ICT minimum standard for SMEs: 106 tasks, no target

The federal ICT minimum standard lists 106 tasks and names a target value for none of them. That is deliberate, and the document states it explicitly as a refusal to give reference or target values.

Most people meet the standard differently. A customer sends a security questionnaire, the insurer wants to see something before renewal, or an industry association recommends "the minimum standard". At some point an Excel file with 106 rows lands in the IT inbox, gets filled in there, and at the end there is a radar chart with five axes and an overall score between 0 and 4.

Then comes the question the document does not answer: is 2.4 good?

What the ICT minimum standard is

The ICT minimum standard is a free federal recommendation for improving ICT resilience. It translates the NIST Cybersecurity Framework into 106 measures, organised along the five functions Identify, Protect, Detect, Respond and Recover. An Excel file for self-assessment comes with it. The Federal Office for Cyber Security (BACS) has been responsible for it since March 2024.

The Federal Office for National Economic Supply published it in 2018. The document contains the sentence that settles the target audience: the standard "is aimed in particular at operators of critical infrastructures, but is in principle applicable to any company or organisation and freely available". The assessment tool is available in German, French, Italian and English.

The measures carry short codes, and the document gives ID.AM-1 as its reading example. The first two letters denote the function, the second pair the category, the number the individual task. This system comes from the NIST framework, which is exactly why an answer taken from the minimum standard can later be explained to a customer who works in ISO language.

Do not confuse any of this with the German IT-Grundschutz. The minimum standard is the Swiss counterpart, with its own counting and its own tool.

Who it is mandatory for and who it is not

For most Swiss SMEs the ICT minimum standard is not mandatory. BACS calls it a recommendation. It is binding for individual sectors: for the electricity sector since 1 July 2024, and for gas suppliers since 1 July 2025. All other operators of critical infrastructures are recommended to implement it, not required to.

Even so, the standard increasingly lands on desks that have nothing to do with electricity or gas. Behind that are customers, insurers and procurement departments, not authorities. These groups need a language in which a security posture can be compared, and a free federal standard is an obvious choice for that.

Keep the two things apart. The minimum standard is a recommendation. Obligations arise elsewhere: from the Information Security Act, if you fall under it, from the duty to report a cyberattack, and from data protection law. A completed assessment satisfies none of these duties. It helps you place them calmly.

The line almost nobody reads

In the evaluation chapter there is a sentence that is rarely quoted. On the example charts it says: "These diagrams are explicitly examples and not reference or target values. Each organisation must define its own risk appetite independently and thereby set the corresponding level of protection (per category)."

In plain terms: the federal government hands you the yardstick and deliberately declines to say what counts as a pass.

That is technically correct. A water utility and a fiduciary office do not need the same maturity level under "Detect". A single target value for everyone would be too low for some and unaffordable for others. So the standard pushes the decision to where it belongs.

Only hardly anyone reads it that way. The chart looks like a result, even though it is a measurement without a reference point. Elsewhere the document notes that the measures described remain "ineffective without implementation by the companies".

Who sets the target value in your company

Defining risk appetite means deciding which disruption you can carry and which you cannot. That is a management decision, and in corporations it sits with the board of directors and its oversight duty. We have described how that oversight connects to cybersecurity in cyber liability on the board of directors.

If IT sets the target value instead, in our experience it goes one of two ways. Either too high, because specialists know what would be possible. Then you get a wish list that never receives a budget, and the assessment is not repeated the following year. Or too low, because the same people would later have to close the gaps themselves. Then self-assessment turns into self-absolution.

Neither is a character problem. It is the predictable consequence of one department rating its own work while also being allowed to define the target level.

The way out is unspectacular. Before anyone opens the Excel, a named person writes down one target value per function, with a date. Five lines. It takes half an hour and turns the 106 rows into a list of deviations instead of a list of grades. Only then does the evaluation become a basis for decisions.

Two scales that often get confused

The standard contains two different measurements, and that regularly causes confusion. One rates each individual task with a value between 0 and 4. The other describes the organisation as a whole and comes from the four implementation tiers of the NIST framework, named in the document as tier 1 "partial", tier 2 "risk informed", tier 3 "repeatable" and tier 4 "dynamic".

The difference is practical. The 0 to 4 says how far a single measure has been implemented. The tier says whether you handle risks systematically or decide case by case. A company can reach a 3 on many individual tasks and still sit at tier 1, because nobody holds the measures together. The good individual scores are then a snapshot that comes out differently next year without anyone changing anything.

For an SME the tier is usually the more informative number. It cannot be improved by one diligent afternoon in the Excel.

What the standard saves you

The minimum standard and its assessment tool are freely available. You buy no standard document, you pay no certification body, and you tie yourself to no vendor. Compared with the route through a certificate, this is the cheapest way to get a defensible statement about where you stand at all. What a certificate costs, and why the audit is the smallest item in it, is covered in ISO 27001 cost.

For many SMEs that is enough. If a customer wants to know how your security stands, an honest evaluation against a federal standard plus a list of measures with deadlines is often sufficient. You need a certificate when a customer or an industry explicitly demands one, not as a substitute for that answer.

What you are allowed to skip:

  • Tools sold with "mapping to the ICT minimum standard" as long as no target value exists. A mapping against an undefined target produces reports, not decisions.
  • An external audit across all 106 rows as a first step. Have it assessed internally first, and bring someone in from outside for the points where your own judgement is uncertain.
  • The chapters on industrial control systems, if you do not operate any.

If you then want to work through a gap in a structured way, that is exactly the work we do in a security assessment: translating the evaluation into a prioritised list with owners.

Where the self-assessment tips over in an SME

The standard was written for operators of critical infrastructures, and it shows. It contains material on industrial control systems, on the distinction between IT and ICS, and on network zones in production environments. If you run an office with 70 people and Microsoft 365, part of that does not apply to you. That is no flaw in the standard, but it means you have to mark rows as not applicable instead of scoring them 0. Otherwise your chart drops without any risk behind it.

106 rows is a lot for one afternoon. The temptation is to click through quickly. A row scored 3 without evidence is worse than an honest 0, because nobody will question that 3 the following year. If no evidence comes to mind for a task, the answer is not 3.

And the average smooths things out. A 4 under "Protect" next to a 0 under "Recover" produces a comfortable overall score. The overall score is the least useful number in the file. The zeros are the interesting part. That the one security number does not exist is a topic of its own: how secure is my company.

For the assessment to hold at all, you need a reasonably current record of your own systems first. The standard begins with asset management, and for good reason: you cannot assess what you do not know about. More on that in asset inventory.

Before you open the Excel

Write down three things before filling anything in. Who decides the target level, by name. Which maturity level should be reached per function, and by when. And who looks at the evaluation again in twelve months.

After that, filling it in is craft. Without those lines you get a chart that looks good and triggers nothing. Purchased assessments fail at the same point, and there too the report is not the product.

As an entry point before a certification project, the minimum standard works well. The difference between a gap list and the ability to operate is shown by the gap analysis against ISO 27001. And if you want to start with the terms, you will find them sorted in our overview of information security in SMEs.

If you want a second opinion on prioritisation or on the target level, talk to us. A first conversation is free of obligation and costs you half an hour.

If your assessment came out at 2.4 today, who in your company would be allowed to say that this is enough?

Frequently asked questions

Is the ICT minimum standard mandatory for SMEs?

For most Swiss SMEs it is not. BACS explicitly calls the ICT minimum standard a recommendation. It is binding for the electricity sector since 1 July 2024 and for gas suppliers since 1 July 2025. All other operators of critical infrastructures are recommended to implement it, not required to.

What does the ICT minimum standard cost?

Nothing. The document and the Excel assessment tool are freely available from the Federal Office for Cyber Security in German, French, Italian and English. You buy no standard document and pay no certification body. Effort starts with filling it in, and then with closing the gaps it reveals.

Which maturity level in the ICT minimum standard is enough?

The standard deliberately does not say. The document states that the example charts are not reference or target values and that each organisation must define its own risk appetite. So the target value per function is set by management, not by IT, and ideally before the Excel is filled in.