ISMS Copilot
NCS

NCS Copilot

Navigate Switzerland's National Cyberstrategy and its 17 measures with confidence

What the NCS Copilot Can Do

Understand the five NCS goals and how M1-M17 relate to your sector

Map your organisation's activities to the relevant NCS target groups

Identify which NCS measures target critical-infrastructure operators and what they signal

Navigate the relationship between the NCS, ISG Art. 74a, and the ICT Minimum Standard

Compare NCS measure objectives with FINMA Circular 2023/1 and FADP requirements

Draft an internal briefing on what the NCS means for public authorities (strategy, not direct obligations)

About NCS Copilot

The Switzerland National Cyberstrategy (NCS), adopted by the Federal Council in April 2023 and jointly endorsed with the cantons, sets out five strategic goals and 17 measures to strengthen cybersecurity across Swiss society. ISMS Copilot helps you understand how the NCS relates to your organisation and how it connects to binding instruments such as the ISG reporting obligation and the ICT Minimum Standard.

Cross-framework mappings

Working across NCS and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.

Browse free mappings

Frequently Asked Questions

What is the NCS?

The National Cyberstrategy (NCS) is a Swiss federal and cantonal policy framework, approved by the Federal Council on 5 April 2023 and jointly adopted with the cantons on 13 April 2023. It sets a vision and five strategic goals, implemented through 17 measures (M1-M17), aimed at improving Switzerland's overall cybersecurity posture across five target groups: population, business community, critical infrastructures, public authorities, and international or NGO actors.

How does the NCS Copilot help?

The NCS Copilot helps you understand the structure and intent of the 17 NCS measures, identify which target groups and goals are relevant to your organisation, and navigate the connection between the NCS and binding instruments such as the ISG incident-reporting obligation (Art. 74a) and the NCSC ICT Minimum Standard.

Does the NCS itself impose compliance obligations or sanctions?

The NCS is a strategic policy framework, not a technical standard or certification scheme, and it does not directly impose fines or sanctions of its own. Binding obligations: such as the mandatory 24-hour cyber-incident reporting requirement under ISG Art. 74a and the mandatory ICT Minimum Standard for electricity and gas operators: are set out in separate legal instruments that operationalise NCS objectives.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.