Skip to main content

Cybersecurity at SAUTER

Security from the start

Building automation is now fully networked, which increases the demands on the protection, integrity and availability of your systems. SAUTER addresses these challenges with a consistent secure-by-design approach: Our development processes are certified according to IEC 62443-4-1 and ensure that security begins in the concept phase and accompanies the entire product lifecycle.

We comply with international and national standards such as BSI Basic Protection, VDMA 24774:2023, the French CSPN programme (recognised by the BSI) and the upcoming EU regulations NIS-2, CRA and RED-DA – and also take into account the British requirements of the PSTI Act (Product Security and Telecommunications Infrastructure). We are currently seeking CSPN certification for our modulo 6 modular controller family.

Transparency and continuous improvement are key components of our programme: Together with CERT@VDE, we publish open security advisories, invite customers to report potential vulnerabilities and regularly participate in hackathons and audits. In terms of technology, we primarily rely on BACnet Secure Connect for end-to-end encrypted communication.

This is how we lay the foundation for digital buildings that are not only smart, but also permanently secure.

This is how we ensure long-term security

Secure-by-design development All our product development follows the certified IEC 62443-4-1 process. This allows us to integrate security requirements from the initial idea to end-of-life and create a defence-in-depth architecture that effectively minimises vulnerabilities.

Continuous SBOM monitoring: Automated tools check our bill of materials software daily for newly disclosed vulnerabilities (CVEs). This allows us to identify critical dependencies immediately and deploy patches quickly.

Active community engagement
 We regularly participate in hackathons, industry conferences and red team tests to bring fresh insights directly into our products and processes.

BACnet Secure Connect on board
 All new SAUTER controllers support BACnet SC – the future-proof, TLS-encrypted communication standard for building networks and cloud connectivity.

Direct line to the PSIRT
You can reach our Product Security Incident Response Team (PSIRT) around the clock via our contact form to report potential vulnerabilities quickly and confidentially.

Advisories
Security notices for industrial control systems

ICS (Industrial Control Systems) advisories are official security recommendations that provide information about discovered vulnerabilities in industrial automation systems – from building management systems to SCADA platforms to programmable logic controllers (PLCs).

The advisories contain technical details about the respective security vulnerabilities as well as specific recommendations for risk mitigation. They are an important source of information for operators of critical infrastructures and automated building management systems.

strategic partnership has been in place between SAUTER and CERT@VDE since August 2025.
Thanks to this collaboration, SAUTER’s cybersecurity advisories are now published directly via the CERT@VDE platform. This means that customers and partners benefit from a central, up-to-date and internationally recognised source of security-relevant information on SAUTER products and systems.

Current SAUTER advisories

Date Advisory ID Title
20 Oct 25 VDE-2025-060 Sauter: Multiple vulnerabilities in SAUTER modulo 6
23 March 23 ICSA-23-082-03 SAUTER EY-modulo 5 Gebäudeautomationsstationen
12 Jan 23 ICSA-23-012-05 SAUTER Controls Nova 200 – 220 Serie (PLC 6)
27 Oct 22 ICSA-22-300-02 SAUTER Controls moduWeb
01 Nov 18 ICSA-18-305-04 Fr. Sauter AG CASE Suite
08 Dec 16 ICSA-16-343-02 Sauter NovaWeb Web HMI Schwachstelle bei Authentifizierungsumgehung
02 Feb 16 ICSA-16-033-01 Sauter moduWeb Vision – Schwachstellen

Contact

Cybersecurity policy

Issuing organisation: Fr. Sauter AG

Policy summary:
This policy describes the procedures for reporting and managing cybersecurity vulnerabilities in Sauter devices.

Sauter’s cybersecurity objectives:

Establishing and maintaining cyber defence across the entire Sauter IoT product range is a key element of Sauter’s development strategy in accordance with IEC 62443-4-1. To support us in this endeavour, we welcome feedback on potential cybersecurity vulnerabilities relating to Sauter products. When a security vulnerability is reported, the team at Fr. Sauter AG works with the product manager to evaluate the information provided and take appropriate action.

Reporting a cybersecurity vulnerability:

To report a security vulnerability, please complete the following form and ensure that all required fields are filled in.


    Um Ihre Rechte zu lesen und auszuüben, insbesondere um Ihre Einwilligung zur Nutzung der über dieses Formular gesammelten Daten zu widerrufen, lesen Sie bitte unsere Datenschutzerklärung.

     

    Handling of reports on security vulnerabilities:

    Product development at Sauter is an ongoing endeavour, with firmware updates released annually.

    Reports of potential security vulnerabilities are disclosed and handled in accordance with the Common Vulnerability Scoring System (CVSS).

    © 2025  Fr. Sauter AG All rights reserved