Cyber-Sicherheitsgesetz (CSG), Incident Notification
Cyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 6
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 February 2025.
A vulnerability and incident reporting rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds an essential or important entity under Article 1 and Annexes 1 and 2, which name an online-marketplace provider, an online-search-engine provider and a social-networking-platform provider (Annex 2 Item 6) among the digital-service providers it reaches expressly; the wider sector classes it also reaches are not separately flagged here, for the reason given on this jurisdiction's companion risk-management row.
- Notify the Stabsstelle Cyber-Sicherheit (Cyber Security Office) without delay, and in any event within 24 hours of becoming aware of a significant security incident, with an early warning stating, where relevant, whether the incident is suspected to result from unlawful or malicious acts or to have cross-border effect.
- Follow with a full notification within 72 hours of becoming aware, updating the early warning where relevant and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
- Submit an intermediate report on the Stabsstelle Cyber-Sicherheit's request, and a final report within one month of the 72-hour notification, describing the incident's severity and impact in detail, the likely threat or root cause, and the mitigation measures taken.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 23(1)'s penalty for an Article 4 or Article 6 infringement is an administrative fine (Busse) for an Übertretung (contravention), imposed by the Stabsstelle Cyber-Sicherheit only where the conduct does not itself constitute a criminal offence within the courts' jurisdiction; no provision reviewed here makes an Article 4 or Article 6 infringement itself a criminal offence.
Penalty structure
Article 23(2)(a) sets the fine for an essential entity's infringement, including a Article 4 or Article 6 infringement, at up to CHF 10,000,000 or up to 2 percent of the total worldwide turnover made in the preceding financial year by the undertaking to which the essential entity belongs, whichever amount is higher, mirroring NIS2 Article 34(4). Article 23(2)(b) sets an important entity's fine at up to CHF 7,000,000 or up to 1.4 percent of that turnover, whichever amount is higher, mirroring NIS2 Article 34(5).
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- CHF
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Stabsstelle Cyber-Sicherheit (Cyber Security Office), Liechtenstein's competent authority under the Cyber-Sicherheitsgesetz, which reviews compliance with Article 4's risk-management measures and Article 6's reporting duties and hosts Liechtenstein's CSIRT.
Settledness
- As of
- 15 September 2026
- Guidance link
- https://scs.llv.li
- Guidance body
- Stabsstelle Cyber-Sicherheit
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 6 requires an essential or important entity to notify the Stabsstelle Cyber-Sicherheit (Cyber Security Office) of a significant security incident without delay.
It requires an early warning within 24 hours of becoming aware of the incident, stating where relevant whether it is suspected to result from unlawful or malicious acts or to have cross-border effect, followed by a full notification within 72 hours that updates that assessment with the incident's severity, impact and any indicators of compromise.
An intermediate report is due on the Office's request, and a final report is due within one month of the 72-hour notification, describing the incident, its cause and its mitigation in detail. Annex 2 Item 6 names an online-marketplace provider, an online-search-engine provider and a social-networking-platform provider among the digital-service providers this duty reaches expressly.
When LexLint raises it
operates_social_platform
Read the law
Cyber-Sicherheitsgesetz (CSG), consolidated text, gesetze.li, Article 6