The Information Security Act (ISA), Art.74b, stipulates that authorities and organisations subject to the reporting obligation, such as energy and drinking water suppliers, transport companies and cantonal and communal administrations, must report cyberattacks to the NCSC within 24 hours of discovery.
More detailed information on the definition of critical infrastructure can be found in the Information Security Act (ISA).
The Cybersecurity Ordinance (CSO) contains the implementing provisions for the reporting obligation and, in particular, regulates the exceptions.
Last modification 21.05.2026