Switzerland: new standalone cybersecurity law LCib (cross-border guide)

Digital infrastructure and servers for cybersecurity in Switzerland

The Federal Council instructs DDPS to draft the LCib by June 2027, based on the European Cyber Resilience Act for digital products and data.

Context

In brief

  • DDPS will prepare a standalone cybersecurity law.
  • The draft will be ready by June 2027 for consultation.
  • The law will bring together three projects on products, data and digital infrastructure.
  • The obligation to report cyberattacks will be transferred from the LSIn to the LCib.

Key facts

  • Decision → Federal Council, 25 September 2026
  • Mandate → DDPS
  • Deadline → June 2027
  • Planned law → standalone federal Cybersecurity Act (LCib)
  • Basis → European Cyber Resilience Act (CRA)
  • Areas → products, data and digital infrastructure
  • Obligation transferred → reporting of cyberattacks on critical infrastructure
  • LSIn → information security of the federal authorities

On 25 September 2026, at its meeting in Bern, the Federal Council instructed the Federal Department of Defence, Civil Protection and Sport (DDPS) to prepare by June 2027 a draft for consultation on a new standalone federal cybersecurity law. The stated objective is to implement three parliamentary initiatives in a single legislative act.

The Federal Office for Cyber Security (FOCS) is working on the projects on behalf of Parliament. The first concerns the cyber-resilience of products with digital elements; the second, the protection of the most important digital data; the third, the role of hosting and cloud service providers in cybersecurity. The three projects concern complementary regulatory levels: products, data and digital infrastructure. They were originally intended to be implemented through amendments to the Federal Act on Information Security (LSIn).

The choice of a standalone law

The Federal Council is now changing its approach. The planned Cybersecurity Act, referred to as the LCib, will bring together the three projects and ensure coherent regulation of cybersecurity by third parties. The new act will also include the obligation to report cyberattacks on critical infrastructure, provided for by the LSIn and in force since April 2025. The LSIn, however, will continue to govern the information security of the federal authorities.

The draft will establish binding requirements for manufacturers, importers and distributors of software and hardware products. It will also create the basis for market surveillance and for a ban on distributing unsafe products. Special obligations are envisaged for important digital data and for hosting and cloud providers, including cooperation and defence in the event of cyberthreats.

The sector-specific rules already in force, including the Telecommunications Act, the Ordinance on the Electricity Supply and the Ordinance on Telecommunications Installations, will remain in force. The LCib will supplement them with cybersecurity obligations. According to the Federal Council, a single law will make it possible to update just one act based on technological or European developments and to address specific issues better, such as open-source software.

DDPS will have to submit the draft to the Federal Council by June 2027, for consultation and the subsequent decision. The planned legislation will be based on the European Cyber Resilience Act (CRA) and aims to keep companies' administrative burden to a minimum. For companies active internationally that already have to comply with the EU CRA, the stated objective is to avoid an additional compliance burden.

Operational details

What changes for organizations

The transition from three amendments to the LSIn to a standalone law introduces a simpler framework for the organizations involved: distinguishing the scope of the activity and placing each obligation under the applicable set of rules. The communiqué describes a project, not an entry-into-force date: the DDPS will have to draft it by June 2027, put it out for consultation and submit it to the Federal Council for a decision. The practical consequence is to keep the obligations already in force separate from those that the LCib will have to define.

ScopeMeasure describedPlanned placement
Products with digital elementsBinding requirements, market surveillance and a ban on distributing unsafe productsLCib
Important digital dataSpecific protection obligationsLCib
Hosting and cloudObligations to cooperate and defend against cyber threatsLCib
Critical infrastructureReporting of cyberattacks in force since April 2025Planned transfer from the LSIn to the LCib
Sector-specific rulesLaws and ordinances remain in forceIntegration of cybersecurity obligations

A map by entity

For a manufacturer, importer or distributor, the dossier covers binding requirements, market surveillance and a possible ban on distributing unsafe products. For a hosting or cloud provider, the text instead focuses on cooperation and defense in the event of cyber threats. Important digital data form a further scope, with specific protection obligations.

The most explicit economic benefit concerns companies operating internationally. Since these companies already have to comply with the EU CRA, the harmonized Swiss law is designed not to create an additional compliance burden. The proposal should also keep companies' administrative burdens to a minimum. The reference to the European CRA thus becomes the main point of comparison for those operating across borders.

Sector-specific rules are neither absorbed nor repealed: the Telecommunications Act, the Ordinance on Electricity Supply and the Ordinance on Telecommunications Installations remain in force, while the LCib adds cybersecurity obligations as a joint task. For federal authorities, the LSIn continues to govern information security.

To explore the business perspective separately from the regulatory dossier, see aziende che assumono.

Useful tools to protect your net income

To reduce FX leakage, compare CHF-EUR exchange options and banks for cross-border workers.

Key points

How to follow the dossier

Following the dossier first of all requires separating the roles, because the project does not concern just one type of entity. The operational sequence can remain aligned with the areas listed in the communication.

Five operational steps

1. Map the scope. Verify whether the activity concerns the production, import or distribution of software and hardware with digital elements, the protection of important digital data, hosting or cloud services, or critical infrastructure. These are the four areas for which the text provides for specific measures.

2. Separate the rules that already apply from the project. For critical infrastructures, bear in mind the obligation to report cyberattacks in force since April 2025. Its planned placement will be in the LCib; it should not be confused with the part of the LSIn that will continue to regulate the information security of federal authorities.

3. Maintain the sectoral framework. The Telecommunications Act, the Ordinance on the Electricity Supply and the Ordinance on Telecommunications Installations will remain in force. The new law will supplement them by adding the obligations arising from cybersecurity as a joint task.

4. Distinguish products and services. For products, follow the binding requirements, market surveillance and the possible distribution ban on unsafe products. For hosting and cloud, instead separate out the planned obligations of cooperation and defence in the event of cyber threats.

5. Note the legislative deadline. By June 2027, DDPS will have to prepare the project, submit it for consultation and submit it to the Federal Council for a decision. For companies active internationally, the European CRA constitutes the reference indicated for future Swiss legislation.

This timetable makes it possible not to anticipate an application date that the communication does not indicate. The certain step is the preparation of the project and its subsequent consultation; the Federal Council will then have to receive it for a decision. For companies, the practical question is therefore which of the scopes affects their activity and how it intersects with sectoral rules or with the CRA already applied by companies active internationally. The standalone law is also intended to update a single act based on technological or European developments and to address specific topics more effectively, such as open-source software.

Those following the issue professionally can also consult the annunci di lavoro, keeping this tool separate from the legislative process. To instead connect the reading to your personal situation, use the calcolatore stipendio.

Source: admin.ch

Frequently Asked Questions
What is LCib and what areas will it cover?
The LCib is a new autonomous federal law on cybersecurity that the DDPS will have to elaborate by June 2027. The regulatory act will bring together three projects previously envisaged as changes to the LSIn: the cyber-resilience of products with digital elements, the protection of the most important digital data and the role of hosting and cloud service providers. The aim is to ensure consistent regulation of third-party cybersecurity, including binding requirements for manufacturers, importers
What changes for internationally active companies?
The planned regulation will be based on the European Cyber Resilience Act (CRA). The goal stated by the Federal Council is to keep the administrative burden on companies to a minimum and, specifically for international companies that already have to comply with the EU CRA, to avoid an additional compliance burden. The choice of a single law will also make it easier to update the act based on technological or European developments, better addressing issues such as open source software.
What is the relationship between LCib, LSIn and sectoral rules?
The LCib will absorb the obligation to report cyberattacks on critical infrastructure (in force since April 2025), which will move from the LSIn to the new law. LSIn will instead continue to regulate the information security of federal authorities. In parallel, existing sectoral rules, such as the Telecommunications Act and the Electricity Supply and Telecommunications Facilities Ordinances, will remain in force, being supplemented by the LCib with new cybersecurity obligations.

Related articles