SCRM Supplier Compliance & Risk Management

Home

Information Security Act · reporting to the BACS

Twenty-four hours is short when the incident happened at your provider.

The Swiss reporting duty falls on the operator – including when the attack arrived through a supplier. What counts then is a contact list that is actually correct.

Operators of critical infrastructure must report cyberattacks to the Federal Office for Cybersecurity. The scope includes energy and water supply, transport, healthcare, public authorities and other areas of significant importance to supply security. The federal ICT minimum standard adds a framework that explicitly covers suppliers and service providers.

The practical core is unglamorous. Attacks frequently begin at a provider with access. Whether a deadline is met depends on whether you know, in the moment, who is responsible at that provider, which systems they touch and what was contractually agreed.

Who is affected

  • Operators of critical infrastructure in Switzerland.
  • Their IT providers, maintenance firms and cloud vendors – through contract and reporting chain.
  • Companies supplying into critical supply chains.
  • Organisations applying the ICT minimum standard or held to it by customers.

What must be ready

Register
All providers with access to systems and data, with criticality and ownership.
Contact routes
Out-of-hours reachability, recorded and tested.
Contractual duties
An obligation on the provider to inform you without delay – with a deadline.
Incident log
Times, findings and actions recorded as they happen, not reconstructed.
Recurring checks
Contacts and responsibilities go stale faster than contracts.

How SCRM covers it

Emergency contacts on the supplier

Held where people look in a crisis, not in a file on a drive.

Criticality by access

Who reaches which systems decides the order of the calls.

Timestamped incident file

The sequence can be evidenced later because it was captured as it happened.

Review cycles

Contact data gets confirmed on a schedule instead of failing in an emergency.

Frequently asked

Does the duty extend to our suppliers?

The operator reports. Your provider owes you only what the contract says – which is why the duty to inform belongs in it explicitly.

How does this differ from NIS2?

NIS2 is EU law with a broader sector scope and its own deadlines. Swiss companies with EU sites can face both regimes side by side.

We are not critical infrastructure. Still relevant?

The duty does not hit you directly. As a supplier to an operator you will receive the requirements by contract.

As of July 2026. The exact scope follows from the act and its ordinances; verify before relying on it. Not legal advice.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required