At a meeting on 7th March 2025, the Swiss Federal Council announced a new reporting obligation for cyberattacks on critical infrastructure, which will come into force on 1 April.
Operators of critical infrastructure will be required to report cyberattacks to the Swiss National Cyber Security Centre (NCSC) within 24 hours of discovery. These reports will enable the NCSC to assist victims of cyberattacks and alert operators of critical infrastructure.
Critical infrastructure providers in the country will have six month to apply the new rules before sanctions for reporting failures kick-in on 1st October.
To make the reporting process as simple as possible, the reporting form will be available on the NCSC’s Cyber Security Hub, which it already uses to exchange information with critical infrastructure operators. Organizations not registered on the platform can submit reports by email using a form available on the NCSC website. After submitting the initial report within 24 hours of discovering the incident, organizations have 14 days to complete their report.






