Switzerland's Federal Council instructed the Department of Defense on September 25, 2026, to draft a preliminary consultation bill for a standalone federal cybersecurity law, known as the Cybersicherheitsgesetz (CSG). The draft text is due by June 2027 and will take the European Union's Cyber Resilience Act as its reference point.
The Federal Council said the aim is to reinforce national cybersecurity by grouping three separate parliamentary interventions into a single act. Those interventions concern the cyber-resilience of products with digital elements, the protection of especially important digital data, and the responsibilities of hosting providers. The Executive had initially considered folding these reforms into the existing Information Security Act, but opted instead for a dedicated statute.
What the new law will cover
The Information Security Act will continue to regulate the information security of federal authorities, the Federal Council said, while the new CSG will set binding requirements for manufacturers, importers and traders of software and hardware products. The law is intended to create legal bases for market surveillance and to allow authorities to prohibit the distribution of insecure products.
It will also introduce specific cybersecurity obligations tied to the protection of important digital data and for hosting and cloud providers, including cooperation duties and requirements to defend against cyberthreats. The Federal Council said the approach is meant to allow Switzerland to address specific issues, such as open-source software, more effectively and to ensure coherent cybersecurity regulation toward third parties.
The measure builds on an existing reporting duty: since April 2025, operators of critical infrastructure have been required to report cyberattacks, a rule overseen by the Federal Office for Cybersecurity (BACS).
No new rules for crypto
The draft does not extend to the regulation of bitcoin, privacy-focused coins, or anonymous account operations. Those areas remain governed separately by the Anti-Money Laundering Act and the frameworks overseen by the Financial Market Supervisory Authority, FINMA.
The plan has drawn criticism from figures in the Bitcoin and open-source communities. Scott Wolfe, coordinator of the Bitcoin Circular Economy Federation, called the initiative "a terrible idea for privacy, individual and family security, and the Swiss brand."
Developer Markus Eicher was more pointed, describing the bill as little more than Switzerland following its European friends with the Cyber Resilience Act. "It is more an act of appeasement than an idea of its own. It will do no good, it will only increase the bureaucratic burden for SMEs working with FOSS," he said.
The consultation draft is expected to be delivered by June 2027, after which it will move through Switzerland's standard legislative review process before any parliamentary vote.




