Switzerland to Introduce New Cybersecurity Act by June 2027
Article Content
- •Federal Council plans a new Cybersecurity Act by June 2027.
- •The Act will consolidate three key cybersecurity motions into one legislation.
- •Binding requirements will be imposed on digital product manufacturers and cloud providers.
On September 25, 2026, the Federal Council of Switzerland announced plans to draft a Federal Act on Cybersecurity, aiming for completion by June 2027. This new legislation will consolidate three parliamentary motions related to the cyber resilience of digital products, data protection, and the role of hosting and cloud providers. The National Cyber Security Centre (NCSC) is tasked with developing this standalone Cybersecurity Act (CySA). The Act will impose binding requirements on manufacturers and distributors of software and hardware, including market surveillance and a ban on insecure products. It will also transfer the obligation to report cyberattacks on critical infrastructure from the Information Security Act (ISA). The legislation is designed to minimize administrative burdens while enhancing cybersecurity across various sectors. Existing regulations will remain in force, and the new Act will allow for future technological developments to be incorporated seamlessly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…