Take-Aways (AI)
  • ISG and four imple­men­ting ordi­nan­ces came into force on Janu­ary 1, 2024.
  • Amend­ments with man­da­to­ry report­ing of cyber attacks on cri­ti­cal infras­truc­tures are still pending.
  • Par­lia­ment adopted the amend­ments on Sep­tem­ber 29, 2023; refe­ren­dum peri­od ends on Janu­ary 18
  • DDPS plans con­sul­ta­ti­on in 1st half of 2024; report­ing obli­ga­ti­on expec­ted to enter into force on Janu­ary 1, 2025

The Infor­ma­ti­on Secu­ri­ty Act and its four imple­men­ting ordi­nan­ces recent­ly came into force on Janu­ary 1, 2024 (see here). This legis­la­ti­ve packa­ge does not include the amend­ments to the ISG, which were intro­du­ced during the legis­la­ti­ve pro­cess and in par­ti­cu­lar pro­vi­de for a report­ing obli­ga­ti­on for cyber­at­tacks on cri­ti­cal infras­truc­tures. Accor­ding to this, ope­ra­tors of cri­ti­cal infras­truc­tures must report cyber­at­tacks to the Natio­nal Cyber Secu­ri­ty Cen­ter within 24 hours under cer­tain cir­cum­stances (for details, see here). Par­lia­ment has appro­ved the Amend­ments to the ISG adopted on Sep­tem­ber 29, 2023, the refe­ren­dum dead­line expi­res on Janu­ary 18.

The asso­cia­ted ordi­nan­ce pro­vi­si­ons are curr­ent­ly being draf­ted by the Depart­ment of Defen­se, Civil Pro­tec­tion and Sport (DDPS). The DDPS has com­mu­ni­ca­ted on Novem­ber 13, 2023The Fede­ral Coun­cil is expec­ted to con­duct a con­sul­ta­ti­on in the first half of 2024. It is the­r­e­fo­re to be expec­ted that infor­ma­ti­on on the con­sul­ta­ti­on pro­ce­du­re will soon be available on Fed­lex (see Plan­ned con­sul­ta­ti­onsor Ongo­ing con­sul­ta­ti­ons).

Accor­ding to the DDPS, plan­ning is curr­ent­ly geared towards the pro­vi­si­ons on the report­ing obli­ga­ti­on coming into force on Janu­ary 1, 2025. Ope­ra­tors of cri­ti­cal infras­truc­tures are the­r­e­fo­re likely to have a good year to prepa­re for the new obligations.