Switzerland is expanding its e-voting program.
Last month, the Swiss Federal Council granted the Canton of Lucerne a basic licence to conduct e-voting trials with a limited electorate. The licence runs through the federal vote on 26 November 2028, and the first authorised use will be the federal vote on 27 September 2026.
The significance extends beyond Switzerland.
As European municipalities, universities, unions, cooperatives and public institutions consider digital voting, Switzerland is establishing an important principle: verifiability should be a requirement, not an optional feature.
Switzerland also shows how far that standard still has to go. Voters can already check that their own ballot arrived correctly, and authorities can verify the complete result. What ordinary voters cannot yet do is verify the full result for themselves.
What complete verifiability means
Only completely verifiable systems can be authorized for e-voting trials.
Complete verifiability is defined in the Federal Chancellery’s Ordinance on Electronic Voting, and it combines two properties. Individual verifiability means each voter receives proof that the system registered the vote they intended to cast. Universal verifiability means auditors receive cryptographic proof that the result was correctly determined from the registered votes.
The definition comes with a strict trust model. Verification must never depend on trusting any single component, operator or authority. The ordinance is concrete down to the numbers: the probability of an attacker forging a voter’s proof must not exceed 0.1 percent.
Together, these requirements serve two purposes.
First, it ensures that attempts to manipulate the system can be reliably detected. Second, it creates transparency around whether the entire voting process was carried out correctly, while preserving the secrecy of every individual vote.
Switzerland supports this with published source code, independent examinations and divided responsibility across multiple systems and participants.
Let’s look at the verifiability being delivered.
1. Voters can check their own ballot
The system allows for individual verifiability.
Each voter receives unique return codes on paper with their voting documents. After voting online, the system displays a code. The voter compares it with the code printed beside their chosen option. When the codes match, the voter has evidence that their intended choice reached the electronic ballot box correctly.
It is a straightforward check that does not require the voter to understand the cryptography behind the system.
2. Electoral authorities can verify the complete result
The system allows for universal verifiability.
After voting closes, the Swiss system uses a Bayer-Groth verifiable mix network to shuffle and re-encrypt the ballots before they are counted.
Each mixer produces a zero-knowledge proof that the shuffle was performed correctly. The proof shows that the output contains the same encrypted votes as the input, only in a different order and under fresh encryption. It does this without revealing the new order of the ballots or how anyone voted.
The verifier checks these proofs to detect whether ballots were added, removed or modified during the mixing process.
Cantonal electoral authorities perform the checks using separate verification software. The verifier operates independently from the main voting system and runs on an offline machine.
If all the cryptographic evidence passes the checks, the verifier confirms the authenticity of the electronic votes and their counting, as explained in Swiss Post’s e-voting documentation.
Can the average person verify the complete result?
Not under the current public-facing process.
An ordinary voter can verify that their own choice reached the electronic ballot box by comparing the return codes.
Verification of the complete result is performed by cantonal electoral authorities using specialist software. Swiss Post publishes the source code, cryptographic protocol, technical documentation and verification software without requiring registration. Independent experts can inspect, compile, test and redevelop these components.
This means Swiss Post does not have exclusive control over how the system is examined. However, making verification technically available is not the same as making it usable by an ordinary voter.
Most people will not compile verification software or interpret cryptographic proofs. They must still rely on electoral authorities, auditors or technical experts to run the complete check and explain what it shows.
How Switzerland performs on verifiability
The return-code check is accessible.
But verification of the complete result remains difficult for non-specialists to perform and interpret.
Overall assessment: Switzerland meets a high standard for private and verifiable digital voting. The cryptographic evidence is published publicly, but verifying it requires specialist software that most voters will never use. Making verification accessible to ordinary voters, not just auditors, is where the standard needs to go further.
Making full-result verification accessible to ordinary voters
Shutter Governance offers one possible approach to addressing this.
The Shutter Governance system publishes the election result with a public cryptographic proof showing that every valid vote was counted correctly. The evidence is available without an account or special access.
An ordinary voter could use an AI assistant to guide them through the verification process and explain the output in plain language. The AI assistant would not replace the cryptographic verification or decide whether the result is correct. It would make the public evidence easier for an ordinary person to understand.
Europe should adopt the standard and improve it
National elections are not the only votes that require privacy and verifiability. Municipalities, universities, unions, cooperatives, associations and political parties all make important decisions through voting, and their digital voting systems should meet the same standard.
Switzerland has shown that complete verifiability can be made a formal requirement. But its current approach still places full-result verification mainly in the hands of electoral authorities and technical experts.
The next step is to make that verification of the full results possible for anyone. The result should not have to be accepted on the word of one institution. Independent organisations, journalists, auditors and technically capable citizens can check the same public evidence, while simpler verification tools can make the outcome understandable to everyone else.
Switzerland deserves credit for making verifiability a requirement for e-voting. Now the rest of Europe should follow.
Sources
- Swiss Federal Chancellery: E-voting media releases
- Swiss Federal Chancellery: Ordinance on Electronic Voting
- Swiss Federal Chancellery: Security in e-voting
- Swiss Federal Chancellery: Examination of e-voting systems
- Swiss Post: E-voting FAQ
- Swiss Post: E-voting community programme
- Swiss Post: Cryptographic protocol and documentation
- Swiss Post: Voting client ElGamal ciphertext implementation
- Swiss Post: Bayer-Groth mix network implementation
- Swiss Post: Separate verification software
- Swiss Post: Complete verifiability and verification of the count
About Shutter Governance
Shutter Governance is a new digital voting system for municipalities, universities, unions, cooperatives, political parties, NGOs, and other organizations, where votes stay hidden from everyone while the results remain publicly verifiable.
Learn how it works →