NCSC / BACS, When Swiss Companies Must Report Cyber Incidents
Introduction
Since 1 January 2024 the Federal Information Security Act (ISG) has been in force; on 1 April 2025 the supplementary provisions on the reporting duty (Art. 74a–74f ISG) took effect. For the first time, Switzerland has a general, sector-wide reporting duty for significant cyber attacks against operators of critical infrastructure (KRITIS). The recipient is the Federal Office for Cyber Security (BACS), which was spun off from the former National Cyber Security Centre (NCSC) in January 2024 and is now an independent federal office within the Department of Defence (VBS).
This article explains in practical terms:
- the terms ISG, BACS, NCSC, who is responsible today;
- which organisations are covered by KRITIS status (sectors, thresholds);
- what counts as a significant cyber attack under Art. 74b ISG;
- the 24-hour initial notification and the 14-day supplementary notification;
- sanctions for non-reporting (Art. 74f ISG) and their addressees;
- the interplay with the FDPIC notification under Art. 24 DSG and with FINMA and GDPR obligations.
The target audience is CISOs, ISBs, executive boards and DPOs of hospitals, energy utilities, telecoms, financial services, logistics and IT service providers whose outage would impair the supply of essential services in Switzerland. Anyone still unclear in 2026 on whether they fall within the reporting duty should have completed the KRITIS assessment formally and in writing, the authority is now actively approaching operators that have not registered.
BACS, NCSC, ISG, terminology
The terms are often mixed up in practice but must be distinguished. The National Cyber Security Centre (NCSC) was set up in 2020 within the Federal Department of Finance as a coordinating body. By Federal Council decision in December 2023 it was spun off as the Federal Office for Cyber Security (BACS) from the EFD on 1 January 2024 and moved to the Federal Department of Defence, Civil Protection and Sport (VBS). The BACS is now the competent federal office for operational federal cyber security and for receiving notifications under the ISG.
The name NCSC lives on in international usage (like the UK's NCSC or the US CISA) and the BACS website continues to use it in English translation. In Swiss law, however, BACS is the correct term, a notification addressed to the NCSC will functionally land at the BACS.
The Information Security Act (ISG) has been the legal basis for federal information security since 2024 and contains in Art. 74a–74f the reporting duty for significant cyber attacks against operators of critical infrastructure. This duty is Switzerland's answer to the EU NIS2 Directive and Germany's IT Security Act 2.0; in some respects it is narrower (no general security standards for mid-sized businesses), in others broader (sectoral breadth, uniform 24-hour deadline). We compare it with NIS2 in our article NIS2 Directive Switzerland.
Who is a KRITIS operator
Art. 74a(1) ISG names the sectors in which operators of critical infrastructure are active. The Information Security Ordinance (ISV) specifies the thresholds. The sectors include:
- Energy (electricity, gas, oil, district heating);
- Drinking water and wastewater;
- Health (hospitals, labs, pharmacies, manufacturers of critical medical devices);
- Banks and financial market infrastructures;
- Insurance;
- Transport (public transport, aviation, shipping, logistics);
- Food supply;
- Information and communications technology (telecom, internet providers, data centres, cloud);
- Federal and cantonal authorities;
- Trust service providers under ZertES;
- Manufacturers and suppliers of hardware and software used in critical infrastructure.
The thresholds are spelled out in the ISV (e.g. supply volume, number of end customers, market share). Rule of thumb: anyone supplying a material share of a critical sector whose outage would be noticeable regionally or nationally is in scope. An SME without structural importance for Swiss supply typically falls outside the reporting duty, but is still subject to the breach notification under Art. 24 DSG when personal data is involved. A formal self-classification, documented and approved by the board, is the 2026 minimum standard.
What is a significant cyber attack
Art. 74b ISG defines the notifiable attack functionally rather than exhaustively. A cyber attack is significant where it meets at least one of the following criteria:
- Functionality of critical infrastructure is impaired: outage, disruption, degradation of service quality that materially affects end customers.
- Manipulation or exfiltration of information: particularly security-relevant data, configuration data of critical systems, or personal data at scale.
- Extortion, threat or coercion: classic ransomware, notifiable even without confirmed data exfiltration.
- Cyber attack with high propagation potential: e.g. supply-chain attacks that may affect other operators.
Not every phishing attempt is notifiable. The significant threshold is met when the impact goes beyond a single workstation and could realistically affect the KRITIS sector. In doubt the maxim holds: notify early rather than miss the deadline. The BACS actively supports operators in an advisory role and uses notifications primarily for situational awareness and to warn other operators, not for sanctions.
Important: the duty applies regardless of whether personal data is also affected. Where it is, the FDPIC must be informed in parallel under Art. 24 DSG and, where applicable, the EU authority under Art. 33 GDPR. The three notifications must be content-consistent but tailored to each recipient.
Deadlines and contents of the notification
The reporting duty follows a two-stage model akin to NIS2:
- Initial notification within 24 hours of awareness of the significant cyber attack. A short description with the essentials suffices: what was detected, which systems are affected, what immediate impacts are suspected, what immediate measures were taken, who is the contact.
- Supplementary or final notification within 14 days with the full findings: root cause, impacts, measures taken and planned, parties involved (processors, suppliers), whereabouts of stolen data.
The BACS runs an online notification platform (cyberreporting.ch / BACS portal) that guides through the mandatory contents. Alternatively the notification can be filed in writing or by phone. We recommend explicitly noting in the initial notification which information is still unclear and when the supplement will follow, that builds trust and prevents the authority from interpreting gaps as deliberate omissions.
Notification to the BACS does not replace notification to the FDPIC. Even though both authorities are now discussing simplified multi-recipient templates, they remain separate today. FINMA requires supervised institutions to notify on their own, usually within 24 hours of significant incidents, regulated in FINMA Circular 2008/21 and FINMA Supervisory Notice 03/2024 on cyber risks. Those serving all three recipients in parallel should reflect this in the incident-response playbook.
Sanctions for non-reporting
Art. 74f ISG provides for fines of up to CHF 100,000 for intentional non-reporting of a significant cyber attack. The addressee of the fine is the natural person responsible for the notification within the operator, analogous to the DSG structure, it lands on the individual, not the company. Negligent infringements carry lower penalties but remain punishable.
In practice the BACS focused on awareness in the first months of application in 2025 and worked cooperatively with companies on compliance. With the end of the transitional phase in mid-2026 a harder line is expected, particularly for repeat infringements and clearly late notifications that surfaced only after media coverage.
Classic risks:
- We wanted to wait for forensics: the deadline does not start with the final forensic report but with awareness of the attack. A preliminary notification with the incomplete picture is the right path.
- Quiet ransom payment without notification: even when the attacker demands silence, the extortion does not extinguish the duty, on the contrary, it qualifies the incident as significant.
- Wrong KRITIS self-classification: we thought we were not in scope does not survive a criminal investigation if no documented assessment exists.
- Multi-party mandates without escalation: where an IT service provider detects the incident but does not inform the client (the KRITIS operator). Contractual clauses must mandate escalation explicitly.
Interfaces with FDPIC, FINMA and GDPR
The ISG reporting duty complements, and partially overlaps with, several other reporting duties. Losing the overview risks duplication or, worse, missing a duty.
FDPIC under Art. 24 DSG: Triggered when personal data is affected and the risk is likely to be high. As soon as possible, normally within 72 hours. Recipient: FDPIC platform. Content overlaps but must be filed separately.
GDPR under Art. 33 GDPR: Triggered when EU data subjects are affected. 72 hours from awareness. Recipient: lead authority or national supervisor. Heavily formalised, with classification duty against the likely risk threshold.
FINMA for supervised institutions: Circular 2008/21 and Supervisory Notice 03/2024 establish a 24-hour reporting duty for critical operational incidents including cyber attacks. Recipient: the competent FINMA supervisor.
BAV, FOCA, ENSI etc.: Sectoral reporting duties in regulated areas (rail, aviation, nuclear). Often parallel to ISG.
In practice a multi-trigger matrix in the incident-response playbook is recommended, for each incident type it lists the applicable reporting duties, deadlines and recipients. The matrix forms part of the executive board briefing in an incident and should be reviewed yearly.
How SIDD supports you
SIDD supports KRITIS operators across the full cyber-compliance value chain: KRITIS classification, setup of the ISG-compliant reporting process, training of the board and incident-response teams, real-time incident support. Through our mandates as external CISO/ISB and on the build and operation of the ISMS to ISO 27001 we secure the organisational maturity the legislator implicitly assumes.
On the technical side we surface weaknesses before the attacker through penetration testing and continuous vulnerability scanning. Awareness programmes via IT security workshops reduce the human risk that is the entry point in most reported incidents.
For an ISG positioning or an active incident, contact us via the contact form or request a quote. We respond outside business hours and can field a crisis team within hours.
