Cybersecurity 2026

SWITZERLAND Law and Practice Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd

5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation The FADP regulates the issue of certification in Article 13. Software and system suppliers, as well as data controllers and their subcontractors, can have their products validated by an independent, accredited body. These certifications attest to their compliance with the requirements of the FADP. In addition to ensuring compliance with data protec - tion standards, these certifications offer a number of advantages. According to Article 22 (5) of the FADP, a data controller who adheres to a code of conduct or holds a certification may be exempted from carry - ing out an otherwise-required data protection impact assessment. These certifications can also be used as a basis for authorising data transfers abroad, even when the recipient country does not offer a level of data protection deemed adequate (Article 12 of the DPO). However, certification mechanisms have so far been little used in Swiss law. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Concerning cybersecurity and data protection, see also 1.2 Cybersecurity Laws . The only truly overarch - ing body of laws is the federal legislation on data pro - tection, namely the FADP and its implementing ordi - nances, in particular the DPO. The FADP and the DPO contain provisions on data security, but the Swiss leg - islator relies on a technologically neutral approach, with the result that these rules on data security remain rather abstract and do not refer to any specific tech - nology, or any specific standard or technical require - ment, except for the obligation to keep logs of certain higher-risk processing activities. Under the FADP, an intentional failure to implement certain minimum tech - nical and organisational measures may incur liability for a criminal fine against the responsible individuals of up to CHF250,000, although there is a debate as to whether there are any binding minimum measures.

The ISA of 18 December 2020, which entered into force on 1 January 2024, governs information secu - rity practices within the federal government and its administrative bodies. Under the ISA, several ordi - nances further specify and implement information security requirements and also repeal (inter alia) the CyRV. Importantly, a significant feature of the ISA is the introduction of a reporting obligation for cyber-attacks for public authorities such as universities; federal, cantonal and municipal agencies; inter-cantonal, can - tonal and intercommunal organisations; and providers of critical infrastructures, for example in the energy, finance, healthcare, insurance, transport, communi - cation and IT sectors. In-scope organisations must report cyber-attacks to the NCSC within 24 hours, where the relevant thresholds and definitions are met. As a more general consideration, the policy discus - sions in Switzerland in recent years have shown that cybersecurity is progressively evolving from what once was a purely technical consideration into a main - stream legal topic. Cybersecurity is now not only part of the legal discussions surrounding data protection and data security (in various areas, such as finance and telecommunications), but is also a focus of other branches of the law, such as insurance law. Moreover, the policy discussions at the federal level are not expected to lead, in the short term, to any overarching cybersecurity law. However, the topic remains highly dynamic and strongly dependent on international developments. Given Switzerland’s size and geographical location, prompt legal develop - ments in the area of cybersecurity are a real possibility. 6.2 Cybersecurity and AI Concerning cybersecurity and AI, see also 6.1 Cyber- security and Data Protection . In Switzerland, there is currently no overarching regulation on the use of AI. The FDPIC has published statements and non-binding guidelines on how to address data protection matters in these areas. For example, the FDPIC pointed out that the FADP is directly applicable to AI-based data processing, and the FDPIC expects manufacturers, providers and users of AI systems to ensure transpar - ency concerning the purpose, functionality, and data sources of AI-based processing.

383 CHAMBERS.COM

Powered by