IoT cyber security regulation in Switzerland

What the IoT cyber security regulation of Switzerland requires, whether it is in force and mandatory, and whether ETSI EN 303 645 is enough to comply.

Last updated

One regulation recorded for Switzerland in the panorama of IoT cyber security regulations, which compares every country that regulates the cyber security of connected products.

Loi fédérale sur la cybersécurité

DDPS · 24 September 2026 · last reviewed ETSI EN 303 645 can be used

QuestionAnswer
Is the regulation in force? No
Scope Hardware and software
Who must follow the regulation? Manufacturers, importers, distributors, commercial open source
Mandatory or Voluntary? Mandatory
Is there a label or a certification? To be confirmed
Does the regulation mandate baseline security requirements? Yes
Are there additional requirements to the baseline security? To be confirmed
Does the regulation contains assurance levels? To be confirmed
Is compliance with ETSI EN 303 645 a requirement? To be confirmed
Can ETSI EN 303 645 be used to comply with the regulation? Yes
Are other standards or guidance referenced? (cf. regulation) To be confirmed

Read the regulation

Every other country

Licence: Free to use for non-commercial purposes. Any use must credit cetome and link to cetome.com/panorama. The data is also open on GitHub.

Next step

Put this research to work

Our research shows where the rules stand. To build secure-by-default products, we help you define a product security strategy and put it into practice across your organisation.