27.02.2025 - The reporting obligation for cyberattacks on critical infrastructure will be introduced in the first half of 2025. To show the affected organizations how to act correctly in the event of a cyberattack, the National Cyber Security Centre (NCSC) is organizing a series of online events on the topic of "reporting obligation for cyberattacks on critical infrastructure".

The security and stability of our critical infrastructure is of the utmost importance. The introduction of a mandatory reporting obligation for cyberattacks on critical infrastructure in the first half of 2025 will provide the National Cyber Security Centre (NCSC) with a better overview of cyberattacks carried out in Switzerland and the methods used. It is therefore essential that operators of critical information infrastructure report cyber incidents promptly and correctly.
In the online events, the NCSC explains the basics of the reporting obbligation and provides operational advice on how to implement it. The principles according to which critical infrastructures are subject to the reporting obbligation and which attacks must be reported are presented. Subsequently, it is explained in concrete terms which information a report must contain and by when it should be submitted. It is also explained where the report can be submitted.
Information on the online events
All events will take place via MS Teams.
The first part of the event will be recorded and published with subtitles in German, French, Italian and English on the NCSC YouTube channel.
The subsequent question and answer session, which takes place towards the end of the online event, will not be published.
Online events for communes:
Date | Time | Language | Link to registration |
13.03.2025 | 12.00 – 13.00 | German | Registration |
27.03.2025 | 12.00 – 13.00 | French | Registration |
Online events for companies:
Date | Time | Language | Link to registration |
20.03.2025 | 12.00 – 13.00 | German | Registration |
Parliament has decided to introduce a reporting obligation for cyberattacks on critical infrastructure. The implementation of the reporting obligation will be specified in the Cybersecurity Ordinance (CSO). The Cybersecurity Ordinance will be submitted to the Federal Council in the first quarter of 2025. The introduction of the reporting requirement for cyber attacks on critical infrastructure is expected to take place in the first half of 2025. Information will be provided immediately following the Federal Council's decision.
Further information on the reporting requirement:
Information on the reporting obbligation
Last modification 27.02.2025