The Federal Council has tasked the Federal Department of Defence, Civil Protection and Sport (DDPS) with drafting a new "Bundesgesetz über die Cybersicherheit" (CSG). According to Netzwoche, this act will merge three previously separate projects and draw heavily on the European Cyber Resilience Act.
For a manager of a Romandy SME, this announcement merits attention. It outlines the contours of future obligations regarding digital product security, protection of sensitive data, and hosting provider accountability. Anticipating these requirements will help avoid a sudden cost spike when the law takes effect.
What the Federal Council Is Preparing
The future CSG targets three distinct areas. First, the cyber resilience of products with digital elements: software, connected hardware, industrial devices. Second, strengthened protection for data deemed particularly important. Third, mandatory cybersecurity measures for hosting and cloud service providers.
The Federal Council justifies this merger by its aim to ensure "coherent regulation of cybersecurity for third parties." A single text would also make life easier for internationally active companies already subject to the EU Cyber Resilience Act. The Informationssicherheitsgesetz (ISG) would remain dedicated to federal authorities' IT security. The obligation for critical infrastructure operators to report cyber incidents would move to the new CSG.
Binding obligations are planned for manufacturers, importers, and distributors of software and hardware products. The text should also define bases for market surveillance and potential distribution bans for non-compliant products. For hosting and cloud providers, collaboration and defence obligations are under consideration.
What Changes Concretely for a Romandy SME
Who is affected? Any company that develops, imports, or resells products with a digital component. A property management firm distributing smart locks. A joinery in Sierre equipping customers with app-controlled roller shutters. A medical practice recommending connected blood pressure monitors. These actors may need to demonstrate product security, maintain up-to-date technical documentation, or provide security updates for a defined period.
SMEs that exclusively use standard software without commercialising it are not targeted as manufacturers. However, they must verify that their suppliers meet the new requirements. Choosing a Swiss or European certified host will become a compliance criterion, not merely a matter of trust.
Companies processing particularly sensitive data—financial, health, security-related—will likely need to strengthen their protection measures. The link with the nFADP remains to be clarified, but dual regulatory pressure is plausible.
Hypothetical Scenario: A Fiduciary in Martigny
Imagine a 12-person accounting firm in Martigny. It hosts client accounting data on a major US public cloud. It uses tax filing software developed by a German publisher. It recommends to clients an e-signature tool based in Ireland.
In two years, this firm might need to: verify that its tax filing software meets CSG requirements (or the equivalent European CRA); justify that its cloud host complies with provider cybersecurity obligations; document its own processes for protecting sensitive tax data. If its US host refuses to sign required attestations, it will need to migrate to a compliant provider. Such a migration, poorly prepared, can cost several weeks of internal work and disrupt client service during dinner hour, at the worst moment of annual closing.
Points of Vigilance: nFADP, Hosting, and Dependency
Hosting and sovereignty. The CSG will specify obligations for hosting and cloud providers. An SME storing customer data or internal information on servers outside Europe faces a double risk: regulatory (uncertain compliance) and operational (provider refusal to commit). Prioritising hosting in Switzerland, or at minimum in Europe, limits these uncertainties. FlowBiz.ai offers Swiss-hosted solutions for this exact reason: our AI solutions for SMEs.
Hidden costs. Regulatory compliance generates indirect costs: supplier audits, contract updates, staff training, potential data migration. These expenses are hard to quantify today since the text does not yet exist. Anticipating allows spreading them over time, rather than suffering them under pressure.
Product maturity. The European Cyber Resilience Act, model for the CSG, imposes precise technical requirements (update lifecycle, security documentation, vulnerability management). Software publishers and hardware manufacturers are not all ready. An SME dependent on a small local publisher or imported equipment without traceability risks supply chain disruption or premature obsolescence.
Vendor lock-in. Choosing a closed ecosystem (Microsoft, Google, Salesforce) eases overall compliance since these actors have massive legal and technical resources. It also creates dependency that is hard to reverse. A Romandy SME must evaluate this trade-off case by case, without ideology. Our automation examples show open architectures that limit this dependency.
What to Do Now
- Inventory your digital assets. List the software, connected hardware, and cloud services you use, purchase, or recommend. Identify those with digital elements that might fall within the future CSG scope. This takes roughly half a day for a 20-person SME.
- Verify your hosts' data location and commitments. Ask your cloud providers where data resides, what certifications they hold, and whether they plan to adapt to the European Cyber Resilience Act. Their response—or lack thereof—will indicate your risk. Prioritise providers willing to commit in writing.
- Document your sensitive data protection processes. Even though the final text remains unknown, having a data map, backup policy, and incident response plan provides a foundation useful for both the nFADP and the future CSG. This avoids rebuilding everything under pressure.
- Evaluate your digital supply chains. If you import or resell connected products, contact your suppliers to understand their compliance strategy. A European supplier will likely find it easier to meet CSG requirements than an Asian supplier without representation on the continent.
- Test your AI and cybersecurity maturity. The 2-minute AI quiz from FlowBiz.ai gives a first diagnostic of your exposure. For deeper analysis, our free selection assistant and pre-diagnosis identifies priorities by sector and size. We are based in Sion and support Romandy SMEs step by step, without upfront fixed-term commitment.
The timeline is known: a public consultation is expected by summer 2027. This leaves time to prepare, not to wait. SMEs that do this anticipation work will gain peace of mind and leverage in supplier negotiations. Those that ignore it will suffer costs and constraints under pressure.



