Just 0.15 percent of all security certificates securing Switzerland’s active .ch domains originate from domestic providers, according to a comprehensive study by Austrian monitoring specialist Risikomonitor released in late June 2026. This stark over-reliance on foreign authorities, predominantly US-based tech giants, exposes a systemic architectural vulnerability where a political or legal revocation of foreign trust could effectively paralyze the entire Swiss web infrastructure.
The Illusion of Hosting Sovereignty
On the surface, Switzerland’s digital real estate appears strongly localized. Over half—specifically 51.7 percent—of all .ch domains run on servers physically located within Swiss borders. Neighboring Germany hosts 18.4 percent, while the United States accounts for 17.1 percent. Yet physical location tells only half the story.
When factoring in corporate ownership, true national control plummets to just 42 percent. A primary driver of this disparity is Metanet, a major player in the Swiss market that is ultimately owned by a British parent company. The server-IP layer further complicates the picture. Switzerland ranks third in server-IP hosting at 21.5 percent, trailing both the US at 29.9 percent and Germany at 28.2 percent. Domestic hosting dominance is concentrated among a few heavyweights: Hostpoint manages 281’092 domains, Infomaniak handles 196’506, and Metanet controls 171’766. Together, these three firms anchor roughly 30 percent of the entire national namespace.
Technical resilience remains high. The study highlights that 91.5 percent of reachable hosts support TLS 1.3, with nearly all others utilizing TLS 1.2. But this cryptographic strength exists in a state of deep operational dependency.
The US Monopoly on Cryptographic Trust
The most alarming bottleneck revealed by the Risikomonitor data lies in certificate authorities (CAs). Out of active domains, a staggering number of certificates rely on certificates issued by US-headquartered entities, including Let’s Encrypt, DigiCert, and Google Trust Services. Domestic providers account for a microscopic 0.15 percent.
This dynamic creates what security researchers describe as a potential “kill switch” scenario. If trust in these US-based certificates were ever revoked via political fiat or extraterritorial legal mandates, nearly the entire Swiss web ecosystem would instantly throw fatal handshake errors to incoming browsers. Security in transit and sovereignty of control are structurally divorced.
Application Layers and the E-Mail Vulnerability
Moving up the OSI stack, the application layer reveals even deeper entanglements with American technology platforms. Fully 77.6 percent of .ch domains embed at least one US service, such as Google Fonts, Cloudflare, Amazon Web Services (AWS), or Wix. These dependencies dictate functional loading processes, asset delivery, and external resource calls.
Simple optimizations, such as loading Google Fonts, actively transmit visitor IP addresses back to American servers—a mechanism flagged by the study’s authors as legally fraught under stringent data privacy expectations. Because these application dependencies remain largely invisible to everyday users, they represent a major blind spot for digital sovereignty.
Electronic mail presents an equally acute risk vector. Approximately 19.4 percent of .ch mail domains route their message queues directly through Microsoft or Google infrastructure. Risikomonitor points to email routing as the single most critical structural vulnerability facing the application layer of the Swiss internet.
While the country maintains a viable foundation of domestic hosting providers, the layers built directly on top of them remain tethered to foreign conglomerates. As digital infrastructure evolves toward tighter integration, the data proves that operational stability and jurisdictional independence are heading in opposite directions.