs in French-speaking Switzerland are not yet legally obliged to report. But the obligation now sets the standard for what a serious organisation must be able to do: detect an attack, and know what to do within 24 hours.
The other deadline not to confuse it with: nLPD's notification duty
Be careful not to confuse two distinct obligations. Alongside the 24-hour ISA deadline for critical infrastructure, the nLPD (revised Swiss data-protection act) requires any organisation processing personal data to notify the FDPIC of a data breach as soon as possible where it poses a high risk to the people concerned. Failing to do so is a separate offence, punishable by a fine of up to CHF 250,000. An SME outside ISA scope is therefore still fully caught by the nLPD.
What a prudent organisation puts in place now
Whether you are legally in scope or simply careful, the same foundations apply:
- Designate an owner — internal or via your MSSP — who knows the OFCS portal and forms before an incident happens. The costliest incidents are those where nobody knew who to alert or how.
- Deploy real detection: EDR on every endpoint and SOC monitoring shorten the gap between compromise and detection — which preserves the 24-hour window and limits damage.
- Document an incident procedure: who decides, who reports, within what deadline, to the OFCS and the FDPIC as applicable.
- Run an annual audit to keep your procedures aligned with ordinance updates — and with the reality of your environment.
In short
The 24-hour duty may not yet apply to your SME. But it has set a new Swiss standard: a credible organisation must be able to detect a cyberattack and act within the day. Between the 24-hour ISA deadline and the nLPD's, the question is no longer "should we be ready?" but "are we, and can we prove it?" — exactly the kind of position our SOC and consulting division help organisations across French-speaking Switzerland document and hold.
Talk to our engineersCould you detect and report an attack within 24 hours?
Our free audit shows you where you stand — detection, procedure, ISA and nLPD compliance — and what it takes to be genuinely ready.