Cybersecurity in Switzerland and the EU in 2026: Who Is Required to Report—and Starting at What Company Size?
Cybersecurity in Switzerland and the EU in 2026: Who Is Required to Report—and Starting at What Company Size?

Two sets of regulations, two approaches, one company: Anyone operating critical infrastructure in Switzerland must report cyberattacks to the Federal Office for Cybersecurity within 24 hours. Those operating in the EU, on the other hand, must assess their sector, number of employees, and financial metrics—and end up with a significantly broader set of obligations. Many companies are subject to both regimes simultaneously without even realizing it.

The difference is not merely theoretical. In Germany, the NIS2 Implementation Act has been in effect since December 6, 2025, with no transition period; in Austria, the substantive obligations under the NISG 2026 take effect on October 1, 2026; and in Switzerland, penalties for failed reporting have been strictly enforced since October 1, 2025. Starting September 11, 2026, manufacturers of digital products will face an additional reporting requirement under the Cyber Resilience Act.

This article clarifies who is actually affected, what role company size plays, which deadlines apply to which entities, and which technical components can be used to implement the requirements in day-to-day operations. Information current as of August 2026.

Who is required to report cyberattacks in Switzerland?

The list in Article 74b, Paragraph 1 of the Information Security Act is decisive. It lists authorities and organizations from a to u—including universities, federal, cantonal, and municipal administrations, energy and drinking water utilities, healthcare facilities, postal, rail, bus, cable car, and shipping companies, providers of digital services, and manufacturers of hardware and software used in critical infrastructure.

The decisive factor is the function, not the legal form. A private corporation that treats drinking water is included; a government agency engaged solely in internal administrative activities is not necessarily included. The reporting authority is the Federal Office for Cybersecurity (BACS). This requirement has been in effect since April 1, 2025, along with the Cybersecurity Ordinance.

Which incidents must be reported—and which do not?

Cyberattacks—that is, intentionally caused cyber incidents—must be reported. A technical failure without an attacker does not trigger a reporting requirement. The threshold is met if any of the following applies:

  • The operational capability of the critical infrastructure is compromised.
  • Information has been manipulated or leaked.
  • The attack remained undetected for an extended period or was clearly intended to prepare the ground for further attacks.
  • Extortion, threats, or coercion have occurred.

An attack on areas outside the scope of critical operations—such as a utility company’s marketing department—is not subject to mandatory reporting. In practice, a simple test can help: If the organization must resort to contingency plans or if employees and third parties are affected by system outages, the incident must be reported.

How quickly must the incident be reported, and what must the report include?

The initial report must be received by BACS within 24 hours of discovery. If not all details are available at that time, there are 14 days to provide the missing information. The clock starts when the incident is first acknowledged, not when the attack itself occurs—this shifts the problem from the technical realm to the organizational one.

In terms of content, the report must include information about the organization, the nature and execution of the attack, the impact, measures already taken, and—to the extent known—the next steps. There are two options: the online form or an account on the Cyber Security Hub. Anyone who waits to set up an account until an emergency arises will lose hours they simply don’t have. Registration should therefore be part of your preparedness plan, not something done during a crisis.

At what size does the Swiss reporting requirement no longer apply?

Article 12 of the Cybersecurity Ordinance sets forth the exceptions, which are sector-specific rather than blanket. Pharmaceutical companies are exempt if they employ fewer than 50 people in the reportable sector and their annual revenue or total assets in that sector do not exceed 10 million Swiss francs. Universities with fewer than 2,000 students are exempt, as are small municipal administrations below a certain population threshold. Separate thresholds apply to energy, transportation, and other sectors.

The point of reference is always the reportable area, not the entire group. A conglomerate may invoke an exemption for one business unit but not for another. A company that supplies both electricity and district heating may claim the exemption only if the attack and its effects are limited to the exempted business area.

What happens if a report is not submitted?

A penalty-free period ran through September 30, 2025. Since then, the BACS has been able to issue orders, and failure to comply with a legally binding order is punishable by fines of up to 100,000 Swiss francs. One detail is often overlooked: The fine under Article 74h of the Information Security Act (ISG) is imposed on the responsible individual, not on the company. This poses a personal risk for executives and IT managers.

The reporting obligation can be delegated to an IT service provider. However, responsibility still rests with the entity required to report. If the third party fails to submit the report, the client is liable. Therefore, organizations that outsource this function should set out the reporting chain in a contract and test it at least once a year.

Do any regulations apply in Switzerland to companies without critical infrastructure?

Not the ISG reporting obligation. Other obligations do apply, however. According to Article 24 of the DSG, a data security breach must be reported to the EDÖB if it poses a high risk to the data subjects. In the event of a ransomware incident involving the leakage of personal data, dual reporting to BACS and the EDÖB may be necessary. Institutions supervised by FINMA must also report serious cyberattacks within 24 hours as a preliminary notification and formally within 72 hours.

In addition, there are contractual obligations. Those who work for an operator subject to reporting requirements are increasingly finding ISG requirements included in contracts—including deadlines that are shorter than those mandated by law. For small teams that simply need solid basic protection with a firewall, password management, and encryption, a compact office solution is often sufficient.

Kaspersky Small Office Security

View Kaspersky Small Office Security

Who falls under NIS-2 in the EU?

The assessment is conducted in two steps. First, the sector: Annex 1 covers eleven high-criticality sectors, Annex 2 covers seven more, for a total of 18—ranging from energy, transportation, and healthcare to digital infrastructure, food, chemicals, waste, and manufacturing. Organizations not operating in any of these sectors are excluded.

Next is size, based on the EU definition of an SME:

  • Critical facility: at least 50 employees or annual revenue and total assets each exceeding 10 million euros.
  • Particularly important entity: at least 250 employees or annual revenue exceeding 50 million euros and, in addition, total assets exceeding 43 million euros.

The two main criteria are mutually exclusive, while the financial thresholds are cumulative. Thus, 60 employees are sufficient, even with low revenue. Conversely, revenue of 80 million euros combined with a low total assets figure is not sufficient on its own.

Why doesn’t the number of employees alone determine whether a company is affected?

This is where most self-assessments fall short. Four reasons:

  • If the sector does not match, the entity is not affected—size is only assessed afterward.
  • Certain entities are covered regardless of size: operators of critical infrastructure, qualified trust service providers, TLD registries, DNS service providers, as well as providers of publicly available telecommunications services and network operators.
  • Group affiliation matters. A subsidiary with 35 employees and 8 million euros in revenue can fall within the scope of application via the economic entity if the group exceeds the thresholds.
  • Multiple areas of activity are assessed separately. The highest classification resulting from any of the activities is the determining factor.

Anyone who looks only at the list of employees will regularly arrive at the wrong conclusion—in either direction. The self-assessment should be documented, even if the result is negative. In the event of an audit, a clear and reasonable justification is more valuable than a mere assertion.

What distinguishes particularly important institutions from important ones?

It is not the catalog of measures, but rather the oversight and sanctions framework. Especially important entities are subject to proactive oversight: the authority can conduct audits and request evidence without a specific cause. For important entities, oversight is event-driven, meaning it occurs in response to reports or incidents.

The maximum fine for particularly important institutions is 10 million euros or 2 percent of global annual revenue; for important institutions, it is 7 million euros or 1.4 percent. In Germany, failure to register under Section 65 of the BSIG is separately punishable by a fine of up to 500,000 euros. Technically, both categories must implement the same risk management measures—the difference lies in the level of documentation required.

What reporting deadlines apply in the EU?

The reporting chain consists of three stages and is structured the same way for all member states:

  • Early warning within 24 hours of becoming aware of a significant security incident.
  • Incident report with an initial assessment within 72 hours.
  • Final report within one month; if the incident is still being investigated, an interim progress report must be submitted first.

Those subject to reporting requirements in both Switzerland and the EU must adhere to two sets of deadlines simultaneously. The Swiss 24-hour deadline, with a 14-day extension, does not align exactly with the EU framework. A unified reporting framework with clear guidelines—specifying which incident goes to which authority, with what content, and by what deadline—prevents disputes over who is responsible in the event of an emergency.

What specific measures does NIS-2 require?

The German BSIG specifies in Section 30 ten areas that correspond in substance to Article 21 of the Directive: Risk analysis and security policies, incident response, business continuity including backup and crisis management, supply chain security, security in procurement and development, effectiveness assessment, training and cyber hygiene, cryptography and encryption, personnel and access control, as well as multi-factor authentication and secure communication.

The catalog is deliberately formulated to be technology-neutral. What is required is appropriateness measured against risk, size, and potential consequences of damage—not a specific product. Experience shows that organizations operating an ISMS in accordance with ISO 27001 cover a large portion of these requirements. In practice, failures rarely stem from the concept itself but rather from three issues: MFA has not been rolled out everywhere, backups have not been tested, and endpoints are not monitored centrally.

ESET Small Business Security

View ESET Small Business Security

What role do backup and recovery play?

Backup management is no afterthought in either regulatory framework. Under NIS-2, it is explicitly part of maintaining operations; in Switzerland, the ability to recover determines whether an attack even jeopardizes the functionality of critical infrastructure. An organization that is back up and running after two hours is dealing with a different incident than one that operates in emergency mode for three weeks.

Three questions determine the quality of a backup strategy: Is there at least one copy located outside the reach of compromised domain accounts? When was the recovery process last fully tested—not just on a spot-check basis? And is there documentation of how long a recovery takes? Without a reliable answer to the third question, any statement about business continuity is merely speculation. For smaller locations, a suite with integrated cloud backup and a centralized status overview can bridge the gap.

Norton by Symantec Small Business

Buy Norton by Symantec Small Business

How far along is implementation in Germany and Austria?

Germany: The NIS2 Implementation and Cybersecurity Strengthening Act was promulgated on December 5, 2025, and entered into force on December 6, 2025—without a transition period for the substantive obligations. The three-month registration period under Section 33 of the BSIG ended on March 6, 2026. Of the approximately 29,500 affected organizations, about 11,500 had registered by that deadline, which is why the BSI announced an extension until July 31, 2026. Registration is conducted via the BSI portal and requires an ELSTER organizational certificate. It remains possible even after the deadline and is still advisable.

Austria: The NISG 2026 was promulgated on December 23, 2025. The substantive obligations take effect on October 1, 2026; registration with the Cybersecurity Agency must be completed within three months thereafter, i.e., by the end of December 2026. A new requirement is a time-limited self-declaration within twelve months of the registration obligation taking effect. The Chamber of Commerce estimates that approximately 4,000 entities will be affected.

Why doesn’t having a registered office in Switzerland protect a company from NIS-2?

Because the directive is based on the nature of the business, not on the location of the headquarters. Three scenarios bring Swiss companies within the scope of the directive or subject them to its effects:

  • A branch or subsidiary in an EU member state: This legal entity is subject to the national implementing law, provided the sector and size criteria are met.
  • Provision of covered services in the EU without a local branch: cloud computing, data center services, content delivery, managed services, managed security, online marketplaces, search engines, and social networks. Article 2(3) of the Directive requires the appointment of a representative in the EU in this case.
  • Position in the supply chain of an EU company subject to NIS-2: no direct legal obligation, but contractual requirements to provide evidence.

The third scenario is the most significant in terms of numbers. NIS 2 is “exported” via contracts to companies that will never themselves file a report with the authorities.

What does supply chain security mean for suppliers and IT service providers?

Covered companies must assess the security of their direct suppliers and service providers and ensure it is addressed in contracts. For suppliers, this means that the level of security becomes a factor in contract awards. Requests for evidence regarding patch cycles, access control, MFA, incident reporting procedures, and recovery times now regularly appear in requests for proposals.

Those who cannot provide this evidence will lose contracts—long before any regulatory authority takes an interest. Conversely, thorough documentation can be used as a sales pitch. A practical first step without a full ISMS project: an up-to-date asset inventory, documented assignment of access rights, verifiably tested backups, centrally managed endpoint protection, and a written reporting process with designated responsible parties. This covers the majority of standard supplier questionnaires.

What personal responsibility does senior management bear?

In all three legal systems, senior management is directly addressed. According to Section 38 of the BSIG, executive boards must approve risk management measures and oversee their implementation; this obligation cannot be delegated, and personal liability applies. The NISG 2026 further requires management bodies, under Section 31, to participate in specific cybersecurity training. In Switzerland, the fine under Article 74h ISG is imposed on the responsible natural person.

In practice, this means that decisions regarding security budgets, accepted residual risks, and audit results must be recorded. Anyone who postpones measures for cost reasons should document this decision along with the rationale. A verbal approval is worthless in the event of a dispute.

What changes will take effect on September 11, 2026, as a result of the Cyber Resilience Act?

As of this date, the CRA’s reporting requirements will take effect for manufacturers of products with digital elements. Actively exploited vulnerabilities and serious security incidents must be reported within 24 hours as an early warning and within 72 hours as a detailed report—simultaneously to ENISA and the relevant CSIRT, which in Germany is CERT-Bund. The deadlines begin upon becoming aware of the issue. The remaining core obligations, including CE marking, will take effect on December 11, 2027.

This affects a group that only partially overlaps with NIS-2: machine builders with networked control systems, software and app providers, and manufacturers of networked devices. Swiss manufacturers supplying products to the EU are covered by the product regulation, regardless of their place of business. Preparation involves the process rather than the form: Who identifies an active exploit, who decides whether to report it, and who submits the report within one business day?

Which report goes to which authority?

In the event of a major incident, multiple obligations often arise simultaneously. This assignment of responsibilities should be documented in writing in advance:

  • Critical Infrastructure Switzerland: BACS, 24 hours, with additional information to be provided within 14 days.
  • High-risk personal data, Switzerland: FDPIC pursuant to Article 24 of the Swiss Data Protection Act (DSG).
  • Personal data with EU relevance: competent supervisory authority, 72 hours pursuant to Article 33 of the GDPR.
  • NIS 2 entity: national authority or CSIRT, 24 hours, 72 hours, one month.
  • Entities supervised by FINMA: Preliminary notification within 24 hours, formal report within 72 hours.
  • Manufacturers of digital products as of September 2026: ENISA and CSIRT, 24 and 72 hours.

The most common mistake is not missing the deadline, but assuming that one notification replaces the other. It does not. For financial firms in the EU, the sector-specific requirements under DORA also take precedence.

Which security solution fits which need?

For small locations, suppliers, and medical practices without their own IT department, compact business suites are the pragmatic starting point: They cover endpoint protection, firewalls, ransomware defense, and—to some extent—backup and encryption, thus addressing several of the required security measures in a single package. The following comparison evaluates the three products mentioned based on the criteria that actually tip the scales in compliance-driven purchases.

FeatureESET Small Business SecurityKaspersky Small Office SecurityNorton Small Business
Protection for Windows file servers See note
Centralized Management See note Partial
Ransomware Defense with Rollback See note Partial
Integrated firewall See note
Cloud backup included See note
Password manager See note
Encryption of sensitive data See note See note
VPN included See note See note
Software Updater See note See note
Mobile devices covered See note
EDR or XDR features
Use in German government agencies and KRITIS See note
Typical use cases Teams with servers Small offices Mobile teams
License type Perpetual license Term license Term license

Regarding restrictions: “See note” refers to features whose scope varies depending on the edition, licensing tier, and version, and which should be verified based on the current product description before purchase—this applies in particular to server modules, VPN quotas, and management consoles. “Partial” refers to a limited feature set, such as a status overview only instead of full-featured policy management. All three products are endpoint suites for small environments and do not replace an EDR or XDR platform; the manufacturers’ respective larger enterprise product lines are intended for particularly critical organizations and for the required effectiveness testing. Regarding the point “Use in German Government Agencies and KRITIS,” it should be noted that the BSI is maintaining its 2022 warning under Section 7 of the BSIG regarding Kaspersky products through 2026; the manufacturer disputes this assessment. For German government agencies and operators of critical infrastructure, this is a disqualifying factor; for other companies, it constitutes a risk decision subject to documentation as part of the supplier evaluation process.

Is security software sufficient to meet the requirements?

No, and this expectation regularly leads to misguided investments. Both sets of regulations require processes, evidence, and defined responsibilities. A license does not create a reporting chain, a role-based framework, or an effectiveness assessment.

However, technology plays a significant role—and a measurable one at that: Endpoint protection and server security meet network and system security requirements; MFA and password management address access control; backup and tested recovery ensure business continuity; encryption fulfills cryptographic requirements; and a software updater handles vulnerability management. It makes sense to follow the reverse order: first clarify the scope of impact, then identify the gaps, and only then procure the solutions. Those who buy first end up paying twice—once for the license and once for the consultant who has to catch up on the documentation.

What specific steps should companies take in the coming weeks?

A sequence that has proven effective in practice:

  1. List legal entities: Which company is located where, in which sector, with how many employees, and what key metrics?
  2. Assess the scope of impact per entity and per area of activity, and document the rationale for the results in writing—even if the findings are negative.
  3. Complete registrations: BSI portal in Germany, Cybersecurity Authority in Austria starting in October 2026, Cyber Security Hub for entities subject to reporting requirements in Switzerland.
  4. Develop a reporting plan: triggers, recipients, deadlines, responsible parties, and representation outside of business hours.
  5. Conduct a gap analysis against the ten areas of action, including a prioritized list of measures and deadlines.
  6. Review contracts with IT service providers for reporting obligations and security requirements.
  7. Involve management: Document approvals, training, and accepted residual risks.
  8. Fully test a recovery process and log the duration.

Point 8 is the most telling. It demonstrates within a single day just how resilient the rest of the system actually is.

 


Disclaimer
This article is for general information purposes only and does not constitute a sales or licensing recommendation. All information has been compiled to the best of our knowledge, but is provided without guarantee of completeness or accuracy. License conditions are subject to change and may be interpreted differently in individual cases. The content does not replace individual legal or licensing advice.