Skip to main content
← Home
Switzerland Compliance Automation

revFADP, FINMA circulars, and ICT minimum standards, evidenced from one scan.

CISGuard gives Swiss enterprises and financial institutions a continuously maintained CIS benchmark baseline: technical evidence for the revised Federal Act on Data Protection, FINMA supervisory expectations, and federal ICT minimum standards, with data that never leaves Switzerland.

Quick Facts

Switzerland compliance at a glance, for fast retrieval.

Atomic factual claims auditors and search engines can cite verbatim.

EU status
Not an EU member; holds an EU adequacy decision for data flows
Data protection law
Revised Federal Act on Data Protection (revFADP), in force September 2023
Privacy regulator
Federal Data Protection and Information Commissioner (FDPIC)
Financial supervision
FINMA; circulars on operational risks and resilience
ICT baseline
Federal minimum standards for ICT resilience, aimed at critical infrastructure
Personal liability
revFADP sanctions can target responsible individuals
Deployment
On-premises in Switzerland, Swiss-region cloud, or air-gapped
Regulatory Landscape

Compliance in Swiss Confederation.

Switzerland is not an EU member state, and its compliance regime is deliberately its own. The revised Federal Act on Data Protection (revFADP), in force since September 2023, modernised Swiss data protection law along lines broadly comparable to GDPR, with the Federal Data Protection and Information Commissioner (FDPIC) as supervisory authority; notably, revFADP sanctions can target responsible individuals personally, which concentrates executive attention on demonstrable technical measures. Financial institutions answer to FINMA, whose circulars on operational risks and resilience set supervisory expectations for ICT risk management at banks and insurers. The federal government has also published minimum standards for improving ICT resilience, aimed particularly at critical infrastructure operators. Because Switzerland holds an EU adequacy decision, data can flow with the EU, but Swiss organisations still commonly require that security tooling and evidence stay on Swiss soil. CISGuard maps a single CIS benchmark scan across 22 CIS Benchmarks and 3,928 controls to ISO 27001, NIST 800-53, and SOC 2 evidence.

Frameworks

Frameworks CISGuard maps for Switzerland.

Each scan generates per-framework reports showing satisfied / partial / not-met status.

FrameworkScopeAuthority
revFADPRevised Federal Act on Data Protection, in force September 2023Federal Data Protection and Information Commissioner (FDPIC)
FINMA circularsOperational risks and resilience expectations for banks and insurersSwiss Financial Market Supervisory Authority (FINMA)
ICT minimum standardsFederal minimum standards for improving ICT resilience, particularly critical infrastructureSwiss federal authorities
GDPR (extraterritorial)Swiss companies offering goods or services to EU residentsEU member state supervisory authorities
ISO 27001Information security management certification, widely expected in Swiss enterprise procurementAccredited certification bodies
Data Residency

Sovereignty and residency, solved by architecture.

Switzerland's non-EU status is the defining sovereignty fact. Swiss organisations, and especially banks, insurers, and public bodies, frequently require that security data remain on Swiss territory under Swiss law, outside both EU and US jurisdictional reach. CISGuard runs on customer-controlled infrastructure with no SaaS phone-home, so scan data, drift history, and audit evidence stay wherever the customer deploys: a Swiss data center, Swiss cloud regions, or a fully air-gapped network. The EU adequacy decision keeps cross-border flows lawful when needed, but with CISGuard nothing has to cross the border at all.

Deployment Options

Three ways to deploy in Switzerland.

Option 01

On-premises in Switzerland

Single-tenant deployment in a customer-controlled Swiss data center. Evidence stays on Swiss territory under Swiss law, the default pattern for banks, insurers, and public bodies.

Option 02

Swiss-region cloud

Deployed in Swiss cloud regions such as AWS Zurich, Azure Switzerland, or Google Cloud Zurich. Keeps scan and evidence data in-country while retaining single-tenant, customer-controlled operation.

Option 03

Air-gapped

Zero outbound connectivity, with CIS benchmark updates delivered via signed media. Suited to private banking environments, critical infrastructure, and government networks with strict isolation policies.

Frequently Asked

Switzerland questions, answered directly.

How does CISGuard support revFADP compliance?

By evidencing data security continuously. The revised Federal Act on Data Protection, in force since September 2023, obliges organisations to ensure adequate data security through technical and organisational measures, and its sanctions can target responsible individuals personally. CISGuard's continuous CIS benchmark scanning documents the hardening state of every scanned system, and drift detection shows regressions being caught, giving executives and the FDPIC a demonstrable technical-measures record.

Does GDPR still matter for Swiss companies?

Often, yes. GDPR applies extraterritorially to Swiss companies offering goods or services to people in the EU or monitoring their behaviour, alongside revFADP at home. CISGuard's multi-framework mapping means the same continuous CIS benchmark evidence serves both regimes at the technical-measures layer, without running separate tooling for the Swiss and EU sides of the business.

How does CISGuard fit FINMA supervisory expectations?

FINMA's circulars on operational risks and resilience expect banks and insurers to manage ICT risk on a hardened, monitored estate. CISGuard's continuous scanning across 22 CIS Benchmarks establishes and maintains that hardening baseline, drift detection surfaces configuration regressions between audits, and ISO 27001 and NIST 800-53 mapping turns the same scan into evidence for internal audit and supervisory review packs.

Can all CISGuard data stay in Switzerland?

Yes. CISGuard runs entirely on customer-controlled infrastructure with no SaaS phone-home and no telemetry to the vendor. Deploy on-premises in a Swiss data center or in Swiss cloud regions, and every scan result, drift event, and report remains on Swiss territory under Swiss law. For maximum isolation, air-gapped deployment removes outbound connectivity entirely.

Is air-gapped deployment realistic for Swiss financial institutions?

Yes. CISGuard supports fully air-gapped operation: zero outbound connectivity, with CIS benchmark content updates delivered via signed media. Scanning, drift detection, and reporting all run inside the isolated environment. This pattern suits private banking networks and other high-confidentiality Swiss environments where isolation policies rule out any internet-connected tooling.

Ready to deploy in Switzerland?

Our compliance engineers have helped organizations across Switzerland achieve regulatory readiness in as little as one business day.