Public Sector IT Outsourcing in Switzerland
Demonstrating that you take cybersecurity seriously —without just paying lip service— is exactly the goal of the Cyber-Safe certification. It is a Swiss cybersecurity certification designed for small and medium-sized businesses, municipalities, and small organizations. Here’s what it certifies, the concrete benefits it offers, and how the certification process works.
What Is the Cyber-Safe Label?
Cyber-Safe is a Swiss certification that assesses and certifies an organization’s cybersecurity level. The process is impartial and covers the three key areas that matter: your IT infrastructure, your organization, and the human factor. Unlike a simple self-declaration, the certification is based on an independent assessment: questionnaires, technical analysis, and full-scale phishing tests conducted with your teams.
Why Get Certified: 4 Concrete Benefits
- Reassure your customers and partners: A recognized certification demonstrates, with supporting evidence, that you take security seriously. In industries that handle sensitive data, this is a direct selling point.
- Stay competitive in the bidding process: More and more buyers, particularly in the public and quasi-public sectors, require proof of cybersecurity maturity. Without certification, you may be eliminated before your proposal is even reviewed.
- Facilitate cyber insurance and nLPD compliance: The process structures your practices—access management, backups, and awareness training. These are all requirements that insurers and the Data Protection Act already mandate.
- Identify your true vulnerabilities: The assessment highlights your actual weaknesses before an attacker finds them. Even if you’re not aiming for the certification logo, the report is worth reviewing—it serves as a prioritized action plan.
How the certification process works
- The assessment: online questionnaires, technical analysis of the infrastructure (internal and external vulnerability scans), and a full-scale phishing test: at least 3 emails per address, over 2 to 6 weeks, with an average click-through rate that must remain below 8.5%. You’ll receive a report on your security level and a list of measures to implement.
- Implementation of measures: You address the identified weaknesses on technical, organizational, and human levels.
- The audit: An expert verifies that the certification requirements are met. In exceptional cases and with written justification, the expert may recommend certification even if up to two criteria are not met.
- Validation: The application is reviewed by the certification committee, which awards the certification.
The certification is granted for two years, with follow-up measures in place during this period. Two useful points to note: the requirements are scaled according to an exposure category (5 categories, ranging from “non-critical” to “very critical”) calculated based on the value of your data relative to the number of employees, and the standard framework covers organizations with up to 250 employees (customized solutions are available for larger organizations).
As for the budget, the association publishes an online price calculator: the price includes the assessment and audit, based on the organization’s size and the number of sites.
Are you ready? Questions to ask yourself before getting started
Before beginning the process, take an honest look at your current situation: Are your backups tested? Is multi-factor authentication enabled? Would your teams be able to recognize a phishing email? Are your access credentials up to date? If you’re unsure about several of these points, it’s best to start with a thorough assessment: you’ll be better prepared for the evaluation, and the certification process will be much simpler as a result.
How We Support You
Obtaining certification requires time and expertise that few SMBs have in-house. We cover the entire process: assessing your security posture, prioritizing measures based on your budget and actual risks, testing your exposure through a penetration test, strengthening your infrastructure, and training your teams to combat phishing with our e-learning course iXsensi.
ANSAM is a partner of the Swiss Cyber-Safe certification: in practical terms, we know and understand the standards and requirements through experience. We guide our clients through the certification process step by step, from the initial assessment to the audit in compliance with the nLPD. If needed, your data can also be hosted in Switzerland on our sovereign cloud.
FAQ
How long is the Cyber-Safe certification valid?
The certification is granted for a period of two years, with follow-up measures throughout this time. When it expires, you don’t start from scratch: renewal builds on what’s already in place. We review the measures implemented and incorporate any new requirements that have emerged in the meantime, which become more stringent with each session. It is this continuous monitoring that gives the label its credibility, whereas certification is obtained once and for all.
Is my small business too small to get certified?
No. Cyber-Safe was specifically designed for SMEs, municipalities, and small organizations. The process adapts to your size and resources.
What happens if the assessment reveals vulnerabilities?
That’s the normal scenario, and that’s the whole point: you receive a list of measures to implement, you address them at your own pace, and then the audit validates the work. The assessment isn’t a pass-or-fail test—it’s the starting point for your action plan.
Conclusion
The Cyber-Safe certification turns your cybersecurity into tangible proof—for your customers, partners, and in response to RFP requests. The key is to treat it as the result of a genuine improvement in security, not as a mere formality. Wondering if your company is ready? Request an initial assessment with our teams.
Tags :
9/15/26, 10:00 AM