Reporting obligations in Switzerland: ISG, FINMA, revFADP, DORA and NIS2
One incident can trigger several reporting duties at once: ISG to the National Cyber Security Centre (NCSC) within 24 hours of discovery, FINMA within 24 hours of discovery, revFADP (revised Federal Act on Data Protection) to the FDPIC as soon as possible where a high risk to the persons concerned is likely, plus DORA and NIS2 with their own deadlines for EU entities. The regimes differ in addressee, deadline and content. A single classification that serves all duties in parallel is what matters.
The five regimes compared
| Regime | Who is affected | Notify | Deadline | Initial notification content | Fines/sanctions | Primary source |
|---|---|---|---|---|---|---|
| ISG Art. 74a-74f | Operators of critical infrastructure and further reporting organisations | BACS (formerly NCSC) | 24 hours after discovery, supplement within 14 days | Type of attack, affected systems, risk assessment | Fine up to CHF 100,000, only after the National Cyber Security Centre (NCSC) contact and order (from 1 Oct 2025) | The NCSC reporting obligation |
| FINMA AM 05/2020, refined by AM 03/2024 | Supervised institutions (banks, insurers, FMI) | FINMA | 24 hours from discovery, full report within 72 hours via the EHP | Affected functions and data, criticality assessment, measures taken | Sanctions under FINMAG possible | FINMA AM 05/2020 |
| revDSG Art. 24 | Controllers, where a data security breach is likely to result in a high risk to the persons concerned | FDPIC | as soon as possible | Nature of the breach, consequences, measures taken or planned (Art. 24 para. 2 revFADP, Art. 15 DPO) | Breaching the reporting duty is not itself a criminal offence; the FDPIC can order the notification. Breaching the minimum data security requirements, for example, can be punishable (Art. 61 let. c revFADP, fine up to CHF 250,000 against responsible individuals). | FDPIC reporting portals |
| DORA | Financial entities in the EU; Swiss institutions via EU subsidiaries, Swiss ICT providers indirectly via contracts with EU financial entities or as critical ICT third-party providers | Competent authority | 4 hours after classification, at latest 24 hours after awareness; interim report 72 hours, final report 1 month | Key elements of the incident and their impact | Sanction mechanisms depending on member state and provider status | EIOPA on DORA |
| NIS2 | Essential and important entities in the EU; Swiss companies only indirectly, for example as providers or via EU subsidiaries | CSIRT or competent authority | 24-hour early warning, 72-hour notification, final report 1 month | Initial assessment of whether a malicious act is suspected, impact, indicators | Essential entities: up to at least EUR 10 million or 2 % of worldwide annual turnover, whichever is higher; important entities: up to at least EUR 7 million or 1.4 %. EU member states set the specific amounts (Art. 34 NIS2). | European Commission on NIS2 |
Parallel duties and one classification
The same ransomware event can trigger ISG, FINMA and revFADP (revised Federal Act on Data Protection) notifications at once; for EU subsidiaries DORA and NIS2 join. The clocks start at different moments: ISG from discovery, FINMA from discovery, revFADP as soon as a report is realistically possible. One classification with a documented decision tree drives all deadlines.
- Prepare the classification once: criteria, decision, owner, timestamp.
- Keep notification templates per regime, fed by the same facts from the ticket trail.
- Document incidents assessed as not reportable, including time and reasoning.
The detail pages cover each regime: ISG 24h reporting duty, FINMA requirements, revFADP and SOC, DORA requirements and NIS2 and Swiss subsidiaries.
What the SOC contributes to the deadlines
The deadline runs from discovery. If an alert sits unhandled overnight or over the weekend, there is little time left for a well-founded initial report. Continuous detection and assessment ensure that discovery, assessment and reporting follow each other closely. The SOC supplies the facts for every notification: timeline, affected systems, measures taken, all timestamped in the ticket trail. The SOC as a Service Switzerland page describes how this works.
Legal basis and sources
- ISG, Fedlex: reporting duty for critical-infrastructure operators, with the National Cyber Security Centre (NCSC) implementation page.
- FINMA AM 05/2020 and FINMA AM 03/2024: reporting cyber incidents to FINMA.
- revFADP, Fedlex: Art. 24 duty to report data breaches, FDPIC reporting portals, FDPIC guide on reporting under Art. 24 revFADP, version 1.2 of 23 April 2025, German.
- EIOPA on DORA: official overview of notification deadlines for major ICT incidents.
- European Commission on NIS2: official overview of the directive.
Placement in SOC operations
The SOC as a Service Switzerland page shows how the evidence for every deadline is produced in live operations.
Frequently asked questions
Which reporting duty applies first when several apply?
There is no order; several duties run in parallel. The shortest deadline sets the internal clock, usually the ISG notification to the National Cyber Security Centre (NCSC) 24 hours after discovery.
Does NIS2 apply to Swiss companies?
NIS2 binds entities in the EU. Swiss companies are affected only indirectly, for example as providers to EU entities or through EU subsidiaries that fall under NIS2 themselves.
When does the FINMA 24-hour clock start?
Under Guidance 03/2024, from discovery of the cyber attack. An initial criticality assessment must be made within that window, and the deadline takes precedence. The full report follows within 72 hours via the EHP; banking business days count, except for severe attacks.
What happens if we miss the deadline?
Depending on the regime, fines or sanctions follow; under the ISG only after the National Cyber Security Centre (NCSC) contact and order. At minimum, reputational and audit risks arise, and the late notification itself must be documented.
Can an external SOC prepare the notifications for us?
The SOC supplies facts, timelines and templates; responsibility and the decision stay with the institution. The [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) page covers how the handover works.