# Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG)

> Since 1 April 2025, the authorities and organisations individually listed in Art. 74b of the Information Security Act (ISG, SR 128) must report cyberattacks on their IT resources to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery (Art. 74a and 74e ISG). Covered are 21 categories of critical infrastructure named in the act, from universities and energy suppliers to banks and hospitals to cloud providers headquartered in Switzerland; the Federal Council can exempt bodies with only minor impact from the reporting obligation (Art. 74c ISG).

- Type: Act, Statutory
- Scope: Switzerland
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/isg_meldepflicht
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does ISG reporting obligation apply to you?

- Activity: Critical infrastructure (Likely applies): You operate or manage critical infrastructure - Art. 74b ISG lists 21 categories of authorities and companies for this; if you are covered, you must report cyberattacks to BACS within 24 hours, unless an exemption under Art. 74c ISG applies.
- Industry: Energy (Likely applies): Companies active in energy generation, trading, metering or control under the Energy Act belong to the reporting categories expressly named in Art. 74b(1)(d) ISG - the only exemption is for holders of licences under the Nuclear Energy Act.
- Industry: Financial services (Applies): Companies subject to the Banking Act, the Insurance Supervision Act or the Financial Market Infrastructure Act are named individually as subject to the reporting obligation under Art. 74b(1)(e) ISG.
- Industry: Healthcare (Recommend individual review): Healthcare institutions listed on a cantonal hospital list, as well as approved medical laboratories, fall under Art. 74b(1)(f-g) ISG; you should check case by case whether your specific institution is on a hospital list or holds a corresponding laboratory licence.
- Industry: Software / SaaS (Recommend individual review): If you provide cloud computing, search engines, digital security or trust services, or data centres headquartered in Switzerland, you belong to the reporting providers named in Art. 74b(1)(t) ISG - this does not apply to every software/SaaS company.

## Exceptions

- The Federal Council exempts authorities and organisations from the reporting obligation if malfunctions triggered by cyberattacks have only minor effects on the functioning of the economy or the wellbeing of the population (Art. 74c ISG).
- If a body subject to the reporting obligation also carries out activities not covered by Art. 74b(1) ISG, there is no reporting obligation for cyberattacks that affect exclusively those other activities (Art. 74b(2) ISG).

## Obligations

- Ensure that cyberattacks on one's own IT resources can be reported to BACS (Art. 74a(1) ISG).
- Report reportable cyberattacks within 24 hours of their discovery; if not all details are yet known, the report must be supplemented as soon as new information becomes available (Art. 74e(1) and (3) ISG).
- Include in the report details on the reporting body, the type and execution of the cyberattack, its effects, measures taken and, to the extent known, further planned action (Art. 74e(2) ISG).
- Submit the report via the secure electronic transmission system provided by BACS (Art. 74f(1) ISG).

## Evidence

- Confirmation of report or log from BACS's electronic reporting system.
- Internal documentation of incident detection and escalation, showing the relevant discovery time for the 24-hour deadline (Art. 74e ISG).

## Deadlines

- 1 April 2025: The reporting obligation for cyberattacks on critical infrastructure (Art. 74a-74f ISG) enters into force (AS 2024 257; AS 2025 173; BBl 2023 84).

## Penalties

The reporting obligation provisions themselves (Art. 74a-74f ISG) contain no penalty provision of their own. Per BACS (FAQ on the reporting obligation), BACS can issue a ruling with a threat of penalty if non-reporting is established; in the case of continued non-compliance, a complaint to the competent cantonal prosecution authorities is possible, which are responsible for prosecuting and adjudicating violations of BACS rulings. A quantified fine amount, and a date from which fines can specifically be imposed, could not be evidenced in this research either in the ISG full text or on the BACS pages reached (see unsicher).

## Frequently asked questions

**Who exactly is subject to the reporting obligation?**
Art. 74b(1) ISG lists 21 categories (letters a-u) by name: universities; federal, cantonal and municipal authorities as well as inter-cantonal/municipal organisations; organisations with tasks in security/rescue, drinking water supply, wastewater treatment, waste disposal; companies in energy generation/trading/metering/control (except nuclear power plant licence holders); companies under the Banking Act, the Insurance Supervision Act or the Financial Market Infrastructure Act; healthcare institutions on cantonal hospital lists; approved medical laboratories; companies with a medicinal product licence; social insurance organisations; the Swiss Broadcasting Corporation; news agencies of national significance; registered postal service providers; railway, cable-car, trolleybus, bus and shipping companies with a concession; civil aviation companies; companies under the Maritime Navigation Act; companies for essential goods; registered telecommunications service providers; registrars/registry operators of internet domains; providers of services for exercising political rights; providers of cloud computing, search engines, digital security/trust services and data centres headquartered in Switzerland; and manufacturers of hardware/software able to remotely maintain critical infrastructure.

**From when does the 24-hour deadline run?**
From the discovery of the cyberattack by the reporting authority or organisation (Art. 74e(1) ISG). If information is still missing at that point, the report must be supplemented as soon as new information becomes available (Art. 74e(3) ISG).

**What does BACS do with the reported data?**
Per Art. 74a(4) ISG, the reporting obligation serves exclusively to enable BACS to detect attack patterns on critical infrastructure at an early stage, warn other potentially affected parties, and recommend suitable prevention and defence measures to them.

**Does the ISG reporting obligation replace sector-specific reporting obligations?**
No. Depending on the sector, additional reporting or information obligations may exist, for example for electricity supply operators under the ICT Minimum Standard per the StromVV. The ISG reporting obligation applies in addition.

## Open points of the research

- The statement given in the brief, 'fines have been possible since 1 October 2025', could not be evidenced either in the ISG full text (Art. 74a-74f contain no penalty provision of their own) or on the BACS pages reached (reporting obligation homepage, FAQ), and is therefore not adopted as fact.
- The Cybersecurity Ordinance (CSV), which per BACS regulates details of the reporting obligation and exemptions under Art. 74c ISG, was not read in full text in this research; the SR number and exact content of the CSV are not confirmed.
- The simplified formula of 'nine sectors' of critical infrastructure used on bacs.admin.ch does not match the exhaustive list of 21 letters (a-u) in Art. 74b(1) ISG; for this file, the statutory list was used as authoritative.

## Sources

- [Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f](https://www.fedlex.admin.ch/eli/cc/2022/232/de), Bundeskanzlei / Fedlex, retrieved 24 September 2026
- [Meldepflicht für Cyberangriffe auf kritische Infrastrukturen](https://www.bacs.admin.ch/de/meldepflicht), Bundesamt für Cybersicherheit (BACS), retrieved 24 September 2026
- [FAQ zur Meldepflicht](https://www.bacs.admin.ch/de/faq-meldepflicht), Bundesamt für Cybersicherheit (BACS), retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
