Switzerland Plans New Cybersecurity Law Targeting Open-Source Software

Wait 5 sec.

TLDR:Switzerland plans one law covering software, hardware, data and digital infrastructure.The proposal could impose binding security duties on manufacturers and distributors.Open-source software could receive broader treatment under the planned cybersecurity framework.Switzerland aims to align its rules with the EU Cyber Resilience Act.Switzerland is preparing a standalone cybersecurity law covering digital products, data, cloud providers and open-source software. The Federal Council has tasked the Federal Department of Defence, Civil Protection and Sport with preparing a consultation draft by June 2027.The planned legislation would combine three parliamentary initiatives into one framework. It would also incorporate existing cyberattack reporting requirements for critical infrastructure.What the Switzerland’s Cybersecurity Law CoversThe proposed Switzerland cybersecurity law would establish binding requirements across several parts of the digital economy. These include software and hardware products, critical digital data, hosting providers and cloud infrastructure.Manufacturers, importers and distributors would face cybersecurity obligations under the proposed framework. The rules would also establish market surveillance powers and provide a basis for banning sales of insecure products.The Federal Council said the framework would follow the European Cyber Resilience Act. It also aims to reduce administrative burdens for companies operating across Switzerland and the European market.The proposal combines three areas previously planned through amendments to the Information Security Act. These cover cyber resilience for digital products, protection of particularly important digital data, and cloud and hosting cybersecurity.The new law would also include Switzerland’s existing cyberattack reporting requirement for critical infrastructure. That obligation has been in effect since April 2025. SWITZERLAND PLANS NEW CYBERSECURITY LAW ADDRESSING OPEN-SOURCE SOFTWAREThe Swiss Federal Council is moving to create a standalone federal cybersecurity law, explicitly citing open-source software as an area that could receive a more comprehensive regulatory approach.The… https://t.co/Kc818nXBn3 pic.twitter.com/kO06KEelB6— Bitcoin News (@BitcoinNewsCom) September 25, 2026Switzerland Cybersecurity Law Expands the Open-Source FocusOpen-source software could receive broader treatment under the planned legislation. The Federal Council said consolidating cybersecurity rules would allow Switzerland to address specific technologies more comprehensively.That approach could provide a single regulatory framework for obligations spanning products, data and digital infrastructure. It would also allow future technological and European developments to be incorporated more easily.Switzerland already has a federal open-source policy. The Federal Administration publishes software as open source under its existing legal framework.The country has also tested open-source projects for security vulnerabilities. A National Cyber Security Centre pilot examined TYPO3 and QGIS, with identified vulnerabilities later fixed by their developer communities.For businesses, the proposed consolidation could reduce the need to navigate separate cybersecurity requirements. The Federal Council specifically pointed to internationally active companies already subject to European cybersecurity rules.The next major step is the consultation draft, which the defence department must prepare by June 2027. Until then, the detailed obligations and enforcement mechanisms remain subject to the legislative process.Switzerland plans to bring product, data and infrastructure cybersecurity requirements into one federal law. The framework would also give open-source software a more comprehensive place within Switzerland’s cybersecurity rules.The post Switzerland Plans New Cybersecurity Law Targeting Open-Source Software appeared first on Blockonomi.