On 25 September 2026 the Federal Council tasked the Federal Department of Defence, Civil Protection and Sport (VBS) with drafting a new, standalone Federal Cybersecurity Act (CSG). A consultation draft is due by June 2027, according to the Federal Council's announcement. The act would fold three parliamentary motions into one law: cyber resilience of products with digital elements (Mo. 24.3810), protection of especially important digital data (Mo. 23.3002), and the role of hosting and cloud providers (Mo. 25.3011). The Telecommunications Act (FMG) is left out. The Federal Council says sectoral laws such as the FMG remain in force alongside the new act.
The case for the Federal Council's approach
The strongest argument for regulating here is that insecure products and concentrated infrastructure impose costs that buyers cannot see. A consumer cannot audit a router's update policy. A small firm cannot assess its cloud host's incident handling. Market discipline works poorly when the risk is invisible until it materialises, and Switzerland has watched the EU adopt the Cyber Resilience Act (CRA) for exactly that reason. Doing nothing would also have a cost. Swiss manufacturers selling into the EU would face CRA obligations anyway, and Swiss buyers would lack a domestic enforcement counterpart.
What is good about the design
Three choices deserve credit. First, a single act instead of three separate bills reduces fragmentation. Companies that wear several hats, such as device maker, hosting customer and data holder, will not have to read three statutes with three definitions of an incident.
Second, the stated aim is alignment with the EU. According to PCtipp's report, the law is modelled on the CRA and is meant to ensure that "no additional compliance burden arises" for internationally active firms already compliant with EU rules. For a small, export-dependent market this is the most important design principle. A Swiss-specific variant of product security rules would force manufacturers to choose between serving a 9-million-person market and keeping their EU conformity process simple. Many would simply stop selling in Switzerland.
Third, the planned integration of existing cyberattack reporting duties into the same framework addresses a real complaint from industry, namely multiple reporting channels for one incident.
Where the risks lie
The first risk is scope creep in the data and cloud elements. "Especially important digital data" and "duties for hosting providers" are open-ended phrases. A law that imposes security obligations on every hosting provider, regardless of size or customer base, would raise costs for the small Swiss providers that the sovereignty debate claims to support. Proportionality means tiering duties by systemic importance, not by the label "cloud." The EFF's September 2026 analysis of digital sovereignty warns that sovereignty framings can drift toward state control of infrastructure, and that the better route is open standards, strong encryption and interoperability. Those are tests the CSG draft should be held to.
The second risk is the seam with the telecom regime. The FMG revision opened for consultation on 27 May 2026 would require telecom operators to source equipment from different suppliers. It would also let the Federal Council prohibit equipment from suppliers deemed problematic for Swiss security or under the influence of a foreign state posing a geopolitical risk, as the Federal Council's May announcement describes. The Federal Office of Communications (BAKOM) would carry those telecom duties. Meanwhile the new act would be drafted by a different department, with the Federal Office for Cybersecurity as the evident technical lead.
The split is defensible. Telecom networks are licensed, concession-based infrastructure with a long supervisory history, and BAKOM knows them. But operators are also buyers of products with digital elements and customers of hosting and cloud services. A network operator could therefore face CSG product requirements on its suppliers, FMG diversification duties on those same suppliers, and two reporting lines for one incident. Which law prevails when a supplier is compliant under one and restricted under the other? The announcement does not say.
What a proportionate draft should contain
- A conflict rule. The CSG should state expressly how it relates to the FMG, so that an operator that satisfies the telecom rules is not audited twice for the same equipment.
- Tiered obligations. Duties on hosting and cloud providers should scale with size and systemic role, with lighter requirements for small providers.
- EU equivalence by default. Conformity with CRA standards should be presumed to satisfy the Swiss requirements, with mutual recognition pursued actively.
- One reporting channel. A single notification point for incidents across both regimes.
- Evidence of need. The consultation draft should publish a regulatory impact assessment with cost estimates for small firms, not only for large ones.
The bottom line
Bern is making the right structural choice by writing one act and tying it to EU rules. The weak point is not the CSG itself but its relationship to the telecom revision, which is already well advanced. The draft is not due until June 2027, so the telecom supplier rules may be settled first. If so, the new act will have to fit around them rather than the reverse. The Federal Council should require the VBS to coordinate explicitly with the telecom file now, while both texts can still change. Otherwise operators will find the gaps in practice, through duplicated audits and conflicting supplier decisions.