Skip to content
Scheidegger Webpublishing Webpublishing, Switzerland
← All review articles

Switzerland and the Cyber Resilience Act: two timetables, one manufacturer

It is often said that the Cyber Resilience Act “does not concern Switzerland”. That is wrong twice over. A Swiss manufacturer falls under the Regulation as soon as its product is made available on the Union market, and Swiss law has already, since 1 April 2025, imposed a reporting duty that names software manufacturers expressly. Here are the two regimes, side by side, with their texts.

8 min read Texts verified on 1 August 2026

The argument one hears most often fits in a sentence: Switzerland is not in the internal market, therefore the Cyber Resilience Act does not concern it. The conclusion is wrong for two distinct reasons, and they are worth separating, because they call for different decisions.

The first lies in the European Regulation itself, which is indifferent to where the manufacturer sits and attentive to the market the product reaches. The second lies in Swiss law, which has already, since 1 April 2025, imposed a reporting duty whose list of addressees expressly names certain software manufacturers.

What Switzerland already requires

The duty to report cyberattacks against critical infrastructure entered into force on 1 April 2025. It was inserted into the Information Security Act by the Federal Act of 29 September 2023, and its implementing provisions sit in the Cybersecurity Ordinance of 7 March 2025.1

The mechanism is simple to describe. The authorities and organisations listed in the Act must ensure that cyberattacks on their IT resources are reported to the Federal Office for Cybersecurity.2 An attack must be reported where it jeopardises the functioning of the critical infrastructure concerned, where it has led to the manipulation or leakage of information, where it went undetected over an extended period, or where it is accompanied by blackmail, threats or coercion.3 The report is due within 24 hours of detection, and must be completed as soon as further information becomes available.4

Two features of this regime deserve to be known, because they are rarely reported.

The first is that whoever discharges the reporting duty is not required, in that context, to supply information that would expose them to criminal prosecution.5 The guarantee is explicit in the text, and it changes how a report is drafted.

The second is that the Act, in its version in force on 1 April 2025, attaches no penal provision to the duty: the text provides neither fine nor administrative penalty for a report omitted or filed late.6 That does not make the duty optional, but it sets the Swiss regime sharply apart from the European one, where breaches of the reporting obligations in Article 14 attract the Regulation’s highest fines.

The point almost nobody makes: software manufacturers are already caught

The Swiss list of addressees is long and reads like an inventory of critical infrastructure: energy, banks and insurers, listed hospitals, transport, telecommunications, cloud services with a seat in Switzerland, domain name registries, and services supporting the exercise of political rights.7

Its final entry is of another kind altogether. The Act also covers “manufacturers of hardware or software whose products are used by critical infrastructure”, provided the hardware or software has remote maintenance access, or serves to control and monitor technical systems and processes, or to safeguard public security.8

In other words: Switzerland already places a product-linked duty on manufacturers that are not themselves critical infrastructure. In principle, that is the same intuition as the Cyber Resilience Act’s, at a far more modest stage, and through reporting alone rather than through design requirements.

The Ordinance moreover provides quantified exemptions, which people forget to check before concluding that they are caught: universities with fewer than two thousand students are exempt, as are several categories of energy undertakings depending on the protection levels applicable to them.9

Finally, the duty does not stop at the border of one’s servers: it applies to cyberattacks that have an effect in Switzerland, even where the IT resources concerned are located abroad.10 A Swiss company whose infrastructure is hosted elsewhere escapes nothing.

What Switzerland does not yet have

On products themselves, by contrast, there is nothing. The Federal Council said so itself, in as many words, in its press release of 20 August 2025: there is in Switzerland practically no regulation on the cyber resilience of digital products.11

That same day, it instructed the defence department to prepare a draft for the consultation procedure, together with the departments responsible for communications and for economic affairs. The work falls to the Federal Office for Cybersecurity, with OFCOM and SECO, and the announced deadline is autumn 2026. The future legal bases are to lay down rules on security in the development and placing on the market of products with digital elements, to organise market surveillance, and to allow the import and distribution of insecure devices to be prohibited.12

Two elements of that release repay close reading.

The first is the parliamentary origin of the project: motion 24.3810, tabled by the Council of States’ Security Policy Committee, instructing the Federal Council to close the gap.13 The file is therefore not an isolated administrative initiative; it carries a mandate.

The second is how the release frames its alignment objective: the international context is to be taken into account, notably the European Regulation, and the legislation is to suit the Swiss economy while ensuring that internationally active Swiss companies are not burdened further by legal contradictions.14 The Federal Council thus treats product cyber resilience as a Swiss legislative project to be coordinated with the Union, not as a matter already settled by mutual recognition.

Why a Swiss manufacturer is already within the European Regulation’s scope

The Cyber Resilience Act takes no interest in the manufacturer’s nationality. It applies to products with digital elements made available on the Union market.15 A manufacturer established in Switzerland is therefore caught as soon as a product within scope is made available there, whether directly or through its distribution chain.

The Regulation in fact organises that situation in detail rather than ignoring it. It sets out the obligations of the authorised representative, of the importer and of the distributor, and provides for the cases in which an importer or distributor becomes subject to the manufacturer’s obligations.16

The clearest proof of that reach lies in the reporting machinery. Where a manufacturer has no main establishment in the Union, the Regulation itself designates the CSIRT to which reports must go, following a cascade: the Member State of the authorised representative; failing that, of the importer placing the largest number of its products on the market; failing that, of the distributor; failing that, the one where the largest number of its users are located.17 A rule written for manufacturers outside the Union is a rule that reaches them.

The two timetables, side by side

What matters is the gap between them.

On the European side, the reporting obligations in Article 14 apply from 11 September 2026, and the Regulation as a whole from 11 December 2027.18

On the Swiss side, the reporting duty tied to critical infrastructure has been in force since 1 April 2025, and the draft on the cyber resilience of products is only due to go out for consultation in autumn 2026.19 A consultation procedure is not a statute: it is followed by the dispatch, the parliamentary debates, the referendum period and entry into force.

A Swiss manufacturer exporting to the Union will therefore find itself, through 2026 and 2027, bound by complete European obligations while the Swiss text meant to dovetail with them does not yet exist. That is the most important practical consequence in this file, and it rests on no forecast: it can be read off the two timetables.

What follows, soberly

Three questions arise, in this order, and none of them requires waiting for the Swiss text.

The first is scope: are your products products with digital elements within the meaning of the Regulation, and are they made available on the Union market, including through a distributor you do not control?

The second is reporting, because it arrives first in both legal orders. A manufacturer may be subject both to the Swiss 24-hour duty and to the European chain of 24 hours, 72 hours and 14 days, with two different addressees and two different definitions of what triggers the report.

The third is the support period, which is the one thing that cannot be fixed after the fact: it is decided when the product is designed and disclosed when it is sold.

This review will follow the Swiss draft as it emerges, and will date every update. When the consultation opens, it will be published on the federal consultation portal: that is the document to read, not the commentary written about it.

Notes

  1. Federal Act of 18 December 2020 on Information Security (ISA), SR 128, as at 1 April 2025; Arts. 74a to 74f inserted by the Federal Act of 29 September 2023 (AS 2024 257; 2025 173; BBl 2023 84). Cybersecurity Ordinance of 7 March 2025 (OCyS), SR 128.51, Art. 1(d).

  2. ISA, Art. 74a(1).

  3. ISA, Art. 74d(a) to (d).

  4. ISA, Art. 74e(1) and (3). The 24-hour deadline is also stated by the Federal Office for Cybersecurity, “Information on the reporting obligation”.

  5. ISA, Art. 74e(4).

  6. Observation drawn from reading the consolidated text of the ISA as at 1 April 2025: Arts. 74a to 74f contain no penal provision, and the Act provides none elsewhere for this failure. For the later state of the law, refer to the version in force on the day of reading.

  7. ISA, Art. 74b(1)(a) to (t).

  8. ISA, Art. 74b(1)(u).

  9. OCyS, Art. 12(1).

  10. ISA, Art. 74b(3).

  11. Swiss Federal Council, press release of 20 August 2025, “Federal Council wants to strengthen the cyber resilience of digital products”.

  12. Same press release.

  13. Motion 24.3810, “Carrying out urgent and necessary cybersecurity checks”, Security Policy Committee of the Council of States, cited in the press release referred to above.

  14. Same press release, section on legislation in step with the international context. It may be noted that this text dates the European Regulation’s entry into force to 11 December 2024, whereas Art. 71(1) of the Regulation yields 10 December 2024.

  15. Regulation (EU) 2024/2847, Art. 2(1).

  16. Regulation (EU) 2024/2847, Art. 18 (authorised representatives), Art. 19 (importers), Art. 20 (distributors) and Art. 22 (other cases in which the manufacturers’ obligations apply).

  17. Regulation (EU) 2024/2847, Art. 14(7), third subparagraph, points (a) to (d).

  18. Regulation (EU) 2024/2847, Art. 71(2).

  19. ISA, Arts. 74a to 74f, in force since 1 April 2025; Federal Council press release of 20 August 2025 for the autumn 2026 deadline.

Texts cited

This review is not legal advice

The house builds and maintains websites, it does not practise law. What is written here is a reading of the texts, kept current and sourced, meant to let a decision-maker know what applies to them and from when. A particular situation, a dispute or a binding compliance exercise calls for a lawyer’s opinion.

Who keeps this review

This review is kept by the workshop that builds and maintains the house’s websites. Reading the texts is part of the trade: a delivered site has to stay compliant after delivery, and the deadlines discussed here are the ones the workshop applies to its own publications before writing about them.

Ask a specific question