NCSC Switzerland, Critical Infrastructure Reporting Duties in 2026

7 min readLast updated By Marc Grob

Introduction

The Swiss cyber incident reporting duty became operational in 2025 and is becoming normative reality for KRITIS operators in 2026. The Federal Information Security Act (ISG, in force since 1 January 2024) and its supplementary reporting provisions (Art. 74a–74f ISG, applicable since 1 April 2025) provide the framework; the Federal Office for Cyber Security (BACS, formerly NCSC) is the competent authority. The official transition phase, during which the BACS acted primarily cooperatively, ends in mid-2026. From the second half of 2026, consistent application of the fines regime is expected.

This overview gives executive boards, supervisory boards and CISOs a compact 2026 orientation on what to do:

  • status of legislation and downstream ordinances;
  • current BACS reporting figures and thematic priorities 2024/2025;
  • the five compliance building blocks: KRITIS classification, contingency planning, reporting process, board briefing, audit;
  • interfaces with the NIS2 Directive and the DORA regime for financial actors;
  • typical maturity profiles and the path to maturity level 4 (managed process);
  • recommended immediate measures for the final months before tighter supervision.

Unlike our foundational article on the NCSC/BACS reporting duty that explains the legal mechanism, this article focuses on the operational reality in 2026 and on the consequences if you are not yet set up.

State of legislation in mid-2026

The ISG and the Information Security Ordinance (ISV) are in force and are continuously concretised by the BACS, the FDPIC and administrative practice. Three developments shape the 2026 picture:

First: The BACS launched a reworked online notification platform in 2025 that supports structured initial and final notifications with built-in plausibility checks and a machine interface for integrated SIEM/SOAR systems of larger operators.

Second: In May 2026 the BACS published an updated guide on KRITIS self-classification that refines sectoral thresholds and provides example cases for borderline situations (e.g. SaaS providers with a Swiss customer base, regional energy distributors below ISV thresholds).

Third: The consultation on revising the ISV closed in April 2026; a first adjustment of thresholds for the health and ICT sectors is announced for Q4 2026. The direction is clearly expansionary, more actors will be covered, not fewer.

In parallel, several regulatory strands run alongside: the EU DORA regime has applied to EU financial actors since 17 January 2025; FINMA implements it indirectly through supervisory notices and Circular 2008/21 in Switzerland. The EU NIS2 Directive creates a broad cybersecurity baseline in the EU that Swiss groups with EU subsidiaries must follow. An internationally active Swiss-based company today typically has three to four parallel cyber reporting duties to handle.

BACS figures and thematic priorities

The operational situation in 2024 and 2025 shows clear trends, which we summarise here:

  • Volume: The BACS recorded around 65,000 voluntary reports in 2024 via the Antiphishing platform and the previous reporting portal, mostly phishing and basic fraud attempts. Mandatory ISG notifications since April 2025 have run in the mid-three-digit range in the first 12 months; the trend is clearly upward.
  • Top attack vectors: Ransomware (especially double extortion), business email compromise, compromised cloud identities (MFA bypass via phishing kits), supply-chain attacks on managed service providers.
  • Sectoral concentration: Health (hospitals, labs), manufacturing/engineering, municipal authorities, telecom sub-providers.
  • Impacts: 5–15 days of operational disruption on average in ransomware cases; in hospitals, repeated emergency modes with the deferral of non-urgent procedures.
  • Insurance situation: Cyber insurers have raised premiums materially and made requirements on policyholders (MFA, EDR, backup concept, incident-response plan) contractually binding.

This picture shows why the duty under Art. 74a ISG is not a bureaucratic formality but a consequence of what Swiss operators are already living through. Without a working reporting process you do not just have a compliance problem, you have an operational resilience problem.

The five compliance building blocks

For a 2026 maturity baseline we recommend the following five building blocks. They also form the audit grid we apply in our external CISO/ISB mandates.

  1. KRITIS classification: Written self-assessment against Art. 74a ISG and ISV thresholds, reviewed and approved by the supervisory board. In borderline cases, preliminary contact with the BACS.
  2. Contingency planning and incident response: Playbook with roles, RACI matrix, escalation paths, communication templates, forensic contacts, parallel reporting duties (BACS, FDPIC, FINMA, GDPR). Annual tabletop exercise with the executive board.
  3. Reporting process: Defined role (CISO or DPO) as notification representative, written authorisation, templates for initial and final notification, interface to the BACS platform.
  4. Executive and board briefing: Semi-annual cyber risk reports with KPIs (notifications, MTTR, patching status), in board-level language. Personal liability of the board makes this a duty, not an option.
  5. Audit and effectiveness measurement: Annual internal or external cyber-compliance audit, including a test of the notification chain (mock incident), review of contractual clauses with vendors, update of the processing register.

Maturity model: in practice we see five levels, ad hoc (1), repeatable (2), defined (3), measured (4), optimised (5). By mid-2026 every KRITIS operator should be at level 3 or higher. Anyone still at level 1 or 2 must catch up urgently in the next six months.

Interface with NIS2 and DORA

Swiss companies with EU operations often face two additional EU regimes that together generate a much higher compliance load than ISG alone.

NIS2 Directive (EU 2022/2555): Transposed since 17 October 2024 in most EU Member States (with delays, e.g. in Germany). Covers essential and important entities across 18 sectors. Requires risk-based security measures (Art. 21 NIS2), board cyber training (Art. 20), notification of significant incidents within 24h early warning, 72h initial notification and a 1-month final report (Art. 23). Recipient is the national CSIRT/supervisor. Fines up to EUR 10 million or 2 % of group turnover. A Swiss parent can be indirectly bound through its EU subsidiaries.

DORA Regulation (EU 2022/2554): Applicable since 17 January 2025. Covers EU financial actors and their critical ICT third-party providers. Requires comprehensive ICT risk management, resilience testing (including TLPT), third-party risk management (Art. 28 et seq.) and notification of major ICT incidents within 4h first notification, 72h initial notification and a 1-month final report. FINMA pursues the DORA line for Swiss banks via supervisory notices, even though DORA does not apply directly, see our DORA-FINMA comparison.

Anyone serving both regimes in parallel should align incident classification and notification timing in a single matrix, otherwise inconsistencies arise that will immediately stand out under EU supervision.

Recommended immediate measures Q3/Q4 2026

If you have not yet reached full maturity level 3 by mid-2026, we recommend the following 90-day prioritisation:

  1. Week 1–2: Close the KRITIS classification in writing. If unclear, seek preliminary contact with the BACS. Obtain a supervisory board decision.
  2. Week 3–6: Build or update the incident-response playbook. Keep notification templates (BACS, FDPIC, FINMA, GDPR) ready. RACI matrix with named individuals, not functions.
  3. Week 7–8: Tabletop exercise with executive board and IR team. Realistic scenario (ransomware on a production system with personal data exposure). Document gaps, action plan with deadlines.
  4. Week 9–10: Vulnerability scan and penetration test on critical systems. Remediate findings by priority.
  5. Week 11–12: Executive briefing with status report, risk picture, planned investments. Update of cyber insurance with new measures, premium renegotiation where applicable.

Doing all five steps in-house requires a seasoned team. Where that is missing, external support is more common and more efficient than trying to do it all alone from a standing start. Crucially, documentation must remain auditable, a BACS auditor, FINMA inspector or ISO 27001 certifier asks essentially the same questions.

Maturity profiles in practice

In our 2026 mandates we encounter four typical profiles that may help with self-positioning:

Profile A, We are not really in scope: SMEs on the edge of the KRITIS definition, without a documented assessment. Cyber incidents are handled ad hoc, no incident-response plan exists or it is outdated. 2026 risk: high personal liability for the executive board in case of an incident.

Profile B, We have a plan, but it is old: Established companies that built an IT emergency manual in the past, but it has not survived two cloud migrations and three personnel changes. Plan exists nominally, but is not in the muscle memory of the organisation.

Profile C, We are ISO 27001 certified, so we are fine: ISMS in place, incident management documented, but specific ISG reporting duties and parallel FDPIC/FINMA/GDPR requirements are not integrated in the playbook.

Profile D, We have the process, but never trained it: Compliance on paper, technical controls in place, but the team has never run through the process under stress. In a real incident, escalations are delayed, briefings forgotten, notification wording drafted under time pressure.

Profiles A and B need strict catch-up in 2026; profiles C and D need targeted complements. Realistic effort: 8–16 advisory days over 90 days, depending on the starting point, enough to reach auditable compliance.

How SIDD supports you

SIDD brings KRITIS operators from any of the four profiles to an auditable maturity level 3 or 4. Our standard packages combine KRITIS classification, build of the reporting process, board training, penetration test of critical systems and tabletop exercise within 60–90 days. Through mandates as external CISO/ISB we then run the process continuously, including annual effectiveness measurement and updates for regulatory changes.

For companies with EU operations we extend ISG compliance with NIS2 and DORA requirements and a consolidated multi-trigger notification matrix. With a full ISMS to ISO 27001:2022 we simultaneously create the organisational base that ISG, NIS2 and DORA implicitly assume. Training via IT security workshops for SMEs embeds knowledge broadly across the organisation.

Write to us via the contact form or request a quote, we respond within one business day with a concrete 90-day plan that takes your actual maturity level as the starting point.

Need help putting this into practice? SIDD operates the matching service.
See service →

NCSC Switzerland, Critical Infrastructure Reporting Duties in 2026

INSIGHT

InfoSec
24 May 2026
Marc Grob
The reporting duty for cyberattacks on critical infrastructure at a glance: current rules, the role of the NCSC, links to NIS2 and DORA, first steps.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.