Information Security Act · reporting to the BACS
Twenty-four hours is short when the incident happened at your provider.
The Swiss reporting duty falls on the operator – including when the attack arrived through a supplier. What counts then is a contact list that is actually correct.
Operators of critical infrastructure must report cyberattacks to the Federal Office for Cybersecurity. The scope includes energy and water supply, transport, healthcare, public authorities and other areas of significant importance to supply security. The federal ICT minimum standard adds a framework that explicitly covers suppliers and service providers.
The practical core is unglamorous. Attacks frequently begin at a provider with access. Whether a deadline is met depends on whether you know, in the moment, who is responsible at that provider, which systems they touch and what was contractually agreed.
Who is affected
- Operators of critical infrastructure in Switzerland.
- Their IT providers, maintenance firms and cloud vendors – through contract and reporting chain.
- Companies supplying into critical supply chains.
- Organisations applying the ICT minimum standard or held to it by customers.
What must be ready
- Register
- All providers with access to systems and data, with criticality and ownership.
- Contact routes
- Out-of-hours reachability, recorded and tested.
- Contractual duties
- An obligation on the provider to inform you without delay – with a deadline.
- Incident log
- Times, findings and actions recorded as they happen, not reconstructed.
- Recurring checks
- Contacts and responsibilities go stale faster than contracts.
How SCRM covers it
Emergency contacts on the supplier
Held where people look in a crisis, not in a file on a drive.
Criticality by access
Who reaches which systems decides the order of the calls.
Timestamped incident file
The sequence can be evidenced later because it was captured as it happened.
Review cycles
Contact data gets confirmed on a schedule instead of failing in an emergency.
Frequently asked
Does the duty extend to our suppliers?
The operator reports. Your provider owes you only what the contract says – which is why the duty to inform belongs in it explicitly.
How does this differ from NIS2?
NIS2 is EU law with a broader sector scope and its own deadlines. Swiss companies with EU sites can face both regimes side by side.
We are not critical infrastructure. Still relevant?
The duty does not hit you directly. As a supplier to an operator you will receive the requirements by contract.
As of July 2026. The exact scope follows from the act and its ordinances; verify before relying on it. Not legal advice.