Switzerland Switzerland BAKOM telecom regulation

Switzerland's Telecom Security Revision Is Sound on Spoofing and Resilience, but the Vendor-Ban Power Needs Tighter Guardrails

Bern's FMG security revision closed consultation on 17 September 2026. Its anti-spoofing and emergency-call measures are proportionate; open-ended vendor bans and location mandates are not.

Swiss FMG Security Revision at a Glance People of Internet Research · Switzerland 4 hours Emergency power duration Minimum for emergency calls in out… 2031 Emergency power starts Emergency calls first, other servi… 17 Sep Consultation closed Opened 27 May 2026. peopleofinternet.com
Swiss FMG Security Revision at a Glanc… People of Internet Research · Switzerland 4 hours Emergency power duration 2031 Emergency power starts 17 Sep Consultation closed peopleofinternet.com

Key Takeaways

Switzerland's consultation on a partial revision of the Telecommunications Act (FMG) in the area of security closed on 17 September 2026. The federal department UVEK, working through the regulator BAKOM, opened it on 27 May 2026. The draft sets out to create the legal basis for future-proof (cyber)security measures in the telecom sector, to strengthen the availability of emergency communications, and to improve youth and consumer protection. Cantons including Basel-Stadt, whose government dealt with the matter on 1 September, and Schwyz have responded, broadly welcoming the proposal.

The broad welcome is defensible. Parts of the package deserve support. Other parts hand the executive more discretion than the evidence in the public record justifies.

The strongest case for the revision

The case for acting is real. Telecom networks are the substrate for banking, health and government, and a failure there cascades. Voluntary measures have not stopped caller-ID spoofing, which is the entry point for much phone fraud. A small country with a handful of national operators has little margin for a single-vendor failure or a hostile-state dependency. If the law gives no authority to act before an incident, regulators can only respond after one. Legislating in calm conditions is better than improvising in a crisis.

What the draft proposes

According to the trade outlet Netzwoche's report on the proposal, the package has four main elements.

BAKOM's explanatory report accompanies the draft and is the document to read for the legal detail. The same package also covers incident reporting, device security, emergency communications, youth and consumer protection, and the end of copper twisted-pair lines in connection networks.

Where the draft is strong

Anti-spoofing is the clearest win. It targets a specific, measurable harm, and operator-level blocking is a narrow tool. The design question is process. Number and domain blocking by authorities should come with a stated legal basis, a duty to notify the affected holder, and a fast route to challenge a block. A domain block that catches a legitimate service is a speech and commerce problem, not just a security one. The consultation is the right moment to write those safeguards into the text instead of leaving them to ordinance.

Emergency-communication resilience is also well grounded. Switzerland already tried one version of this and then moderated it. According to SAVE's account of the Telecommunications Services Ordinance amendment, the Federal Council first proposed requirements covering power outages of up to three days. Industry criticised them in consultation as too complex and difficult to implement. The final approach requires emergency power at key locations so that emergency calls keep working for at least four hours during an outage from 2031, with other services following from 2034. The government will evaluate further hardening by the end of 2027. This is how consultation should work. The proposal was cut to what was achievable, and the harder questions were deferred to evidence.

Where the draft overreaches

The vendor-ban power is the part that needs discipline. The stated criteria are open-ended: a supplier "problematic for Switzerland's security" or "under the influence of a foreign state posing geopolitical risk." Neither phrase has a published test. An operator that has built a network around a vendor needs to know in advance what triggers a prohibition, who decides, what evidence is required, whether an affected vendor can contest it, and what transition period and compensation apply. Without those answers, the power itself becomes a business risk. It pushes up capital costs for networks that Switzerland wants to see invested in 5G and fibre.

The EU's approach in its 5G security toolbox is a useful comparison. Risk-based criteria, published in advance, give operators something to plan against. Switzerland should write comparable criteria into the statute or require them in the implementing ordinance, and add judicial review.

The mandatory multi-vendor sourcing rule has the same problem. Diversification is sensible in principle. A hard obligation, though, can force a small operator to buy from a second supplier at higher cost and with a thinner support relationship. That can make a network less secure, not more. A comply-or-explain standard tied to a risk assessment would achieve the resilience goal without mandating a purchasing pattern.

The requirement to keep network and security operations centres in Switzerland is the weakest element. Physical location is a poor proxy for security. Many cybersecurity functions benefit from follow-the-sun staffing and shared threat intelligence across borders. A location mandate raises costs, especially for the smaller full MVNOs, and it points toward the data-localisation logic that EFF's September analysis of digital sovereignty cautions about. EFF warns that sovereignty frameworks can be used to enable censorship and surveillance, and argues that sovereignty should centre user autonomy, encryption and interoperability. Swiss lawmakers should ask for the security case for localisation, and what it adds beyond access controls, audit rights and incident reporting.

What to watch next

The next step is the Federal Council's consultation report and a dispatch to Parliament. Three tests will show whether the revision is proportionate:

Switzerland has a good record of trimming proposals after industry input, as the emergency-power episode shows. It should do so again here, and keep the useful core: spoofing defences, resilient emergency calls and clear incident reporting.

Sources & Citations

  1. BAKOM explanatory report on the FMG security revision
  2. Basel-Stadt government resolution P260799 (response to UVEK)
  3. blue News: Federal Council on cyber-attack protection
  4. Netzwoche: proposed telecom cybersecurity measures
  5. SAVE: emergency power requirements for mobile networks
  6. EFF: Digital Sovereignty: What It Is, What It Could Be