Skip to main content

Federal Information Security

Until the end of 2023, the NCSC was responsible for the Confederation’s IT security. On 1 January 2024, the Information Security Act (ISA) and its implementing ordinances came into force. The ISA established a specialised federal service for information security within the State Secretariat for Security Policy (SEPOS), which is now responsible for the Confederation’s guidelines on information security.

During a transitional period, the NCSC will continue to issue guidelines on security procedures and the minimum requirements applicable to assets to be protected and IT security processes. The guidelines issued by the NCSC remain in force.

Federal ICT security specifications

The existing IT security specifications within the federal administration, issued by the NCSC.

Federal IT-Security reports

Annual reports published by the NCSC on IT security in the federal administration.

Bug bounty programme to increase cyber-resilience in the Federal Administration

In order to increase its cyber security and reduce cyber risks effectively and cost-efficiently, the Federal Administration runs bug bounty programmes under the leadership of the National Cyber Security Centre (NCSC) and in cooperation with other administrative units and Bug Bounty Switzerland AG.

Campaign in the Federal Administration

The campaign "Security is in your hand" was run by NCSC and was aimed at employees of the Federal Administration. Of course, a lot of information and tips also apply to users outside the Federal Administration.