Duration: 10 minutes For whom: Admin / Owner of a Swiss SME aiming for the Cyber-Safe label Prerequisite: Having created your organisation
The Cyber-Safe label is a Swiss label issued by the Cyber-Safe Association (an official implementation partner of the national cybersecurity strategy of the OFCS / BACS). It targets organisations with 250 employees or fewer.
⚠️ Important: CyberPassport does not issue the Cyber-Safe label. What you do here is a preparatory self-assessment that helps you understand your exposure level and prepare for the official audit carried out by an accredited Cyber-Safe auditor.
Understanding the methodology
The Cyber-Safe label uses categorisation by exposure level based on the value of your data.
The 4 amounts to estimate (in CHF)
- C — Confidentiality: cost of a data leak (nLPD/GDPR penalties, loss of customers, legal fees)
- I — Integrity: cost of data corruption (wrong decisions, reconstruction from backups)
- AT — Temporary Absence: loss of operations during a 10-business-day outage
- AD — Permanent Absence: total cost if your data and systems were permanently destroyed
The 2 calculations
- Vtd (Total value of data) = C + I + AT + AD
- Vrd (Relative value per FTE) = Vtd / number of FTEs
The 5 exposure categories
| Vrd (CHF) | Category | Label |
|---|---|---|
| ≤ 10,000 | 1 | Non critical |
| 10,000 – 20,000 | 2 | Low criticality |
| 20,000 – 50,000 | 3 | Medium criticality |
| 50,000 – 100,000 | 4 | Critical |
| > 100,000 | 5 | Highly critical |
The higher your category, the more controls the Cyber-Safe framework requires of your organisation.
Step 1 — Launch the activation
- Go to Settings → Frameworks (
/settings/frameworks). - At the bottom of the page, find the "Cyber-Safe label (Switzerland)" card.
- Click the purple "Activate Cyber-Safe" button.
📸 Screenshot location: Cyber-Safe card in /settings/frameworks
You arrive on the 4-step categorisation wizard (/onboarding/cyber-safe-scope).
Step 2 — The wizard (4 steps)
Step 1/4 — Eligibility
Enter your total headcount (headcount — individuals under an active contract, permanent + fixed-term + apprentices).
⚠️ Important: the standard Cyber-Safe label targets organisations of ≤ 250 employees. Beyond that, the Cyber-Safe Association defines tailored requirements through its labelling commission (outside of self-assessment).
If you enter more than 250, you will see a message directing you to cyber-safe.ch.
📸 Screenshot location: eligibility step with headcount field
Step 2/4 — Your organisation
3 pieces of information to enter:
- Full-time equivalent (FTE): sum of occupancy rates (e.g. 1.0 + 0.8 + 0.5 = 2.3 FTE)
- Number of devices: workstations, laptops, work smartphones (excluding network equipment)
- Type of organisation: SME / private company OR Municipality / public administration
🟣 Tip: this information is saved on your organisation and reused by any future framework (CIS, ISO SoA, etc.). You only enter it once.
📸 Screenshot location: step 2 with the 3 fields filled in
Step 3/4 — CHF impacts
This is the step that requires the most thought: putting a figure on the 4 impacts (C / I / AT / AD).
💡 Good to know: you are not required to know these figures precisely. CyberPassport offers an AI-assisted estimate.
Option A — AI estimate (recommended if you're starting out)
- Click the purple banner "✨ Not sure about the amounts? Let the AI suggest an estimate."
- In the window that opens, describe your business in a few sentences:
"IT consulting SME, 5 people, about 800,000 CHF turnover, client files on Office 365, heavy reliance on email and laptops."
- (Optional) Specify your constraints: nLPD, banking secrecy, medical data…
- Click "✨ Estimate".
- After 2 to 5 seconds, the AI suggests the 4 amounts with a confidence level (low / medium / high) and a rationale explaining how it arrived at these figures.
- Click "Use these values" → the wizard's 4 fields are pre-filled.
- You can adjust manually if you find an amount too high or too low.
📸 Screenshot location: AI estimate modal with result displayed
⚠️ Important: the amounts suggested by the AI are estimates based on your description. They are not official figures. You remain free to adjust them.
Option B — Manual entry
If you have your own estimates or an in-house risk officer, enter the 4 amounts directly. Each field has an indicative range in its placeholder (e.g. "30,000 – 80,000" for C).
Step 4/4 — Summary
You see:
- Scope: headcount, FTE, devices, type
- Vtd: sum of the 4 impacts (total data to protect)
- Vrd: Vtd divided by FTE (value per person)
- Exposure category: 1 to 5, with a colour (green → red)
- Non-substitution disclaimer (reminder)
Click "Activate Cyber-Safe".
📸 Screenshot location: summary step with Vtd/Vrd/Category
Step 3 — After activation
On the Settings → Frameworks card
The Cyber-Safe card now shows:
- ✅ Your exposure category (e.g. "Category 2 — Low criticality")
- "Modify my scope" button (to re-edit if your business changes)
- Discreet "Deactivate" link (see below)
📸 Screenshot location: Cyber-Safe card after activation, with category displayed
In your report
When you publish your assessment, the report contains a dedicated Cyber-Safe section:
- Purple banner "Cyber-Safe · V3.0"
- Non-substitution disclaimer prominently displayed
- Your organisation's scope (headcount, FTE, devices, type)
- Your Vtd / Vrd / Exposure category calculations
- Methodological note
Modify or deactivate
Modify my scope
If your business evolves (turnover, headcount, new risks):
- Settings → Frameworks → Cyber-Safe card → "Modify my scope".
- The wizard reopens with all your entries pre-filled.
- Modify the values you want.
- Confirm → the category is recalculated automatically.
Deactivate Cyber-Safe
If you change your mind and prefer to no longer display Cyber-Safe in your report:
- Settings → Frameworks → Cyber-Safe card → grey "Deactivate" link.
- In-place confirmation: "You can reactivate later — your inputs are preserved."
- Click "Confirm deactivation".
- The card returns to its initial state ("Activate Cyber-Safe" button).
💡 Good to know: deactivation does not erase your entries (CHF impacts, company facts). If you reactivate later, the wizard picks up where you left off.
⚠️ Important: if the platform administrator temporarily disables the Cyber-Safe framework (e.g. following a change to the partnership with the Cyber-Safe Association), the card temporarily disappears from your interface. The scope remains saved and will return as soon as it is reactivated.
For Cyber-Safe certifiers
If you are an accredited Cyber-Safe auditor reviewing an SME's report:
- The report's dedicated section contains all the values you need for your initial analysis: Vtd / Vrd / Category + scope
- The non-substitution disclaimer is explicit — the SME knows that CyberPassport does not replace your audit
- The values are frozen at the moment of sealing (see guide 07)
- The Cyber-Safe block is only shown if the SME has completed its scope (Vtd / Vrd / Category present in the database)
Next step
→ Invite my team and my auditors → Or back to the dashboard