Building automation is now fully networked, which increases the demands on the protection, integrity and availability of your systems. SAUTER addresses these challenges with a consistent secure-by-design approach: Our development processes are certified according to IEC 62443-4-1 and ensure that security begins in the concept phase and accompanies the entire product lifecycle.
We comply with international and national standards such as BSI Basic Protection, VDMA 24774:2023, the French CSPN programme (recognised by the BSI) and the upcoming EU regulations NIS-2, CRA and RED-DA – and also take into account the British requirements of the PSTI Act (Product Security and Telecommunications Infrastructure). We are currently seeking CSPN certification for our modulo 6 modular controller family.
Transparency and continuous improvement are key components of our programme: Together with CERT@VDE, we publish open security advisories, invite customers to report potential vulnerabilities and regularly participate in hackathons and audits. In terms of technology, we primarily rely on BACnet Secure Connect for end-to-end encrypted communication.
This is how we lay the foundation for digital buildings that are not only smart, but also permanently secure.
Secure-by-design development All our product development follows the certified IEC 62443-4-1 process. This allows us to integrate security requirements from the initial idea to end-of-life and create a defence-in-depth architecture that effectively minimises vulnerabilities.
Continuous SBOM monitoring: Automated tools check our bill of materials software daily for newly disclosed vulnerabilities (CVEs). This allows us to identify critical dependencies immediately and deploy patches quickly.
Active community engagement We regularly participate in hackathons, industry conferences and red team tests to bring fresh insights directly into our products and processes.
BACnet Secure Connect on board All new SAUTER controllers support BACnet SC – the future-proof, TLS-encrypted communication standard for building networks and cloud connectivity.
Direct line to the PSIRT You can reach our Product Security Incident Response Team (PSIRT) around the clock via our contact form to report potential vulnerabilities quickly and confidentially.
ICS (Industrial Control Systems) advisories are official security recommendations that provide information about discovered vulnerabilities in industrial automation systems – from building management systems to SCADA platforms to programmable logic controllers (PLCs).
The advisories contain technical details about the respective security vulnerabilities as well as specific recommendations for risk mitigation. They are an important source of information for operators of critical infrastructures and automated building management systems.
A strategic partnership has been in place between SAUTER and CERT@VDE since August 2025.
Thanks to this collaboration, SAUTER’s cybersecurity advisories are now published directly via the CERT@VDE platform. This means that customers and partners benefit from a central, up-to-date and internationally recognised source of security-relevant information on SAUTER products and systems.
| Date | Advisory ID | Title |
| 20 Oct 25 | VDE-2025-060 | Sauter: Multiple vulnerabilities in SAUTER modulo 6 |
| 23 March 23 | ICSA-23-082-03 | SAUTER EY-modulo 5 Gebäudeautomationsstationen |
| 12 Jan 23 | ICSA-23-012-05 | SAUTER Controls Nova 200 – 220 Serie (PLC 6) |
| 27 Oct 22 | ICSA-22-300-02 | SAUTER Controls moduWeb |
| 01 Nov 18 | ICSA-18-305-04 | Fr. Sauter AG CASE Suite |
| 08 Dec 16 | ICSA-16-343-02 | Sauter NovaWeb Web HMI Schwachstelle bei Authentifizierungsumgehung |
| 02 Feb 16 | ICSA-16-033-01 | Sauter moduWeb Vision – Schwachstellen |
Cybersecurity policy
Issuing organisation: Fr. Sauter AG
Policy summary:
This policy describes the procedures for reporting and managing cybersecurity vulnerabilities in Sauter devices.
Sauter’s cybersecurity objectives:
Establishing and maintaining cyber defence across the entire Sauter IoT product range is a key element of Sauter’s development strategy in accordance with IEC 62443-4-1. To support us in this endeavour, we welcome feedback on potential cybersecurity vulnerabilities relating to Sauter products. When a security vulnerability is reported, the team at Fr. Sauter AG works with the product manager to evaluate the information provided and take appropriate action.
Reporting a cybersecurity vulnerability:
To report a security vulnerability, please complete the following form and ensure that all required fields are filled in.
Handling of reports on security vulnerabilities:
Product development at Sauter is an ongoing endeavour, with firmware updates released annually.
Reports of potential security vulnerabilities are disclosed and handled in accordance with the Common Vulnerability Scoring System (CVSS).
TLC TECHNICAL SERVICE TRADING COMPANY LIMITED
219/8 Duong so 5 Khu pho 3, Binh Hung Hoa Ward Binh Tan District, Ho Chi Minh City, Vietnam. Tel. +84 (0) 90 2540 929 long.nt(at)tl-controls(dot)com http://www.tl-controls.com/ Sauter Building Control International GmbH Hans-Bunte-Strasse 15 DE-79108 Freiburg i. Br. Tel. +49 761 510 54 05 Fax +49 761 510 54 20 ms.sbci(at)de.sauter-bc(dot)com www.sauter-controls.comYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More Information