Die Schweiz hat seit dem 1. April 2025 erstmals eine allgemeine, sektorübergreifende Meldepflicht für Cyberangriffe: Betreiberinnen kritischer Infrastrukturen müssen erhebliche Angriffe innert 24 Stunden nach Entdeckung dem Bundesamt für Cybersicherheit (BACS) melden. Grundlage sind die neuen Artikel 74a ff. des Informationssicherheitsgesetzes (ISG) und die Cybersicherheitsverordnung. Seit dem 1. Oktober 2025 ist die Schonfrist vorbei: Wer vorsätzlich nicht meldet, riskiert eine Busse bis CHF 100'000 – adressiert an die verantwortliche Person, nicht an die Firma.
Wen betrifft die Pflicht?
Der Kreis ist breiter, als viele denken: Neben Energie- und Wasserversorgung, Spitälern, Transportunternehmen, Rechenzentren und Cloud-Anbietern gehören ausdrücklich auch Kantons- und Gemeindeverwaltungen dazu. Für viele Gemeinden ist das die erste harte Cyber-Rechtspflicht überhaupt – und sie gilt unabhängig von der Grösse der Verwaltung.
Was ist meldepflichtig?
Meldepflichtig sind Angriffe mit grossem Schadenspotenzial: wenn die Funktionsfähigkeit der Infrastruktur gefährdet ist, Daten manipuliert wurden oder abgeflossen sind, oder wenn der Angriff mit Erpressung verbunden ist – der klassische Verschlüsselungstrojaner erfüllt das praktisch immer. Wichtig: Die 24-Stunden-Frist beginnt mit der Entdeckung, nicht mit dem forensischen Schlussbericht. Eine unvollständige Erstmeldung ist ausdrücklich vorgesehen; für die Vervollständigung bleiben 14 Tage.
Die erste Bilanz
Nach sechs Monaten zog das BACS Ende September 2025 Bilanz: 164 Meldungen gingen ein, am häufigsten zu DDoS-Angriffen (18%), Hacking (16%) und Ransomware (12%). Das Amt zeigte sich zufrieden – die Meldungen kamen fristgerecht, und der Informationsaustausch über den Cyber Security Hub funktioniert. Für die Gemeldeten hat das einen direkten Nutzen: Das BACS unterstützt bei der Bewältigung und warnt andere Betreiber vor denselben Angriffsmustern.
Was heisst das für Ihre Organisation?
1. Klären, ob Sie meldepflichtig sind – schriftlich und nachvollziehbar. Wer 2026 noch nicht weiss, ob er in den Geltungsbereich fällt, sollte diese Prüfung nachholen, bevor die Behörde von sich aus anklopft.
2. Meldeweg vorbereiten: Wer meldet, mit welchen Informationen, über welchen Kanal? Das gehört in den Incident-Response-Plan und auf die Notfallkarte – um 2 Uhr nachts sucht niemand mehr Formulare.
3. Erkennen können: Eine 24-Stunden-Frist setzt voraus, dass man Angriffe überhaupt bemerkt. Logging, Alarmierung und klare interne Meldewege sind die eigentliche Hausaufgabe hinter der Meldepflicht.
4. Auch ohne Pflicht melden: Organisationen ausserhalb des Geltungsbereichs können freiwillig melden – und profitieren vom selben Unterstützungs- und Warnnetz. Daneben gilt weiterhin die separate Meldepflicht des revDSG an den EDÖB bei Datensicherheitsverletzungen mit hohem Risiko.
Fazit
Die Meldepflicht ist kein Papiertiger – die Sanktionen sind scharf, und die erste Bilanz zeigt, dass das System gelebt wird. Wer Meldewege, Zuständigkeiten und Erkennung jetzt sauber regelt, erfüllt nicht nur eine Pflicht, sondern ist im Ernstfall schlicht schneller handlungsfähig.
Quellen
Since 1 April 2025, Switzerland has for the first time had a general, cross-sector reporting obligation for cyberattacks: operators of critical infrastructures must report significant attacks to the Federal Office for Cybersecurity (NCSC/BACS) within 24 hours of discovery. The legal basis is the new Articles 74a ff. of the Information Security Act (ISG) and the Cybersecurity Ordinance. Since 1 October 2025 the grace period is over: anyone who deliberately fails to report risks a fine of up to CHF 100,000 – addressed to the responsible person, not the company.
Who is covered by the obligation?
The circle is wider than many think: alongside energy and water supply, hospitals, transport companies, data centres and cloud providers, it explicitly includes cantonal and municipal administrations. For many municipalities this is the first hard cyber legal obligation ever – and it applies regardless of the administration's size.
What must be reported?
Reportable attacks are those with major damage potential: when the functioning of the infrastructure is at risk, data has been manipulated or exfiltrated, or when the attack is combined with extortion – the classic ransomware trojan practically always qualifies. Important: the 24-hour deadline starts with discovery, not with the final forensic report. An incomplete initial report is explicitly provided for; 14 days remain to complete it.
The first review
After six months, the NCSC took stock at the end of September 2025: 164 reports were received, most frequently concerning DDoS attacks (18%), hacking (16%) and ransomware (12%). The office was satisfied – reports arrived on time, and information exchange via the Cyber Security Hub works. For those who report there is a direct benefit: the NCSC supports the response and warns other operators about the same attack patterns.
What does this mean for your organisation?
1. Clarify whether you are subject to the obligation – in writing and traceably. Anyone who still does not know in 2026 whether they fall within scope should complete this check before the authority comes knocking on its own.
2. Prepare the reporting path: who reports, with which information, via which channel? That belongs in the incident response plan and on the emergency card – at 2 a.m. nobody wants to search for forms.
3. Be able to detect: a 24-hour deadline presupposes that attacks are noticed at all. Logging, alerting and clear internal reporting channels are the real homework behind the reporting obligation.
4. Report even without an obligation: organisations outside the scope can report voluntarily – and benefit from the same support and warning network. In addition, the separate revFADP obligation to notify the FDPIC of data security breaches with high risk continues to apply.
Conclusion
The reporting obligation is no paper tiger – the sanctions are sharp, and the first review shows that the system is being lived. Anyone who sorts out reporting paths, responsibilities and detection now not only fulfils an obligation, but is simply able to act faster in an emergency.