Swiss ICT Minimum Standard,
aligned and assessed with confidence.
The Swiss NCSC’s recommended baseline for resilient ICT, built on the NIST Cybersecurity Framework. I assess your posture against all 106 measures, map the gaps and hand you a scored result you own, doing the hands-on work alongside your team.
A recommended baseline, not a certificate.
The ICT Minimum Standard is issued by the Swiss NCSC, through the Federal Office for National Economic Supply. It is a recommended baseline for resilient information and communications technology, structured as 106 concrete measures that any organisation can assess itself against. It gives you a clear, honest picture of where your security actually stands.
There is no certificate and no examiner to pass. What you get instead is a scored posture you own, and evidence you can put in front of partners, regulators, insurers and due-diligence teams. My job is to run that assessment properly, close the gaps that matter, and leave you able to speak to your own security.
106 measures, five clear functions.
Identify
Assets, risks and governance mapped, so you know what you are protecting and why.
Protect
Safeguards and access control put in place around the systems and data that matter.
Detect
Monitoring and detection tuned to surface unusual activity before it becomes an incident.
Respond
Incident response planned and rehearsed, so a bad day stays contained and controlled.
Recover
Backups and continuity proven, so you can restore operations and keep running.
Built for critical infrastructure, valuable for everyone.
An adoptable baseline
You do not need to be Swiss or run critical infrastructure. Any organisation can adopt the standard as a structured, credible way to measure and improve its security.
- →Open to organisations of any size or sector
- →A recognised, well-structured baseline to work to
- →A scored posture you can share and defend
- →Evidence for partners, insurers and due-diligence
Aligned with NIST CSF & ISO 27001
Because it is built on the NIST Cybersecurity Framework, the standard maps neatly to work you may already be doing, or plan to do next.
- →Originally issued for critical-infrastructure operators
- →Structured on the five NIST CSF functions
- →Cross-maps cleanly to NIST CSF and ISO 27001
- →A head start toward wider certification later
Thinking about Swiss ICT Minimum? Let’s map a realistic path in a free 20-minute call.
Start with an assessment→Done with you, not handed over a wall.
Know where you stand
We scope your environment and work through the 106 measures together, so you see exactly where you conform, and where you don’t.
Close the gaps together
I guide your team through each fix in plain English, gathering the evidence as we go and prioritising the measures that reduce real risk first.
A result you own
You walk away with a scored gap report, a prioritised roadmap and an evidence pack, ready to share with partners and reviewers.
A posture you can stand behind.
- ✓A scored assessment against all 106 measures
- ✓A prioritised remediation roadmap
- ✓An evidence pack you own and keep
- ✓Cross-mapping to NIST CSF and ISO 27001
- ✓The confidence to speak to your own security
- ✓A re-assessment reminder, so it stays current
The things teams usually ask.
Is there a Swiss certificate for this?
No. The ICT Minimum Standard is a recommended baseline, not a certification scheme. There is no certificate and no examiner. What you get is a documented, scored posture that you own, and evidence you can share with partners, regulators, insurers and due-diligence teams.
Do we need to be a Swiss company or critical infrastructure?
No. The standard was originally issued with critical-infrastructure operators in mind, but the Swiss NCSC recommends it for any organisation. It is freely adoptable, whatever your size, sector or country.
Is the self-assessment tool free?
Yes. The Swiss NCSC publishes a free self-assessment tool, provided as an Excel workbook, that covers all 106 measures. I use it as the backbone of the engagement so the result is transparent and entirely yours to keep.
How does it map to NIST CSF and ISO 27001?
The standard is built on the NIST Cybersecurity Framework, so its 106 measures sit under the five NIST CSF functions and map cleanly across. That also makes it straightforward to cross-reference with ISO 27001, giving you a head start if you pursue wider certification later.
How long does it take?
Most organisations complete a first assessment in around four to six weeks. It depends on the size of your environment and how much remediation you choose to take on before the final scored report.
Ready to see where you stand against the Swiss ICT Minimum Standard?
Tell me a little about your organisation and I’ll map a realistic path to a scored, defensible posture. A free 20-minute call, no obligation.