revFADP, FINMA circulars, and ICT minimum standards, evidenced from one scan.
CISGuard gives Swiss enterprises and financial institutions a continuously maintained CIS benchmark baseline: technical evidence for the revised Federal Act on Data Protection, FINMA supervisory expectations, and federal ICT minimum standards, with data that never leaves Switzerland.
Switzerland compliance at a glance, for fast retrieval.
Atomic factual claims auditors and search engines can cite verbatim.
- EU status
- Not an EU member; holds an EU adequacy decision for data flows
- Data protection law
- Revised Federal Act on Data Protection (revFADP), in force September 2023
- Privacy regulator
- Federal Data Protection and Information Commissioner (FDPIC)
- Financial supervision
- FINMA; circulars on operational risks and resilience
- ICT baseline
- Federal minimum standards for ICT resilience, aimed at critical infrastructure
- Personal liability
- revFADP sanctions can target responsible individuals
- Deployment
- On-premises in Switzerland, Swiss-region cloud, or air-gapped
Compliance in Swiss Confederation.
Switzerland is not an EU member state, and its compliance regime is deliberately its own. The revised Federal Act on Data Protection (revFADP), in force since September 2023, modernised Swiss data protection law along lines broadly comparable to GDPR, with the Federal Data Protection and Information Commissioner (FDPIC) as supervisory authority; notably, revFADP sanctions can target responsible individuals personally, which concentrates executive attention on demonstrable technical measures. Financial institutions answer to FINMA, whose circulars on operational risks and resilience set supervisory expectations for ICT risk management at banks and insurers. The federal government has also published minimum standards for improving ICT resilience, aimed particularly at critical infrastructure operators. Because Switzerland holds an EU adequacy decision, data can flow with the EU, but Swiss organisations still commonly require that security tooling and evidence stay on Swiss soil. CISGuard maps a single CIS benchmark scan across 22 CIS Benchmarks and 3,928 controls to ISO 27001, NIST 800-53, and SOC 2 evidence.
Frameworks CISGuard maps for Switzerland.
Each scan generates per-framework reports showing satisfied / partial / not-met status.
| Framework | Scope | Authority |
|---|---|---|
| revFADP | Revised Federal Act on Data Protection, in force September 2023 | Federal Data Protection and Information Commissioner (FDPIC) |
| FINMA circulars | Operational risks and resilience expectations for banks and insurers | Swiss Financial Market Supervisory Authority (FINMA) |
| ICT minimum standards | Federal minimum standards for improving ICT resilience, particularly critical infrastructure | Swiss federal authorities |
| GDPR (extraterritorial) → | Swiss companies offering goods or services to EU residents | EU member state supervisory authorities |
| ISO 27001 → | Information security management certification, widely expected in Swiss enterprise procurement | Accredited certification bodies |
Sovereignty and residency, solved by architecture.
Switzerland's non-EU status is the defining sovereignty fact. Swiss organisations, and especially banks, insurers, and public bodies, frequently require that security data remain on Swiss territory under Swiss law, outside both EU and US jurisdictional reach. CISGuard runs on customer-controlled infrastructure with no SaaS phone-home, so scan data, drift history, and audit evidence stay wherever the customer deploys: a Swiss data center, Swiss cloud regions, or a fully air-gapped network. The EU adequacy decision keeps cross-border flows lawful when needed, but with CISGuard nothing has to cross the border at all.
Three ways to deploy in Switzerland.
On-premises in Switzerland
Single-tenant deployment in a customer-controlled Swiss data center. Evidence stays on Swiss territory under Swiss law, the default pattern for banks, insurers, and public bodies.
Swiss-region cloud
Deployed in Swiss cloud regions such as AWS Zurich, Azure Switzerland, or Google Cloud Zurich. Keeps scan and evidence data in-country while retaining single-tenant, customer-controlled operation.
Air-gapped
Zero outbound connectivity, with CIS benchmark updates delivered via signed media. Suited to private banking environments, critical infrastructure, and government networks with strict isolation policies.
Switzerland questions, answered directly.
How does CISGuard support revFADP compliance?
By evidencing data security continuously. The revised Federal Act on Data Protection, in force since September 2023, obliges organisations to ensure adequate data security through technical and organisational measures, and its sanctions can target responsible individuals personally. CISGuard's continuous CIS benchmark scanning documents the hardening state of every scanned system, and drift detection shows regressions being caught, giving executives and the FDPIC a demonstrable technical-measures record.
Does GDPR still matter for Swiss companies?
Often, yes. GDPR applies extraterritorially to Swiss companies offering goods or services to people in the EU or monitoring their behaviour, alongside revFADP at home. CISGuard's multi-framework mapping means the same continuous CIS benchmark evidence serves both regimes at the technical-measures layer, without running separate tooling for the Swiss and EU sides of the business.
How does CISGuard fit FINMA supervisory expectations?
FINMA's circulars on operational risks and resilience expect banks and insurers to manage ICT risk on a hardened, monitored estate. CISGuard's continuous scanning across 22 CIS Benchmarks establishes and maintains that hardening baseline, drift detection surfaces configuration regressions between audits, and ISO 27001 and NIST 800-53 mapping turns the same scan into evidence for internal audit and supervisory review packs.
Can all CISGuard data stay in Switzerland?
Yes. CISGuard runs entirely on customer-controlled infrastructure with no SaaS phone-home and no telemetry to the vendor. Deploy on-premises in a Swiss data center or in Swiss cloud regions, and every scan result, drift event, and report remains on Swiss territory under Swiss law. For maximum isolation, air-gapped deployment removes outbound connectivity entirely.
Is air-gapped deployment realistic for Swiss financial institutions?
Yes. CISGuard supports fully air-gapped operation: zero outbound connectivity, with CIS benchmark content updates delivered via signed media. Scanning, drift detection, and reporting all run inside the isolated environment. This pattern suits private banking networks and other high-confidentiality Swiss environments where isolation policies rule out any internet-connected tooling.
Ready to deploy in Switzerland?
Our compliance engineers have helped organizations across Switzerland achieve regulatory readiness in as little as one business day.