
On 25 September 2026, the Swiss Federal Council has announced plans to develop a new standalone Cybersecurity Act aimed at strengthening Switzerland’s cyber resilience and creating a more coherent legal framework for cybersecurity. The proposed legislation will consolidate several ongoing legislative projects, including requirements relating to the cyber resilience of digital products, the protection of critical digital data, and cybersecurity obligations for hosting and cloud service providers. It is also intended to incorporate the existing cyber incident reporting obligations applicable to operators of critical infrastructure.
The new framework is expected to align closely with international and European developments, including the EU Cyber Resilience Act, while seeking to minimize the administrative burden on businesses. The Federal Council has tasked the Federal Department of Defence, Civil Protection and Sport (DDPS) with preparing a consultation draft by June 2027.