Reporting obligations in Switzerland: ISG, FINMA, revFADP, DORA and NIS2

One incident can trigger several reporting duties at once: ISG to the National Cyber Security Centre (NCSC) within 24 hours of discovery, FINMA within 24 hours of discovery, revFADP (revised Federal Act on Data Protection) to the FDPIC as soon as possible where a high risk to the persons concerned is likely, plus DORA and NIS2 with their own deadlines for EU entities. The regimes differ in addressee, deadline and content. A single classification that serves all duties in parallel is what matters.

All

The five regimes compared

RegimeWho is affectedNotifyDeadlineInitial notification contentFines/sanctionsPrimary source
ISG Art. 74a-74fOperators of critical infrastructure and further reporting organisationsBACS (formerly NCSC)24 hours after discovery, supplement within 14 daysType of attack, affected systems, risk assessmentFine up to CHF 100,000, only after the National Cyber Security Centre (NCSC) contact and order (from 1 Oct 2025)The NCSC reporting obligation
FINMA AM 05/2020, refined by AM 03/2024Supervised institutions (banks, insurers, FMI)FINMA24 hours from discovery, full report within 72 hours via the EHPAffected functions and data, criticality assessment, measures takenSanctions under FINMAG possibleFINMA AM 05/2020
revDSG Art. 24Controllers, where a data security breach is likely to result in a high risk to the persons concernedFDPICas soon as possibleNature of the breach, consequences, measures taken or planned (Art. 24 para. 2 revFADP, Art. 15 DPO)Breaching the reporting duty is not itself a criminal offence; the FDPIC can order the notification. Breaching the minimum data security requirements, for example, can be punishable (Art. 61 let. c revFADP, fine up to CHF 250,000 against responsible individuals).FDPIC reporting portals
DORAFinancial entities in the EU; Swiss institutions via EU subsidiaries, Swiss ICT providers indirectly via contracts with EU financial entities or as critical ICT third-party providersCompetent authority4 hours after classification, at latest 24 hours after awareness; interim report 72 hours, final report 1 monthKey elements of the incident and their impactSanction mechanisms depending on member state and provider statusEIOPA on DORA
NIS2Essential and important entities in the EU; Swiss companies only indirectly, for example as providers or via EU subsidiariesCSIRT or competent authority24-hour early warning, 72-hour notification, final report 1 monthInitial assessment of whether a malicious act is suspected, impact, indicatorsEssential entities: up to at least EUR 10 million or 2 % of worldwide annual turnover, whichever is higher; important entities: up to at least EUR 7 million or 1.4 %. EU member states set the specific amounts (Art. 34 NIS2).European Commission on NIS2

Parallel duties and one classification

The same ransomware event can trigger ISG, FINMA and revFADP (revised Federal Act on Data Protection) notifications at once; for EU subsidiaries DORA and NIS2 join. The clocks start at different moments: ISG from discovery, FINMA from discovery, revFADP as soon as a report is realistically possible. One classification with a documented decision tree drives all deadlines.

  • Prepare the classification once: criteria, decision, owner, timestamp.
  • Keep notification templates per regime, fed by the same facts from the ticket trail.
  • Document incidents assessed as not reportable, including time and reasoning.

The detail pages cover each regime: ISG 24h reporting duty, FINMA requirements, revFADP and SOC, DORA requirements and NIS2 and Swiss subsidiaries.

What the SOC contributes to the deadlines

The deadline runs from discovery. If an alert sits unhandled overnight or over the weekend, there is little time left for a well-founded initial report. Continuous detection and assessment ensure that discovery, assessment and reporting follow each other closely. The SOC supplies the facts for every notification: timeline, affected systems, measures taken, all timestamped in the ticket trail. The SOC as a Service Switzerland page describes how this works.

Legal basis and sources

Frequently asked questions

Which reporting duty applies first when several apply?

There is no order; several duties run in parallel. The shortest deadline sets the internal clock, usually the ISG notification to the National Cyber Security Centre (NCSC) 24 hours after discovery.

Does NIS2 apply to Swiss companies?

NIS2 binds entities in the EU. Swiss companies are affected only indirectly, for example as providers to EU entities or through EU subsidiaries that fall under NIS2 themselves.

When does the FINMA 24-hour clock start?

Under Guidance 03/2024, from discovery of the cyber attack. An initial criticality assessment must be made within that window, and the deadline takes precedence. The full report follows within 72 hours via the EHP; banking business days count, except for severe attacks.

What happens if we miss the deadline?

Depending on the regime, fines or sanctions follow; under the ISG only after the National Cyber Security Centre (NCSC) contact and order. At minimum, reputational and audit risks arise, and the late notification itself must be documented.

Can an external SOC prepare the notifications for us?

The SOC supplies facts, timelines and templates; responsibility and the decision stay with the institution. The [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) page covers how the handover works.

Continue reading in this cluster
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.
revFADP (revised Federal Act on Data Protection) and SOC: what the revised Swiss data-protection act requires from security operations
The revFADP (revised Federal Act on Data Protection, in force since 1 Sep 2023) requires appropriate technical and organisational measures. Controllers must document these measures and notify the FDPIC as soon as possible of data security breaches likely to result in a high risk to the persons concerned. A SOC delivers the detection, documented response and evidence trail needed for a credible FDPIC notification and for informing data subjects.
DORA requirements for the SOC: what the Digital Operational Resilience Act means in operations
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) requires EU financial entities to maintain a continuous ICT risk and resilience framework. It has applied since 17 January 2025. For Swiss groups, DORA applies directly through EU subsidiaries and indirectly through contracts with EU financial customers. These subsidiaries include banks, insurers, payment institutions, crypto-asset service providers, CSDs, CCPs and trading venues. A SOC delivers four DORA cornerstones. It provides continuous ICT detection and classified incident notification to the competent authority under the 24-hour / 72-hour / 1-month cascade. It also provides the evidence trail for supervisory review and the operational foundation for threat-led penetration testing (TLPT).
NIS2 for Swiss subsidiaries: when the EU directive lands in Switzerland
The EU NIS2 directive (transposition deadline was 17 Oct 2024, implemented nationally by member states) does not apply directly in Switzerland. It bites through two channels: first, EU subsidiaries of Swiss groups fall directly under national NIS2 implementations. Second, Swiss providers of essential services to regulated EU customers inherit obligations contractually. A SOC is the operational building block for detection, notification and evidence in both cases.