Cybersecurity obligations are tightening rapidly: from 11 September 2026, any manufacturer selling products in the EU must report vulnerabilities, including for products already on the market. In Switzerland, failing to report certain cyberattacks to the Federal Office for Cybersecurity (OFCS) can lead to fines of up to CHF 100,000. At the same time, the projected shortage of 54,400 ICT specialists by 2033 means the biggest challenge may be finding the expertise needed to meet these new compliance requirements.

26 July 2026 • FED Engineering • 1 min

Two calendars, and only one is still negotiable

Swiss manufacturers operate under two regimes: Swiss law for their operations, EU law for their exported products. The deadlines do not line up.

Regulatory deadlines applying to Swiss industry

Date Instrument What applies Who is caught
1 April 2025 Information Security Act (ISA) Report any cyberattack to the Federal Office for Cybersecurity within 24 hours Swiss critical infrastructure operators
1 October 2025 ISA Fines up to CHF 100,000 for failure to report Same
11 June 2026 Cyber Resilience Act (EU 2024/2847) Regime for conformity assessment bodies Notified bodies
11 September 2026 Cyber Resilience Act, Art. 14 Reporting of actively exploited vulnerabilities and severe incidents, via the ENISA platform Any manufacturer selling in the EU, including existing products
11 December 2027 Cyber Resilience Act Full application: no compliance, no CE marking Hardware, software and industrial control systems sold in the EU

The fourth row is the one that matters. Many Swiss industrial firms have anchored their planning on December 2027 and treat 2026 as a preparation year. That reading is wrong: the reporting duty switches on this September, independently of full application, and it covers what is already in the field. A manufacturer of industrial controls with no coordinated disclosure channel and no notification procedure has seven weeks to build one. Penalties reach EUR 15 million or 2.5 % of worldwide turnover, but the real consequence lies elsewhere: no compliance, no CE marking, no sale.

The Swiss duty: who reports, and who is exempt

One confusion still circulates: the NCSC and the FOCS are not two bodies. The National Cyber Security Centre became the Federal Office for Cybersecurity (FOCS), attached to the Federal Department of Defence. There is a single counterpart.

The duty covers nine sectors: authorities, energy, waste disposal, finance, health, information and communication, food supply, public safety, transport. Reports are filed within 24 hours through the Cyber Security Hub — roughly 1,600 members at the end of 2025 — and may be completed within fourteen days.

The exemption is less well known: companies with fewer than 50 employees and less than CHF 10 million in turnover or balance sheet total in the critical infrastructure activity are exempt. Both conditions are cumulative. A 60-person subcontractor in the energy sector is caught.

What the reports show

The FOCS annual report of February 2026 records 222 mandatory notifications by the end of 2025, rising to 325 cumulatively in the semi-annual report of March 2026. In the second half of 2025 they came mainly from public administration (25 %), IT and telecommunications firms (18 %) and banking and insurance (15.7 %). Voluntary reports reached 64,733 in 2025, around 2,000 more than in 2024.

What the figures do not show is the manufacturing share, which is thin among mandatory notifications. Either industry is targeted less, or it detects less. Our reading at Fed Engineering favours the second: you only report what you see, and seeing requires people able to look.

Why OT is not run like IT

The difference is not a technical nuance, it is an inversion of priorities. It explains why transplanting an IT team onto a plant floor fails.

Two security logics

Criterion IT environment OT / ICS environment
First priority Data confidentiality Availability and personal safety
Equipment lifecycle 3 to 5 years 15 to 30 years
Update window Weekly, automated Planned production shutdown, sometimes annual
Consequence of an incident Leak, service unavailable Line stoppage, equipment damage, human risk
Natural owner IT department Production and maintenance

The last row is the costly one. On most of the Swiss sites we work with, the controller estate does not sit with the IT department and nobody formally owns it from a security standpoint. Governance is missing before technology is.

The bottleneck is not technological, it is human

ICT-Berufsbildung Schweiz quantified the need in September 2025: 266,000 people worked in ICT occupations in 2024, and 128,600 more will be needed by 2033. The education system will supply 44,400 and migration around 29,800, leaving a shortfall of 54,400. Two thirds of these professionals work outside the ICT sector — in industry, precisely. Salary ranges give the cost of entry.

Gross annual salaries observed in Switzerland

Role Range Source
SOC analyst CHF 75,000 – 130,000 Michael Page, published April 2026
Cybersecurity engineer CHF 90,000 – 130,000 (median 115,000) swissdevjobs.ch
Information Security Officer CHF 130,000 – 180,000 Michael Page
CISO CHF 170,000 – 280,000 Michael Page

These benchmarks cover IT profiles. For a genuinely OT role — someone who reads a process diagram as fluently as a traffic table — supply narrows and offers land at the top of the range. We routinely see four to six months to fill these mandates, against eight to ten weeks for a generalist IT security profile: the engineer shortage in Switzerland in its sharpest form.

What a team costs, and what its absence costs

A representative case from Swiss industry: 180 employees, CHF 42 million turnover, 60 % exported to the EU, so roughly CHF 25 million of revenue exposed to the Cyber Resilience Act.

Annual cost of an in-house OT security function

Cost item Annual amount
OT security manager, gross salary CHF 140,000
Employer contributions (around 15 %, depending on age and pension plan) CHF 21,000
Certification and continuing education CHF 8,000
Occasional external support (audit, standards expertise) CHF 25,000
Total CHF 194,000

That is 0.78 % of the revenue being protected. Set against the regulation's penalty ceiling of 2.5 % of worldwide turnover, and above all against loss of CE marking, which is not measured in fines but in market closure.

Our position at Fed Engineering is blunt: on an exporting site, outsourcing the entire OT security function is a mistake. A provider audits, documents and leaves, whereas Cyber Resilience Act compliance is a continuing duty of monitoring and reporting across the product lifecycle. It requires someone who stays. The model that works pairs an internal lead with external support at peaks, not the reverse.

Four profiles, in this order

Companies that get compliance right do not hire four people at once: they sequence.

  • The OT security manager. First hire, and the only one that cannot be delegated. Typical profile: automation or electrical engineer with seven to twelve years on the floor, upskilled into security through certification. A pure IT specialist fails here — they do not speak the language of production.
  • The industrial network engineer. Segmentation, asset mapping, architecture. Often recruitable internally from maintenance teams, with eighteen months of training.
  • The product compliance lead. Underestimated everywhere. They own the CRA file, the technical documentation and the reporting channel. A quality or regulatory affairs profile retrained internally is usually faster than an external hire.
  • The detection analyst. Last, and only if volume justifies it. Below a certain threshold, an outsourced monitoring service beats an isolated post.

On the first two profiles, internal retraining beats external recruitment about half the time, provided certification is funded: the available routes are set out in our piece on continuing education for engineers. For external hiring, see our guide to recruiting engineers in Switzerland.

Frequently asked questions

Is a Swiss SME that does not export affected by the Cyber Resilience Act?

Not directly. But if it supplies a component built into a product sold in the EU, its customer will pass the requirement down by contract. The obligation travels up the supply chain.

Will Switzerland transpose NIS2?

No adoption is planned. The Information Security Act and its reporting duty are the Swiss answer, over a narrower perimeter. Swiss companies meet NIS2 through their European customers, not through their own law.

Is IEC 62443 mandatory in Switzerland?

No, it is a standard, not a law. It becomes contractually required in many industrial tenders, which produces much the same effect.

Does a 200-person manufacturer need a CISO?

Rarely. An OT security manager reporting to the technical director covers the real need at a third of the cost. The CISO title makes sense from several sites and a broad IT perimeter upwards.

Useful resources and documents

Read also

Sources

  • FOCS, Annual Report 2025 (16.02.2026) and Semi-annual Report H2 2025 (30.03.2026); Federal Council statement of 07.03.2025; Information Security Act and Cybersecurity Ordinance.
  • Regulation (EU) 2024/2847 on cyber resilience, Art. 14 and 71; Swissmem and SNV implementation notes.
  • ICT-Berufsbildung Schweiz, skilled labour requirements study, September 2025.
  • Michael Page, Swiss IT salary data (April 2026); swissdevjobs.ch.