Switzerland DMARC & MTA-STS Adoption Report 2026
An exhaustive national audit across Swiss digital assets reveals that while baseline domain hygiene is widely maintained, organizational hesitation to enforce strict protection policies leaves key sectors exposed to Business Email Compromise (BEC), CEO fraud, and transport-layer eavesdropping. This exposure is particularly urgent in light of evolving regulatory requirements, including the revised Swiss Information Security Act (ISA), which introduced strict reporting obligations for critical infrastructure operators to report cyber incident vectors to the National Cyber Security Centre (NCSC) within 24 hours, as well as the enforced revised Federal Act on Data Protection (nFADP / revDSG) and financial sector standards from FINMA.