Skip to main content

Published on 8 September 2026

IT Service Continuity Management for AGOV (agov.ch/itscm)

AGOV is a central infrastructure for digital access to government services. It is therefore essential that the service not only operate reliably under normal conditions, but can also continue operating or be restored in a controlled manner following a serious disruption.

The Federal Chancellery, Digital Transformation and ICT Steering sector (FCh DTI), is therefore systematically strengthening AGOV’s crisis resilience as part of its IT Service Continuity Management (ITSCM).

The underlying principle is straightforward:

Technical redundancy only becomes effective resilience when failovers, restarts and recoveries actually work and are exercised on a regular basis.

External assessment identifies room for improvement

Digital Public Services Switzerland (DPSS) commissioned an external assessment of AGOV’s crisis resilience.

The assessment concludes that the existing technical and organisational arrangements need to be developed further. Particular attention is required for regularly exercised failovers between separate operating environments, verified backups, suitable offline backups, and documented and tested restart procedures.

Technical and organisational dependencies should also be made visible through realistic exercises. Lessons learned must subsequently be translated into concrete improvements.

This highlights an important distinction:

Redundancy and backups are essential, but the decisive factor is the demonstrated ability to restore service in an incident.

The Swiss Federal Audit Office also identifies a need for action

The Swiss Federal Audit Office (SFAO) reached comparable conclusions in its audit of the eIAM identity and access management system.

In its report published in 2025, it examined, among other things, the emergency failover of the eIAM core between the federal data centres “Primus” and “Campus”.

The complete failover was successful, but also revealed a number of technical challenges. The SFAO notes that certain issues need to be resolved before another full failover test is carried out. It also found that not all important components are included in regular failover tests.

At the time of the audit, there were also no concrete plans for the simultaneous failure of both data centres.

The SFAO assesses eIAM operations as stable overall, while identifying further room for improvement in service continuity.

For AGOV, the starting point is more demanding: a complete cross-site failover comparable to that of the eIAM core is not yet possible.

The external DPSS assessment and the SFAO audit therefore point in the same direction: continuity arrangements must be strengthened and their effectiveness demonstrated on a regular basis.

FCh DTI has defined a binding action plan

Based on these findings, FCh DTI has defined a concrete development and exercise plan for AGOV.

Strategic and technical direction lies with FCh DTI. Commissioned suppliers and service providers are responsible for implementing the corresponding measures.

The 2027 programme includes the following work:

  • completion of an additional AGOV operating environment outside the federal data centres;
  • active integration of this environment into productive operations;
  • introduction of active-active operation across multiple sites;
  • exercises covering failure and failover scenarios;
  • provision by the Federal Office of Information Technology, Systems and Telecommunication (FOITT) of a suitable offline backup of AGOV;
  • transfer of this backup to the additional operating environment;
  • complete restoration of AGOV from the backup;
  • execution and documentation of the restart process;
  • remediation and retesting of identified weaknesses.

This moves AGOV from conceptual preparedness towards demonstrable recovery capability.

Additional operating environment outside the federal data centres

FCh DTI has already commissioned the AGOV supplier to build AGOV additionally on the cloud platform of a provider based in Switzerland, at an operating location in Switzerland.

No cloud region of a global hyperscaler is used for this additional location.

The approach creates geographical, technological and operational diversity and reduces shared dependencies on data-centre, platform and operating infrastructures.

The additional environment is not intended to remain a passive standby site. It will be integrated into productive operations and used continuously.

Active-active during 2027

FCh DTI has commissioned FOITT to integrate the additional environment into productive AGOV operations in active-active mode during 2027.

Several operating environments will therefore form part of the productive system at the same time.

The main advantage is that the additional environment will not need to be activated for the first time during a crisis. Connections, components and operating procedures will already be in use and monitored during normal operations.

Once integration is complete, targeted failure scenarios will be exercised. These will include demonstrating that AGOV can continue operating when one operating environment becomes unavailable.

Offline backups as an independent recovery layer

Service continuity also requires independent protection of data.

For certain crisis scenarios, backups accessible through the same systems, networks or administrative access paths as the production environment are not sufficient.

AGOV therefore requires suitable offline backups whose integrity and completeness can be verified and which can be used independently of the production environment.

FOITT has been tasked with providing such backups.

The objective is not merely to preserve data, but to ensure that the service can actually be rebuilt from it.

2027: complete recovery from an offline backup

A comprehensive recovery exercise will therefore be carried out in 2027.

FOITT will provide a suitable offline backup of AGOV. The backup will be transferred to the additional operating environment. AGOV will then be fully restored there and brought back into operation.

The exercise will test the entire recovery chain:

  • Can the required backup be provided in an incident?
  • Is it complete, intact and technically usable?
  • Can it be used independently of the federal production infrastructure?
  • Are all required data and configurations available?
  • Can AGOV be fully rebuilt on the additional infrastructure?
  • Can the service, interfaces and dependent components be started successfully?
  • Are access rights, responsibilities and procedures sufficiently documented?

Recovery is only considered successful once the service is actually operational again.

The results will be documented. Identified weaknesses will be corrected and subsequently retested.

2027 as a year of implementation and exercises

The findings from the external reviews will therefore be translated into concrete technical and operational steps.

During 2027, in particular:

  • the additional operating environment will be completed;
  • active-active operation will be introduced;
  • cross-site failure and failover scenarios will be exercised;
  • suitable offline backups will be provided;
  • a complete recovery will be carried out in the additional environment;
  • the restart process will be documented;
  • identified weaknesses will be corrected and tested again.

The approach follows a clear cycle:

assess → implement → exercise → improve → reassess.

Exercises will become part of regular ITSCM

The work in 2027 forms the starting point for a permanent process.

In future, the following scenarios will be exercised regularly as part of the regular ITSCM process:

  • failure of individual technical components;
  • loss of an entire operating environment;
  • continued operation through remaining environments;
  • loss of communication links;
  • controlled failovers;
  • restart following a complete outage;
  • recovery from backups;
  • recovery from offline backups in another operating environment;
  • mobilisation of the required operations and application teams.

Lessons learned will be documented, improvement measures defined and their effectiveness tested again in subsequent exercises.

Resilience is therefore treated as a capability that must be maintained and continuously verified.

Multiple independent layers of protection

AGOV’s resilience is based on several complementary mechanisms:

  • high-availability operation;
  • geographically separated operating environments;
  • an additional operating platform outside the federal data-centre infrastructure;
  • technological and operational diversity;
  • active-active operation;
  • independent backups;
  • offline backups;
  • regularly exercised failovers;
  • regularly exercised recoveries;
  • documented restart procedures;
  • continuous improvement based on exercises, audits and real incidents.

No single measure is sufficient on its own. Resilience results from the interaction of several protection layers that are as independent from one another as possible.

Transparency about the current situation

Not all of the capabilities described above are available today.

AGOV does not yet provide complete cross-site failover capability comparable to that of the eIAM core.

Complete recovery from an offline backup provided by FOITT in an independent operating environment also still needs to be tested.

These gaps have been identified and the required measures have been commissioned.

During 2027, the additional operating environment will be actively integrated, failover capability will be established, and a full recovery from an offline backup will be carried out.

The requirements identified by DPSS and the SFAO are thus being translated into concrete technical and operational improvements.

Resilience is an end-to-end responsibility

AGOV is only one component of a digital government service.

For a digital government transaction to function during a crisis, end-user infrastructure, power supply, communication networks, internet connectivity, the relevant specialist application and its dependent systems must also remain available.

AGOV alone therefore cannot guarantee the availability of an entire digital government service.

For the part for which AGOV is responsible, however, the objective is clear:

Reduce dependencies, create independent recovery layers, exercise failovers and recoveries regularly, and systematically remedy identified weaknesses.

Further information

  • Swiss Federal Audit Office: Audit of the eIAM identity and access management system, SFAO-24141, 2025
  • Information on AGOV availability
  • Information on AGOV digital sovereignty