Direct Answer
An IT provider in Zurich needs to help companies working as IT or service partners to banks and insurers meet the requirements of FINMA's outsourcing and operational resilience circulars: automated onboarding, central device management, documented IT security under Switzerland's data protection law (nFADP), and IT support with a defined response time - deeploi delivers this as an all-in-one platform with transparent per-user pricing, without requiring an in-house IT role.
Key Takeaways
- Canton Zurich counts around 112,500 companies, of which 99% are SMBs - together they generate around 21% of Swiss GDP.
- Zurich is by far Switzerland's largest financial center, home to UBS, Zurich Insurance, Swiss Re, and numerous international banks.
- FINMA Circular 2018/3 "Outsourcing" requires banks and insurers to apply strict due diligence, contractual, and control obligations toward service providers when outsourcing essential functions.
- Since January 2024, FINMA Circular 2023/1 "Operational Risks and Resilience" has added further requirements for ICT risk management and business continuity at service providers to financial institutions.
- As a non-EU country, Switzerland applies its own Federal Act on Data Protection (nFADP) instead of GDPR, and has no direct NIS2 obligation - but Zurich financial institutions still expect comparably high standards from their IT partners.
Your Zurich company has 45 employees and supplies IT services, software, or digital solutions to a bank or insurer. The new framework agreement suddenly requires evidence that wasn't there before: documented risk management, clear exit strategies, data location details, and regular audit rights for the client - in line with FINMA Circulars 2018/3 and 2023/1.
That's not an exception - it's standard practice at the Swiss financial center. Zurich is by far Switzerland's largest financial hub - home to UBS, Zurich Insurance, Swiss Re, and a dense network of international banks. If you work as a Zurich SMB on behalf of a financial institution, these regulatory requirements are increasingly written straight into the contract.
This article covers what IT support needs to deliver for Zurich SMBs today - and why a platform like deeploi builds a solid, documented IT foundation, especially for companies operating around the financial center.
Why Zurich deserves its own perspective
With around 112,500 companies, 99% of them SMBs, canton Zurich is Switzerland's strongest economic region, contributing around 21% of national GDP. Unlike Munich with its automotive talent competition, Cologne with insurance and media, or Frankfurt with its DORA regulation, Zurich is defined above all as Switzerland's undisputed financial center - with its own regulation, independent of the EU.
That regulatory independence matters: instead of GDPR, Switzerland applies the revised Federal Act on Data Protection (nFADP); instead of NIS2, FINMA circulars govern the IT requirements for financial institutions and their service providers. For Zurich SMBs working as suppliers to banks or insurers, that means a distinctly Swiss compliance landscape that doesn't map one-to-one onto German or EU requirements.
Why FINMA requirements matter especially for Zurich SMBs
FINMA Circular 2018/3 "Outsourcing" requires banks, insurers, and certain financial institutions to carefully vet who they engage when outsourcing essential functions - including contractual audit and control rights, data location requirements, and clear exit strategies. Since January 2024, Circular 2023/1 "Operational Risks and Resilience" has added further ICT risk management and business continuity obligations on top.
For a Zurich SMB without an in-house IT department, that means: an improvised IT setup is no longer enough once a financial institution becomes a client - evidence of risk management, data location, and audit rights is increasingly a prerequisite.

What an IT provider needs to deliver for Zurich SMBs today
Automated onboarding
New hires start productive, with pre-configured devices and documented access rights - a basic requirement for traceable IT risk management.
Central device management
A complete, always-visible device inventory that serves directly as documentation when providing security evidence to financial partners.
IT security and compliance to Swiss standards
ISO 27001 and Switzerland's Federal Act on Data Protection (nFADP) form the baseline - for Zurich suppliers to the financial industry, FINMA circulars add further, specific requirements around outsourcing and operational resilience.
IT support with a defined response time
A support team with an average response time of 12 minutes, reachable via Slack, Teams, or email - also relevant for the incident reporting channels FINMA requirements call for.
{{cta}}
How deeploi supports Zurich companies
deeploi brings device management, IT support, security, and compliance together in one platform - giving Zurich SMBs the documented IT foundation increasingly expected during FINMA-relevant contract reviews. Devices ship pre-configured directly to employees, security policies are enforced automatically, and all relevant processes are documented centrally instead of scattered across loose tools.
For companies operating around the Zurich financial center, that shifts the question from "can we even pass the next due diligence review?" to "which evidence can we pull straight from the platform?"
Comparison: traditional IT provider vs. deeploi in Zurich
FAQ
What do the FINMA circulars mean for Zurich IT providers working with financial companies?
FINMA Circular 2018/3 "Outsourcing" and the 2023/1 "Operational Risks and Resilience" circular, in force since 2024, require banks and insurers to enforce strict due diligence, audit, and risk management obligations on their service providers when outsourcing essential functions.
Does GDPR apply in Zurich, or does Switzerland have its own data protection law?
As a non-EU country, Switzerland applies its revised Federal Act on Data Protection (nFADP), not GDPR. For companies with both Swiss and EU operations, both frameworks can be relevant.
What's the difference between deeploi and a traditional Zurich IT provider?
A traditional provider usually works reactively and bills hourly. deeploi automates device management, security, and onboarding, and offers transparent per-user pricing, independent of location.










