The Swiss energy sector is in the midst of digital transformation: electricity grids and gas infrastructure are becoming increasingly interconnected and digitalised. Modern smart grids, remote maintenance systems, and the convergence of IT and OT systems deliver efficiency gains, but also significantly increase vulnerability to cyberattacks. At the same time, the number of reported cyber incidents continues to rise, increasing the overall risk to Switzerland’s energy industry.
These developments were recognised early on, leading to the introduction of federal-level measures such as minimum standards and mandatory incident reporting obligations.
A Shift Towards Mandatory Cybersecurity Measures
Originally, the ICT minimum standard was issued as a recommendation and could be applied voluntarily. This has since changed. For operators of critical energy infrastructure, implementation is now mandatory.
- Electricity supply: Since 1 July 2024, the ICT minimum standard for electricity grid operators has been mandatory. This is based on a revision of the Electricity Supply Ordinance (StromVV), which makes the standard and associated protection levels legally binding.
- Gas supply: Since 1 July 2025, the obligation applies based on the revised Gas Supply Act (GasVG). The Federal Council explicitly defines the ICT minimum standard as a minimum requirement to protect gas networks against cyber risks.
This shift from voluntary recommendations to binding measures underlines the critical importance of energy supply. Regulation makes it clear that basic cybersecurity measures are no longer optional, but a mandatory requirement for every utility operator.