Let’s start with the answer to the question you are probably already asking yourself: IEC 62443 is not a legal obligation in Switzerland. No federal law requires it. It is a family of international standards, applied on a voluntary basis.
This does not mean it is optional for you. Over the past two or three years, it has been appearing in the specifications of industrial principals, in insurance questionnaires and in the tenders of large groups. The obligation does not come from the legislator, it comes from the contract. For an SME in French-speaking Switzerland supplying an equipment manufacturer, or a player in the energy or pharmaceutical sector, the difference is purely theoretical.
This article explains what this family of standards seeks to address, why office-grade IT security is not enough on a shop floor, and where to start when you operate a fleet of machines that cannot be replaced.
Why isn’t office security enough on the shop floor?
This is the central point, and it is widely misunderstood. Many business leaders think it is enough to extend to the shop floor what has been done for the offices: antivirus software, updates, a firewall. In practice, this approach fails.
In an office, the absolute priority is the confidentiality of data. You protect contracts, salaries, customer files. If a workstation fails, you restart it and carry on.
On a shop floor, the priority is availability and the safety of people. A halted production line costs money immediately, and equipment behaving unpredictably can injure someone. The industrial data itself rarely has value as a secret. It is the movement of the machine that matters.
Three very concrete consequences follow from this.
You do not restart a line the way you restart a computer. Bringing it back online can take hours: a purge, a return to temperature, a fresh qualification of the batch. The simple restart that fixes an office problem becomes a production decision here.
You do not update a controller in the middle of production. A software patch on a programmable logic controller changes the behaviour of a system that drives physical movements. It requires a shutdown window, testing, often the manufacturer’s validation, and sometimes a new machine safety acceptance.
Some machines will never be updated. A 2011 machining centre with a control panel running a discontinued operating system works perfectly and will still be producing in ten years. The manufacturer no longer publishes anything. The update is not delayed: it does not exist.
| Business IT (office) | Industrial IT (shop floor) | |
|---|---|---|
| Main priority | Data confidentiality | Availability and safety of people |
| Consequence of downtime | Inconvenience, rescheduled work | Production halted, batches lost, physical risk |
| Updates | Automatic, frequent | Planned, tested, sometimes impossible |
| Restart | Immediate, no stakes | Long, costly, requires a decision |
| Equipment lifecycle | 3 to 5 years | 15 to 25 years |
| Vendor support | Continuous | Often ended well before end of use |
| Who decides | The IT department | Production, together with IT |
This difference in nature explains why an industrial SME cannot simply copy its office rules onto its shop floor. It needs a framework designed for this environment. That is exactly what IEC 62443 offers.
What does this family of standards offer, without going into detail?
IEC 62443 is not a single document but a set of documents, published by the International Electrotechnical Commission, that cover the security of industrial automation and control systems.
Its overall structure is organised around four main blocks: common concepts and terminology, requirements addressing the organisation’s policies and procedures, those addressing the system as a whole, and finally those addressing components and their development.
The most useful point for a business leader to remember lies elsewhere. The standard distinguishes three roles, and you do not read the same parts depending on which one you occupy:
- the asset owner, who uses the installation in their plant;
- the integrator, who designs, assembles and commissions the solution;
- the manufacturer, who produces the machine or component.
An industrial SME in French-speaking Switzerland frequently wears two hats at once. It operates its own shop floor and manufactures machines that it delivers to its customers. These are two distinct undertakings, with different counterparts and deliverables.
The documents in the series are sold by the International Electrotechnical Commission and by national standardisation bodies. Their content cannot be freely reproduced, and this article does not do so: it describes their logic and structure, not their requirements clause by clause. Be wary of documents circulating for free that claim to reproduce the standard: they are often outdated, partial or simply wrong, and an approach built on them will not hold up before an auditor.
Zones and conduits: segment before you protect
This is the standard’s most important concept, and the easiest to understand.
A zone groups together equipment that shares the same security needs. A robotic cell forms a zone. The supervision system forms another. The office workstations of the quality department form a third.
A conduit is the controlled passage that connects two zones. All communication between zones passes through a conduit, and you explicitly decide what is allowed to travel through it.
The underlying idea is simple: instead of trying to individually secure dozens of pieces of equipment, many of which cannot be secured, you secure the boundaries between groups of equipment. The obsolete machine remains obsolete, but it can no longer be reached from just anywhere.
This is also what limits the spread of an incident. Ransomware that encrypts the administration’s file server will not reach the production line if the two networks are not flat and interconnected. Without segmentation, a compromised mailbox can bring a whole factory to a halt. With segmentation, it costs a day of office work.
Security levels: not everything deserves the same protection
Second structuring concept, just as accessible. The standard defines a scale of security levels, graded from lowest to highest, corresponding to the type of attacker you want to withstand.
The bottom of the scale addresses what is accidental: an operating error, a bad USB stick, an unfortunate connection. The top of the scale addresses an organised attacker, with substantial resources, time and skills specific to the industrial world.
The practical benefit is being able to state, zone by zone, which level you are aiming for. A cell driving a dangerous movement and an energy metering cabinet do not call for the same effort. This gradation avoids the two classic pitfalls: protecting everything to the maximum, which is financially impossible for an SME, or protecting nothing, for lack of knowing where to start.
Almost every industrial SME has left a remote maintenance access open for its machine suppliers. Often installed at commissioning, rarely documented, sometimes still active ten years later. This is the most frequently neglected entry point. Make a list of these accesses, check who is still using them, and disable them by default, opening them only on request. This single measure is worth several months of project work.
Where to start with an existing fleet of machines?
You are not going to replace your fleet, and no one is asking you to. The realistic approach is to protect the environment around machines that will remain as they are.
- Make an inventory of what is connected. Which machines have a network port, a Wi-Fi card, a modem, remote access? The answer almost always comes as a surprise. A list on a sheet of paper is enough to start.
- Separate the production network from the office network. This is the measure with the best effect-to-cost ratio. If your coffee machine, your accounting system and your injection press are on the same network, start here.
- Take back control of remote access. Who can come in, from where, with what authentication, and who is notified when it happens.
- Regulate removable media. The automation engineer’s USB stick remains a major infection vector in industrial environments, precisely because isolated machines get updated this way.
- Back up controller programs and configurations. Not just office files. A lost controller program means a restart measured in days. Apply the 3-2-1 backup rule to them.
- Identify your zones and set a target for each one. Only at this stage does the standard’s logic become actionable, because you finally know what you have.
- Document what you do. This is what a customer or an insurer will ask for, well before a certificate.
These steps do not require deep normative expertise. They require getting production and IT to talk to each other, which is often the real obstacle in an SME.
What this means for a Swiss SME today
The overall context is hardening. In 2025, the National Cyber Security Centre received 64,733 voluntary reports, compared with 62,954 in 2024. In the second half of 2025, 57 ransomware-related incidents were reported to it (NCSC, semi-annual report 2025/II, 30 March 2026). Industrial companies are among the targets, because a production halt creates payment pressure that few sectors experience.
At the same time, two regulatory movements affect Swiss manufacturers exporting to the European Union: the cybersecurity requirements for radio equipment and the European Cyber Resilience Regulation. These texts are binding for accessing the European market. We cover them in dedicated articles, on EN 18031 and on the CRA. An IEC 62443 approach already under way considerably eases dealing with them, since the concepts overlap significantly.
So remember the nuance: IEC 62443 remains voluntary under Swiss law, but it is becoming the common language of industrial security. Being able to speak about it with a customer or an insurer is becoming a commercial argument as much as a protective measure.
To assess your company in three minutes, the cyber check-up gives you a score and your three priorities. The other texts applicable to Swiss businesses are grouped in the Regulations pillar.