NCS Copilot
Navigate Switzerland's National Cyberstrategy and its 17 measures with confidence
What the NCS Copilot Can Do
Understand the five NCS goals and how M1-M17 relate to your sector
Map your organisation's activities to the relevant NCS target groups
Identify which NCS measures target critical-infrastructure operators and what they signal
Navigate the relationship between the NCS, ISG Art. 74a, and the ICT Minimum Standard
Compare NCS measure objectives with FINMA Circular 2023/1 and FADP requirements
Draft an internal briefing on what the NCS means for public authorities (strategy, not direct obligations)
About NCS Copilot
The Switzerland National Cyberstrategy (NCS), adopted by the Federal Council in April 2023 and jointly endorsed with the cantons, sets out five strategic goals and 17 measures to strengthen cybersecurity across Swiss society. ISMS Copilot helps you understand how the NCS relates to your organisation and how it connects to binding instruments such as the ISG reporting obligation and the ICT Minimum Standard.
Cross-framework mappings
Working across NCS and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.
Browse free mappingsFrequently Asked Questions
What is the NCS?
The National Cyberstrategy (NCS) is a Swiss federal and cantonal policy framework, approved by the Federal Council on 5 April 2023 and jointly adopted with the cantons on 13 April 2023. It sets a vision and five strategic goals, implemented through 17 measures (M1-M17), aimed at improving Switzerland's overall cybersecurity posture across five target groups: population, business community, critical infrastructures, public authorities, and international or NGO actors.
How does the NCS Copilot help?
The NCS Copilot helps you understand the structure and intent of the 17 NCS measures, identify which target groups and goals are relevant to your organisation, and navigate the connection between the NCS and binding instruments such as the ISG incident-reporting obligation (Art. 74a) and the NCSC ICT Minimum Standard.
Does the NCS itself impose compliance obligations or sanctions?
The NCS is a strategic policy framework, not a technical standard or certification scheme, and it does not directly impose fines or sanctions of its own. Binding obligations: such as the mandatory 24-hour cyber-incident reporting requirement under ISG Art. 74a and the mandatory ICT Minimum Standard for electricity and gas operators: are set out in separate legal instruments that operationalise NCS objectives.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
