What Bern actually decided
The Swiss Federal Chancellery's BOSS proof-of-concept study, concluded on 2 September 2026, found that an open-source browser-based workplace is "in principle, suitable for key standard processes" of the federal administration. The study also acknowledges "technical, operational and organisational hurdles" to widespread productive use (Federal Chancellery). On that basis the Chancellery is launching a programme to put around 3,000 employees on openDesk, the suite maintained by Germany's ZenDiS, by the end of 2027. Press coverage puts the first phase at roughly CHF 9 million. That is a reported figure we could not confirm on the Chancellery's study page.
The 3,000 seats are about 7% of the central administration's workstations (ITPro). The study itself involved 172 federal test users. It rated document editing, file storage, email and calendar positively. Large-scale video conferencing showed technical limits and needs "significant adaptations and security work", according to press reports of the study.
This is not a Microsoft exit. It runs alongside Microsoft 365, which the federal administration finished rolling out in 2023.
The strongest case for the move
The sovereignty argument deserves a fair hearing. In November 2025 privatim, the conference of Swiss data protection officers, resolved that outsourcing particularly sensitive or legally confidential personal data to SaaS offerings from large international providers is impermissible for public authorities in most cases. It noted that US providers can be compelled under the 2018 CLOUD Act to hand customer data to US authorities. It added that such services are acceptable only if the authority encrypts the data itself and the provider has no access to the key (privatim).
That is a coherent legal position. A Swiss ministry holding Federal Council dossiers has real reason to worry that a foreign court order, or US surveillance law such as FISA 702, could reach data stored in a Swiss data centre. Contractual promises from a provider cannot override a statute that binds that provider. For the narrow category of state secrets and confidential files, the case for a controllable alternative is strong. Resilience adds to it: the Chancellery itself says the tested solution could contribute to an emergency fallback if Microsoft 365 goes down.
Why the pilot framing is the right call
The pro-innovation objection to "sovereign cloud" projects is that they tend to become expensive, slow substitutes for products people already use. Switzerland's design avoids most of that trap, for three reasons.
- It is scoped to the sensitive tail. The first wave targets staff who handle the most sensitive material. It does not try to move the whole administration for ideological reasons.
- It tests before it scales. The study found real gaps, notably in video conferencing, and the programme does not pretend otherwise. A procurement that publishes its weaknesses is more credible than one that does not.
- It builds on shared work. openDesk is developed by ZenDiS, and Bern is collaborating with Schleswig-Holstein, which already runs it. Swiss money is not funding a bespoke fork.
The broader lesson is that data-flow risk is better handled by classifying data and matching it to an architecture than by blanket bans. Privatim's own encryption condition points that way. Customer-held keys on a commercial service, or open-source software on infrastructure the state controls, are two tools for different data classes. Neither is a general answer.
Where the risks lie
There are three. First, scope creep: if "digital sovereignty" becomes a mandate to replace productivity software across all of government, the costs and usability losses will fall on civil servants and on the public services they deliver. Second, security is not automatic. Self-hosted or domestically hosted software still needs patching, monitoring and skilled staff, and the Chancellery's own caveat about security work for video conferencing shows this. Third, sovereignty claims should be measured. If the pilot cannot show that exposure to foreign legal compulsion fell for the data it covers, and at what cost per seat, it will have bought symbolism.
The other half of the evidence is interoperability. A federal worker who must exchange documents with cantonal authorities, businesses and foreign counterparts that use Microsoft formats will judge openDesk on friction, not on principle. Pilot metrics should report that friction honestly.
What to watch
The useful questions for 2027 are concrete. Which categories of federal data move to openDesk, and which stay on Microsoft 365 with encryption controls? What did the 3,000-seat rollout cost per user against the licences it displaced or complemented? And did the video conferencing gap close? Parliament and the Federal Audit Office are the natural places to ask.
Switzerland has chosen a modest, testable response to a real legal conflict between US extraterritorial access powers and Swiss confidentiality duties. That is more defensible than a ban and more honest than assuming the problem does not exist. Its value depends on keeping it a measured hedge, with published results, rather than a slogan.