Skip to main content

Report to NCSC

The NCSC receives voluntary reports of cyberincidents from the public, companies and the authorities, and assists them in taking the necessary steps. The NCSC is also responsible for collecting reports of cyberincidents from operators of critical infrastructure, who have been subject to a reporting obligation since 1 April 2025. The NCSC also receives reports of vulnerabilities and assigns them a unique identification number in accordance with the international reference system.

Please note that reports are not processed around the clock. In the event of an acute emergency, call the police emergency number 112 or 117.

Voluntary notification

We can identify possible trends in dangers on the internet and take targeted action against them. After answering a few questions, you will receive an automated initial assessment of your case with the measures to be taken and can then forward the case to the National Cyber Security Center NCSC for further processing.

Voluntary notification: Report the incident here

Mandatory notification

From 1 April 2025, critical infrastructures must report critical cyber incidents to the NCSC. You can find the criteria whether your authority or organisation is required to report on the federal law publication platform (in german, french and italian only). In a step-by-step guide, you can find out whether your incident has to be reported and how to report it correctly.

Mandatory notification:Step-by-step guide

Coordinated Vulnerability Disclosure (CVD)

Have you discovered a vulnerability in an IT system or in commercially available applications, software or hardware impacting Switzerland and want to report it? There are different ways to report a vulnerability.

Report a vulnerability

Online criminal complaint

Online complaints can only be filed for the offences listed below. For all other criminal offences, you must contact a police station. The NCSC does not accept criminal complaints.