Skip to content
ISGReporting ObligationComplianceBACS

ISG Reporting Obligation: What Swiss Companies Need to Know Now

19 February 2026|7 min read

Since April 2025, cyberattacks on critical infrastructure operators must be reported. Since October 2025, violations carry fines of up to CHF 100,000. We explain who is affected, what must be reported and how to prepare.

Over 260 mandatory reports reached the BACS (Federal Office for Cybersecurity) in the first twelve months. The ISG (Information Security Act) has required critical infrastructure operators to report cyberattacks within 24 hours since April 2025, and since October 2025 violations have been punishable by fines of up to CHF 100,000 against responsible individuals. The clock starts at discovery of the incident, not at your management team's next free slot. If you only work out who triggers the report once an incident is under way, half of the 24 hours is already gone.

Who Is Affected?

The reporting obligation covers 9 sectors with 27 subsectors: energy, drinking water, wastewater, transport, healthcare, banks, insurance, digital infrastructure and public administration. Suppliers and IT service providers working for these sectors can also be indirectly affected. Check against the BACS criteria list whether your company falls under the definition. When in doubt, report.

How the Reporting Process Works

The report must be filed within 24 hours of discovery, via the BACS Cyber Security Hub (security-hub.ncsc.admin.ch) or the general reporting form (report.ncsc.admin.ch). Required information includes the affected system, the type of attack and the immediate response measures taken. A detailed follow-up report with root cause analysis and an action plan must be submitted within 14 days. The report does not replace filing a complaint with the cantonal police.

Preparation: The Reporting Playbook

Prepare now, not after an incident. Create a reporting playbook with clear responsibilities. Define who files the initial report, who provides the technical analysis and who handles internal communications. Test the process in a tabletop exercise. Document your critical systems and their dependencies. This preparation takes one working day. A late report costs considerably more.

How MilesGuard Supports You

MilesGuard helps companies with ISG readiness assessments: we determine whether you are subject to the reporting obligation, create your reporting playbook and run a simulation exercise. This way you are prepared before an incident occurs.

Share:LinkedIn

More Posts

Related Services