Two calendars, and only one is still negotiable
Swiss manufacturers operate under two regimes: Swiss law for their operations, EU law for their exported products. The deadlines do not line up.
Regulatory deadlines applying to Swiss industry
| Date | Instrument | What applies | Who is caught |
|---|---|---|---|
| 1 April 2025 | Information Security Act (ISA) | Report any cyberattack to the Federal Office for Cybersecurity within 24 hours | Swiss critical infrastructure operators |
| 1 October 2025 | ISA | Fines up to CHF 100,000 for failure to report | Same |
| 11 June 2026 | Cyber Resilience Act (EU 2024/2847) | Regime for conformity assessment bodies | Notified bodies |
| 11 September 2026 | Cyber Resilience Act, Art. 14 | Reporting of actively exploited vulnerabilities and severe incidents, via the ENISA platform | Any manufacturer selling in the EU, including existing products |
| 11 December 2027 | Cyber Resilience Act | Full application: no compliance, no CE marking | Hardware, software and industrial control systems sold in the EU |
The fourth row is the one that matters. Many Swiss industrial firms have anchored their planning on December 2027 and treat 2026 as a preparation year. That reading is wrong: the reporting duty switches on this September, independently of full application, and it covers what is already in the field. A manufacturer of industrial controls with no coordinated disclosure channel and no notification procedure has seven weeks to build one. Penalties reach EUR 15 million or 2.5 % of worldwide turnover, but the real consequence lies elsewhere: no compliance, no CE marking, no sale.
The Swiss duty: who reports, and who is exempt
One confusion still circulates: the NCSC and the FOCS are not two bodies. The National Cyber Security Centre became the Federal Office for Cybersecurity (FOCS), attached to the Federal Department of Defence. There is a single counterpart.
The duty covers nine sectors: authorities, energy, waste disposal, finance, health, information and communication, food supply, public safety, transport. Reports are filed within 24 hours through the Cyber Security Hub — roughly 1,600 members at the end of 2025 — and may be completed within fourteen days.
The exemption is less well known: companies with fewer than 50 employees and less than CHF 10 million in turnover or balance sheet total in the critical infrastructure activity are exempt. Both conditions are cumulative. A 60-person subcontractor in the energy sector is caught.
What the reports show
The FOCS annual report of February 2026 records 222 mandatory notifications by the end of 2025, rising to 325 cumulatively in the semi-annual report of March 2026. In the second half of 2025 they came mainly from public administration (25 %), IT and telecommunications firms (18 %) and banking and insurance (15.7 %). Voluntary reports reached 64,733 in 2025, around 2,000 more than in 2024.
What the figures do not show is the manufacturing share, which is thin among mandatory notifications. Either industry is targeted less, or it detects less. Our reading at Fed Engineering favours the second: you only report what you see, and seeing requires people able to look.
Why OT is not run like IT
The difference is not a technical nuance, it is an inversion of priorities. It explains why transplanting an IT team onto a plant floor fails.
Two security logics
| Criterion | IT environment | OT / ICS environment |
|---|---|---|
| First priority | Data confidentiality | Availability and personal safety |
| Equipment lifecycle | 3 to 5 years | 15 to 30 years |
| Update window | Weekly, automated | Planned production shutdown, sometimes annual |
| Consequence of an incident | Leak, service unavailable | Line stoppage, equipment damage, human risk |
| Natural owner | IT department | Production and maintenance |
The last row is the costly one. On most of the Swiss sites we work with, the controller estate does not sit with the IT department and nobody formally owns it from a security standpoint. Governance is missing before technology is.
The bottleneck is not technological, it is human
ICT-Berufsbildung Schweiz quantified the need in September 2025: 266,000 people worked in ICT occupations in 2024, and 128,600 more will be needed by 2033. The education system will supply 44,400 and migration around 29,800, leaving a shortfall of 54,400. Two thirds of these professionals work outside the ICT sector — in industry, precisely. Salary ranges give the cost of entry.
Gross annual salaries observed in Switzerland
| Role | Range | Source |
|---|---|---|
| SOC analyst | CHF 75,000 – 130,000 | Michael Page, published April 2026 |
| Cybersecurity engineer | CHF 90,000 – 130,000 (median 115,000) | swissdevjobs.ch |
| Information Security Officer | CHF 130,000 – 180,000 | Michael Page |
| CISO | CHF 170,000 – 280,000 | Michael Page |
These benchmarks cover IT profiles. For a genuinely OT role — someone who reads a process diagram as fluently as a traffic table — supply narrows and offers land at the top of the range. We routinely see four to six months to fill these mandates, against eight to ten weeks for a generalist IT security profile: the engineer shortage in Switzerland in its sharpest form.
What a team costs, and what its absence costs
A representative case from Swiss industry: 180 employees, CHF 42 million turnover, 60 % exported to the EU, so roughly CHF 25 million of revenue exposed to the Cyber Resilience Act.
Annual cost of an in-house OT security function
| Cost item | Annual amount |
|---|---|
| OT security manager, gross salary | CHF 140,000 |
| Employer contributions (around 15 %, depending on age and pension plan) | CHF 21,000 |
| Certification and continuing education | CHF 8,000 |
| Occasional external support (audit, standards expertise) | CHF 25,000 |
| Total | CHF 194,000 |
That is 0.78 % of the revenue being protected. Set against the regulation's penalty ceiling of 2.5 % of worldwide turnover, and above all against loss of CE marking, which is not measured in fines but in market closure.
Our position at Fed Engineering is blunt: on an exporting site, outsourcing the entire OT security function is a mistake. A provider audits, documents and leaves, whereas Cyber Resilience Act compliance is a continuing duty of monitoring and reporting across the product lifecycle. It requires someone who stays. The model that works pairs an internal lead with external support at peaks, not the reverse.
Four profiles, in this order
Companies that get compliance right do not hire four people at once: they sequence.
- The OT security manager. First hire, and the only one that cannot be delegated. Typical profile: automation or electrical engineer with seven to twelve years on the floor, upskilled into security through certification. A pure IT specialist fails here — they do not speak the language of production.
- The industrial network engineer. Segmentation, asset mapping, architecture. Often recruitable internally from maintenance teams, with eighteen months of training.
- The product compliance lead. Underestimated everywhere. They own the CRA file, the technical documentation and the reporting channel. A quality or regulatory affairs profile retrained internally is usually faster than an external hire.
- The detection analyst. Last, and only if volume justifies it. Below a certain threshold, an outsourced monitoring service beats an isolated post.
On the first two profiles, internal retraining beats external recruitment about half the time, provided certification is funded: the available routes are set out in our piece on continuing education for engineers. For external hiring, see our guide to recruiting engineers in Switzerland.
Frequently asked questions
Is a Swiss SME that does not export affected by the Cyber Resilience Act?
Not directly. But if it supplies a component built into a product sold in the EU, its customer will pass the requirement down by contract. The obligation travels up the supply chain.
Will Switzerland transpose NIS2?
No adoption is planned. The Information Security Act and its reporting duty are the Swiss answer, over a narrower perimeter. Swiss companies meet NIS2 through their European customers, not through their own law.
Is IEC 62443 mandatory in Switzerland?
No, it is a standard, not a law. It becomes contractually required in many industrial tenders, which produces much the same effect.
Does a 200-person manufacturer need a CISO?
Rarely. An OT security manager reporting to the technical director covers the real need at a third of the cost. The CISO title makes sense from several sites and a broad IT perimeter upwards.
Useful resources and documents
- Federal Office for Cybersecurity (FOCS) — reporting duty and semi-annual reports
- Swissmem — industrial cybersecurity and Cyber Resilience Act guidance
- Fedlex — Information Security Act and Cybersecurity Ordinance
Read also
- Future specialisations in engineering: robotics, AI, cleantech
- Automation technician in Switzerland: what do you actually earn?
- Engineer of the future: which specialisations survive and which disappear
- Software, data and ML engineer salaries in Switzerland
- Work permits for foreign engineers in Switzerland
Sources
- FOCS, Annual Report 2025 (16.02.2026) and Semi-annual Report H2 2025 (30.03.2026); Federal Council statement of 07.03.2025; Information Security Act and Cybersecurity Ordinance.
- Regulation (EU) 2024/2847 on cyber resilience, Art. 14 and 71; Swissmem and SNV implementation notes.
- ICT-Berufsbildung Schweiz, skilled labour requirements study, September 2025.
- Michael Page, Swiss IT salary data (April 2026); swissdevjobs.ch.