Skip to content
Scheidegger Webpublishing Webpublishing, Switzerland

Digital regulation

Review of digital product and data regulation

The regulation of digital products is changing in kind: it no longer targets only the processing of data, it targets the product itself, how it is designed, how it is updated and how its flaws are disclosed. This review follows that shift text by text, deadline by deadline, and never asserts what it cannot show.

Review RSS feed

The method, so it can be held against us

  1. 01

    Only official texts and the authorities that apply them count as sources: the Official Journal of the European Union, Fedlex, the European Commission, ENISA, the Swiss Federal Council, the OFCS, the FDPIC. A law firm’s commentary, an agency guide or an advisory note are not sources: they are readings, and we produce one of our own.

  2. 02

    Every statement of fact carries a note reference, and every note points to the precise article, annex or recital. A note pointing at a whole text points at nothing.

  3. 03

    Every article displays the date on which its texts were reopened and read again. The law cited here moves, and an article of law with no verification date cannot be dated, so it cannot be believed.

  4. 04

    What could not be verified is left out, however widely it is repeated elsewhere. A later correction is dated and flagged, never slipped quietly into the old text.

  1. 15 min read Texts verified on 1 August 2026

    The Cyber Resilience Act: what the Regulation requires and when it applies

    Regulation (EU) 2024/2847 subjects products with digital elements to cybersecurity requirements and CE marking. The timeline, the obligations, and who is caught by it.

    Regulation (EU) 2024/2847 (Cyber Resilience Act), OJ L of 20.11.2024 · Directive (EU) 2022/2555 (NIS 2) · Regulation (EU) 2016/679 (GDPR)

  2. 8 min read Texts verified on 1 August 2026

    Switzerland and the Cyber Resilience Act: two timetables, one manufacturer

    Switzerland has no CRA equivalent, yet already requires some software makers to report cyberattacks within 24 hours. What applies to a Swiss manufacturer selling into the EU, and from when.

    Information Security Act (ISA), SR 128, as at 1 April 2025 · Cybersecurity Ordinance of 7 March 2025 (OCyS), SR 128.51 · Swiss Federal Council, press release of 20 August 2025 on the cyber resilience of digital products · Regulation (EU) 2024/2847 (Cyber Resilience Act)

And for what already applies

The regulation file sets out, question by question, what a website must comply with today in Switzerland, the European Union and elsewhere. The review follows the texts that are going to change it.

Open the regulation file

This review is not legal advice

The house builds and maintains websites, it does not practise law. What is written here is a reading of the texts, kept current and sourced, meant to let a decision-maker know what applies to them and from when. A particular situation, a dispute or a binding compliance exercise calls for a lawyer’s opinion.