Switzerland's consultation on a partial revision of the Telecommunications Act (FMG) in the area of security closed on 17 September 2026. The federal department UVEK, working through the regulator BAKOM, opened it on 27 May 2026. The draft sets out to create the legal basis for future-proof (cyber)security measures in the telecom sector, to strengthen the availability of emergency communications, and to improve youth and consumer protection. Cantons including Basel-Stadt, whose government dealt with the matter on 1 September, and Schwyz have responded, broadly welcoming the proposal.
The broad welcome is defensible. Parts of the package deserve support. Other parts hand the executive more discretion than the evidence in the public record justifies.
The strongest case for the revision
The case for acting is real. Telecom networks are the substrate for banking, health and government, and a failure there cascades. Voluntary measures have not stopped caller-ID spoofing, which is the entry point for much phone fraud. A small country with a handful of national operators has little margin for a single-vendor failure or a hostile-state dependency. If the law gives no authority to act before an incident, regulators can only respond after one. Legislating in calm conditions is better than improvising in a crisis.
What the draft proposes
According to the trade outlet Netzwoche's report on the proposal, the package has four main elements.
- Anti-spoofing. Providers could block numbers they suspect of misuse. The federal police (fedpol) and the Cyber Security Agency (BACS) would gain authority to block suspicious numbers and domain names. Reselling previously allocated numbers would be restricted.
- Supplier diversification. Providers would have to source equipment from several suppliers, to reduce single-vendor dependency.
- High-risk supplier controls. According to blue News, the Federal Council would be able to prohibit the procurement, installation and operation of equipment from suppliers it deems problematic for Swiss security or controlled by a foreign state posing geopolitical risk.
- Operations in Switzerland. Netzwoche reports that the largest operators and full MVNOs would have to run their network and security operations centres exclusively in Switzerland.
BAKOM's explanatory report accompanies the draft and is the document to read for the legal detail. The same package also covers incident reporting, device security, emergency communications, youth and consumer protection, and the end of copper twisted-pair lines in connection networks.
Where the draft is strong
Anti-spoofing is the clearest win. It targets a specific, measurable harm, and operator-level blocking is a narrow tool. The design question is process. Number and domain blocking by authorities should come with a stated legal basis, a duty to notify the affected holder, and a fast route to challenge a block. A domain block that catches a legitimate service is a speech and commerce problem, not just a security one. The consultation is the right moment to write those safeguards into the text instead of leaving them to ordinance.
Emergency-communication resilience is also well grounded. Switzerland already tried one version of this and then moderated it. According to SAVE's account of the Telecommunications Services Ordinance amendment, the Federal Council first proposed requirements covering power outages of up to three days. Industry criticised them in consultation as too complex and difficult to implement. The final approach requires emergency power at key locations so that emergency calls keep working for at least four hours during an outage from 2031, with other services following from 2034. The government will evaluate further hardening by the end of 2027. This is how consultation should work. The proposal was cut to what was achievable, and the harder questions were deferred to evidence.
Where the draft overreaches
The vendor-ban power is the part that needs discipline. The stated criteria are open-ended: a supplier "problematic for Switzerland's security" or "under the influence of a foreign state posing geopolitical risk." Neither phrase has a published test. An operator that has built a network around a vendor needs to know in advance what triggers a prohibition, who decides, what evidence is required, whether an affected vendor can contest it, and what transition period and compensation apply. Without those answers, the power itself becomes a business risk. It pushes up capital costs for networks that Switzerland wants to see invested in 5G and fibre.
The EU's approach in its 5G security toolbox is a useful comparison. Risk-based criteria, published in advance, give operators something to plan against. Switzerland should write comparable criteria into the statute or require them in the implementing ordinance, and add judicial review.
The mandatory multi-vendor sourcing rule has the same problem. Diversification is sensible in principle. A hard obligation, though, can force a small operator to buy from a second supplier at higher cost and with a thinner support relationship. That can make a network less secure, not more. A comply-or-explain standard tied to a risk assessment would achieve the resilience goal without mandating a purchasing pattern.
The requirement to keep network and security operations centres in Switzerland is the weakest element. Physical location is a poor proxy for security. Many cybersecurity functions benefit from follow-the-sun staffing and shared threat intelligence across borders. A location mandate raises costs, especially for the smaller full MVNOs, and it points toward the data-localisation logic that EFF's September analysis of digital sovereignty cautions about. EFF warns that sovereignty frameworks can be used to enable censorship and surveillance, and argues that sovereignty should centre user autonomy, encryption and interoperability. Swiss lawmakers should ask for the security case for localisation, and what it adds beyond access controls, audit rights and incident reporting.
What to watch next
The next step is the Federal Council's consultation report and a dispatch to Parliament. Three tests will show whether the revision is proportionate:
- Whether vendor-ban criteria are published and reviewable.
- Whether the location and multi-vendor mandates survive in their current form after operator responses.
- Whether anti-spoofing powers carry notice and appeal rights.
Switzerland has a good record of trimming proposals after industry input, as the emergency-power episode shows. It should do so again here, and keep the useful core: spoofing defences, resilient emergency calls and clear incident reporting.