AI news

New Cybersecurity Law: What Romandy SMEs Need to Prepare For

The Federal Council has tasked the DDPS with drafting a Swiss Cybersecurity Act. What obligations for SMEs, what timelines, and how to start preparing now.

FlowBiz.ai25 September 2026 5 min readBased on Netzwoche

Photo : Netzwoche

Key takeaways

  • The Federal Council has mandated the DDPS to draft a Swiss Cybersecurity Act (CSG)
  • The text will draw on the European Cyber Resilience Act and target products, data, and hosting providers
  • A first draft is expected by summer 2027, with a prior public consultation period
Contents
  1. What the Federal Council Is Preparing
  2. What Changes Concretely for a Romandy SME
  3. Hypothetical Scenario: A Fiduciary in Martigny
  4. Points of Vigilance: nFADP, Hosting, and Dependency
  5. What to Do Now

The Federal Council has tasked the Federal Department of Defence, Civil Protection and Sport (DDPS) with drafting a new "Bundesgesetz über die Cybersicherheit" (CSG). According to Netzwoche, this act will merge three previously separate projects and draw heavily on the European Cyber Resilience Act.

For a manager of a Romandy SME, this announcement merits attention. It outlines the contours of future obligations regarding digital product security, protection of sensitive data, and hosting provider accountability. Anticipating these requirements will help avoid a sudden cost spike when the law takes effect.

What the Federal Council Is Preparing

The future CSG targets three distinct areas. First, the cyber resilience of products with digital elements: software, connected hardware, industrial devices. Second, strengthened protection for data deemed particularly important. Third, mandatory cybersecurity measures for hosting and cloud service providers.

The Federal Council justifies this merger by its aim to ensure "coherent regulation of cybersecurity for third parties." A single text would also make life easier for internationally active companies already subject to the EU Cyber Resilience Act. The Informationssicherheitsgesetz (ISG) would remain dedicated to federal authorities' IT security. The obligation for critical infrastructure operators to report cyber incidents would move to the new CSG.

Binding obligations are planned for manufacturers, importers, and distributors of software and hardware products. The text should also define bases for market surveillance and potential distribution bans for non-compliant products. For hosting and cloud providers, collaboration and defence obligations are under consideration.

What Changes Concretely for a Romandy SME

Who is affected? Any company that develops, imports, or resells products with a digital component. A property management firm distributing smart locks. A joinery in Sierre equipping customers with app-controlled roller shutters. A medical practice recommending connected blood pressure monitors. These actors may need to demonstrate product security, maintain up-to-date technical documentation, or provide security updates for a defined period.

SMEs that exclusively use standard software without commercialising it are not targeted as manufacturers. However, they must verify that their suppliers meet the new requirements. Choosing a Swiss or European certified host will become a compliance criterion, not merely a matter of trust.

Companies processing particularly sensitive data—financial, health, security-related—will likely need to strengthen their protection measures. The link with the nFADP remains to be clarified, but dual regulatory pressure is plausible.

Hypothetical Scenario: A Fiduciary in Martigny

Imagine a 12-person accounting firm in Martigny. It hosts client accounting data on a major US public cloud. It uses tax filing software developed by a German publisher. It recommends to clients an e-signature tool based in Ireland.

In two years, this firm might need to: verify that its tax filing software meets CSG requirements (or the equivalent European CRA); justify that its cloud host complies with provider cybersecurity obligations; document its own processes for protecting sensitive tax data. If its US host refuses to sign required attestations, it will need to migrate to a compliant provider. Such a migration, poorly prepared, can cost several weeks of internal work and disrupt client service during dinner hour, at the worst moment of annual closing.

Points of Vigilance: nFADP, Hosting, and Dependency

Hosting and sovereignty. The CSG will specify obligations for hosting and cloud providers. An SME storing customer data or internal information on servers outside Europe faces a double risk: regulatory (uncertain compliance) and operational (provider refusal to commit). Prioritising hosting in Switzerland, or at minimum in Europe, limits these uncertainties. FlowBiz.ai offers Swiss-hosted solutions for this exact reason: our AI solutions for SMEs.

Hidden costs. Regulatory compliance generates indirect costs: supplier audits, contract updates, staff training, potential data migration. These expenses are hard to quantify today since the text does not yet exist. Anticipating allows spreading them over time, rather than suffering them under pressure.

Product maturity. The European Cyber Resilience Act, model for the CSG, imposes precise technical requirements (update lifecycle, security documentation, vulnerability management). Software publishers and hardware manufacturers are not all ready. An SME dependent on a small local publisher or imported equipment without traceability risks supply chain disruption or premature obsolescence.

Vendor lock-in. Choosing a closed ecosystem (Microsoft, Google, Salesforce) eases overall compliance since these actors have massive legal and technical resources. It also creates dependency that is hard to reverse. A Romandy SME must evaluate this trade-off case by case, without ideology. Our automation examples show open architectures that limit this dependency.

What to Do Now

  1. Inventory your digital assets. List the software, connected hardware, and cloud services you use, purchase, or recommend. Identify those with digital elements that might fall within the future CSG scope. This takes roughly half a day for a 20-person SME.
  2. Verify your hosts' data location and commitments. Ask your cloud providers where data resides, what certifications they hold, and whether they plan to adapt to the European Cyber Resilience Act. Their response—or lack thereof—will indicate your risk. Prioritise providers willing to commit in writing.
  3. Document your sensitive data protection processes. Even though the final text remains unknown, having a data map, backup policy, and incident response plan provides a foundation useful for both the nFADP and the future CSG. This avoids rebuilding everything under pressure.
  4. Evaluate your digital supply chains. If you import or resell connected products, contact your suppliers to understand their compliance strategy. A European supplier will likely find it easier to meet CSG requirements than an Asian supplier without representation on the continent.
  5. Test your AI and cybersecurity maturity. The 2-minute AI quiz from FlowBiz.ai gives a first diagnostic of your exposure. For deeper analysis, our free selection assistant and pre-diagnosis identifies priorities by sector and size. We are based in Sion and support Romandy SMEs step by step, without upfront fixed-term commitment.

The timeline is known: a public consultation is expected by summer 2027. This leaves time to prepare, not to wait. SMEs that do this anticipation work will gain peace of mind and leverage in supplier negotiations. Those that ignore it will suffer costs and constraints under pressure.

Frequently asked questions

My company is not in tech, will it be affected by this future CSG?+

Probably, if you use, sell, or recommend products with digital elements. A smart lock, point-of-sale software, a connected medical device: these items fall within the scope. The SME as end user is not targeted by manufacturing obligations, but must ensure its suppliers' compliance.

Will the CSG replace the nFADP?+

No, these are complementary texts. The nFADP protects personal data of Swiss residents. The CSG targets digital product security, protection of sensitive digital data in the broader sense, and hosting provider obligations. An SME might need to comply with both. For precise nFADP details, consult the Federal Data Protection and Information Commissioner.

Do I need to change hosts immediately?+

Not necessarily. The text does not yet exist and precise obligations for Swiss hosts remain to be defined. However, verifying your data location, your provider's current certifications, and its willingness to adapt to European regulation is useful work to start now. This gives you options if migration proves necessary.

What is the timeline before entry into force?+

The Federal Council expects a first draft for consultation by summer 2027. Between consultation, Parliamentary adoption, and entry into force, several years may pass. However, if the text draws on the European Cyber Resilience Act, companies exporting to the EU will already need to comply with that regulation by 2026-2027 depending on product categories.

And in your business, what could we automate?

Answer a few questions and get a free, personalised AI pre-diagnosis with three concrete leads in two minutes.

Share this article

New Cybersecurity Law: What Romandy SMEs Need to Prepare For | FlowBiz.ai