Reporting obligation

Information on the reporting obligation
On 7 March, the Federal Council introduced a reporting obligation for cyberattacks on critical infrastructure, which will come into force on 1 April. Operators of critical infrastructure will be required to report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of discovery. After submitting the initial report within 24 hours of discovering the incident, they have 14 days to complete their report.

Who has to report?
The Information Security Act (ISA), Art.74b, stipulates that authorities and organisations subject to the reporting obligation, such as energy and drinking water suppliers, transport companies and cantonal and communal administrations, must report cyberattacks to the NCSC within 24 hours of discovery.

Which incidents need to be reported?
Examples of when a cyberattack must be reported include when it threatens the functioning of critical infrastructure, has resulted in the manipulation or leakage of information, or involves blackmail, threats or coercion. Critical infrastructure operators who fail to report a cyberattack may be fined.

How should it be reported?
To make the reporting process as simple as possible, the reporting form will be available on the NCSC's Cyber Security Hub, which it already uses to exchange information with critical infrastructure operators.

Information about the CSH
The Cyber Security Hub (CSH) is an important information system of the National Cyber Security Centre (NCSC). It is used to share and manage information on cyber threats, cyber incidents and cybersecurity practices.

FAQ about the reporting obligation
You will find answers to the most important questions about the reporting obligation.

Legal basis for the reporting obligation
The reporting requirement is set out in the Information Security Act (ISA) and in the Cybersecurity Ordinance (CSO).