Home / Services

Vier Regelwerke, zwei Welten, ein Partner.

Ein Assessment für AI Act, Maschinenverordnung, Cyber Resilience Act und NIS2. Dazu Beratung für IT- und OT-Security, vom Awareness-Training bis zur Kritischen Infrastruktur. Und ein Ökosystem, das die Umsetzung übernimmt. Hier finden Sie alle Leistungen im Detail.

Four sets of regulations are combined into a single certification document

How We Work with You

A lifecycle from clarity to ongoing security. A one-time assessment and roadmap, with ongoing security and verification. A single project leads to lasting, verifiable compliance.

Step 1 · One-time

Convergence Assessment

What regulatory frameworks do you comply with, and where do you stand today? Record it once, use it across all regulatory frameworks.

Learn more
Step 2 · One-time

Roadmap & Implementation

Prioritized measures featuring quick wins and a consolidated set of controls, implemented in collaboration with our partners.

Learn more
Step 3 · Program for Your Supplier Base

Supplier Enablement

CRA documentation for your supplier base. A program provided to your suppliers to serve as the basis for your declaration of conformity.

Learn more
Step 4 · Ongoing, recurring annually

Audit Readiness as a Service

Continuously monitors your audit and compliance capabilities, with annual reassessments, a complete audit trail, and version control.

Learn more

Additional Services

IT & OT · On-site or Remote

Security Awareness Training

Practical training for production and office staff, tailored to your OT environment. Includes handouts, exercises, and sample solutions that work in everyday situations.

  • OT-Security Awareness für Produktionsteams
  • IT-Security Awareness für alle Mitarbeitenden
  • Zahlt direkt auf die Schulungspflichten von 8 der 11 Rahmenwerke ein
KRITIS · Municipalities & Energy Providers

Critical Infrastructure Consulting

Assessment of compliance with the minimum ICT standards, which are already mandatory for the electricity sector. Compact, affordable, and with a clear report on the results.

  • IKT-Standortbestimmung für Energieversorger
  • Kompakter IT-Check für Gemeinden
  • Priorisierte Maßnahmen und Ergebnisbericht für die Führung
Workshops · German & English

Compliance Workshops on Entering the EU Market

A structured workshop series for manufacturers looking to enter the EU market. Topics range from manufacturer status to the Machinery Directive and the Cyber Resilience Act.

  • Klärung von Herstellerstatus und Rollen
  • Anforderungen je Regelwerk mit harten Fristen
  • Ergebnis ist eine planbare 12-Monats-Roadmap

The New Reality of Compliance

Four sets of EU regulations are affecting the mechanical and plant engineering sectors almost simultaneously. As a manufacturer and operator, you are subject to both sets of obligations. Obligations, deadlines, and liability all converge.

since August 1, 2025
RED EN 18031

Cybersecurity requirements for wireless devices with Bluetooth or Wi-Fi are already in effect. They will be replaced by the CRA as of December 11, 2027.

today
NIS2 Takes Effect

Cybersecurity Obligations for Operators. Reporting Requirements and Liability of Management.

2.8.2026
AI Act Transparency

Transparenzpflichten nach Art. 50 gelten. Kennzeichnung bestehender Systeme bis 2.12.2026.

11.9.2026
CRA Reporting Requirements

Actively exploited vulnerabilities and serious incidents must be reported (Art. 14).

20.1.2027
Machinery Regulation

For the first time, digital and AI risks are being considered as part of product safety.

2.12.2027
AI Act: High Risk

Obligations for autonomous high-risk AI (Annex III), as newly established under the Digital Omnibus.

11.12.2027
CRA Key Responsibilities

Security by Design for products with digital elements.

2.8.2028
AI Act: AI in Products

Requirements for high-risk AI in regulated products (Annex I). Machine learning is largely covered by the GDPR.

70 %
Cybersecurity requirements overlap. Those who address them separately end up paying multiple times.
12 to 18
Conformity assessment and technical documentation require several months of lead time. Anyone who needs to deliver in 2027 should get started now.
Welche dieser Fristen Sie wirklich treffen und welche Sie ignorieren dürfen, klären wir in 30 Minuten.Schnell-Check vereinbarenJetzt anrufen

A dual role, two sets of responsibilities

Machinery and plant manufacturers are almost always both at the same time. This is precisely where the leverage of convergence is greatest.

Role 1 · Manufacturer

Vernetzte Produkte mit digitalen und KI-Elementen

  • RED EN 18031 für Funkanlagen, bereits in Kraft
  • Cyber Resilience Act (EU) 2024/2847
  • Machinery Regulation (EU) 2023/1230
  • EU AI Act mit Art. 15 für Hochrisiko-KI

Security by Design, technical documentation, and product conformity assessment.

Role 2 · Operator

Eigene OT- und Produktionsinfrastruktur

  • NIS2-Richtlinie (EU) 2022/2555
  • EU AI Act mit Betreiberpflichten nach Art. 4 und 26
  • IKT-Minimalstandard (BACS / Schweiz)
  • ISO/IEC 27001 als ISMS-Fundament

Risk management, reporting requirements, and ongoing, safe operations.

An assessment covers both roles.

Those who manage the two separately create two separate compliance frameworks. We integrate both into a common ISMS framework based on ISO 27001, with IEC 62443 serving as a bridge between product security and operational security. Manufacturer and operator responsibilities are consolidated into a single system.

Three Pillars, a Foundation of Security

Jede Säule folgt derselben Logik aus gesetzlicher Pflicht, zertifizierbarem Nachweis und bewährter Methodik. Welche Bausteine Sie davon wirklich brauchen, hängt von Ihren Produkten, Märkten und Rollen ab.

SÄULE 1 · AI Governance & Security

Ist Ihre KI rechtssicher?

  • EU AI Act mit Art. 15 zu Robustheit & Cybersecurity
  • ISO/IEC 42001 als zertifizierbares KI-Managementsystem
  • NIST AI RMF mit Govern · Map · Measure · Manage
SÄULE 2 · Produktrecht

Darf Ihr Produkt in die EU?

  • Maschinenverordnung (EU) 2023/1230 ab 20.01.2027
  • Cyber Resilience Act mit Security by Design ab 11.12.2027
  • IEC 62443 als technische Brücke zur OT-Security
SÄULE 3 · Cyber-Resilience

Übersteht Ihr Betrieb den Ernstfall?

  • NIS2 mit Meldepflichten & Haftung der Geschäftsleitung
  • ISO/IEC 27001 als gemeinsames ISMS-Fundament
  • IKT-Minimalstandard (BACS/CH) für die operative Praxis
Ob alle drei Säulen bei Ihnen tragen, sehen wir in 30 Minuten.Schnell-Check vereinbaren

The Convergence Matrix

Vier Regelwerke, elf Rahmenwerke, hunderte Einzelanforderungen. Unsere Konvergenz-Matrix verdichtet das auf 14 Maßnahmen und zeigt, welche davon mehrfach zählen. Das erspart Ihnen den drei- bis vierfachen Projektaufwand.

11/11
Risikomanagement zählt in allen elf Rahmenwerken. Einmal sauber aufgebaut, elffach angerechnet.
10/11
Logging und Audit Trail bedienen zehn Rahmenwerke mit einer einzigen Einrichtung.
9/11
Technische Dokumentation trägt neun Nachweispflichten auf einmal.

Eine einzige offene Lücke trifft dafür oft sieben Regelwerke zugleich. Wo Ihre größten Hebel und Ihre gefährlichsten Lücken liegen, zeigt die Matrix erst, wenn wir sie auf Ihr Unternehmen anwenden. Das gibt es nur im Gespräch, nicht im Netz.

Schedule a Quick Check

The Rules in Detail

Vier Vorgaben bestimmen die nächsten Jahre im Maschinen- und Anlagenbau. Wir kennen sie im Detail und übersetzen sie in einen machbaren Fahrplan.

Gilt bereits · Hersteller und Betreiber

EU AI Act

Die KI-Kompetenz-Pflicht nach Art. 4 gilt seit Februar 2025, die Kennzeichnungspflichten nach Art. 50 seit August 2026 mit Frist bis 2.12.2026 für bestehende Systeme. Hochrisiko folgt gestaffelt bis 2028. Von zehn geplanten Normen ist erst eine veröffentlicht und keine rechtsverbindlich zitiert. Ausgerechnet die zur Sicherheit fehlt.

  • KI-Inventar und Risikoscreening als Einstieg
  • AI Security Standortbestimmung
  • Schulungen zur KI-Kompetenz-Pflicht
Reporting Requirements Effective September 11, 2026 · Main Requirements Effective December 11, 2027

Cyber Resilience Act (EU) 2024/2847

Security by Design for products with digital components, vulnerability management throughout the entire lifecycle, and mandatory SBOM reporting. The reporting requirement applies retroactively to products that have already been shipped. Without a declaration of conformity, sales may be suspended starting at the end of 2027.

  • Produkt-Scoping und Anforderungen aus Anhang I
  • Lieferantennachweise über unser Enablement-Programm
  • Eine Bewertung zählt auch für Art. 15 AI Act
Effective January 20, 2027 · Product Law

Machinery Regulation (EU) 2023/1230

Replaces the Machinery Directive with an abrupt transition and no grace period for selling off existing stock. For the first time, digital and AI risks are included in product safety requirements, including protection against tampering with safety-critical software and documentation requirements regarding modifications and software versions.

  • Gap-Analyse Ihrer technischen Dokumentation
  • Konformitätsfahrplan bis zum Stichtag
  • Abstimmung mit CRA und AI Act in einem Durchgang
BACS · Switzerland

Minimum ICT Standard

The Swiss benchmark for ICT resilience, based on the NIST Cybersecurity Framework and comprising over 100 specific measures. Already mandatory for the electricity sector; for other sectors, it serves as the gateway to regulated supply chains.

  • Standortbestimmung entlang der Maßnahmen
  • Priorisierte Umsetzung für Betrieb und Notfall
  • Anschlussfähig an ISO 27001 und NIS2

White Papers & Publications

White Paper Cover
White Paper

Regulatory Cybersecurity in Mechanical and Plant Engineering

From ISG and the Minimum ICT Standard to PrSG/MaschV, the EU Machinery Directive, NIS2, and the Cyber Resilience Act. This white paper provides a Swiss perspective on which national and EU regulations apply, what deadlines are in effect, and how you can efficiently meet all requirements using an integrated approach.

White Paper anfordern
Stefan Hungerbühler, CEO of SecureComply GmbH
Stefan Hungerbühler
CEO of SecureComply GmbH
LinkedIn
Expertise on an equal footing

Do you have any questions?

Im 30-Minuten-Schnell-Check zeigen wir Ihnen, welche Regelwerke Sie treffen und wo Ihr größter Hebel liegt.

SecureComply GmbH

‍Islerenweg 5a
8708 Männedorf

info@securecomply.ch
+41 79 746 35 88

© SecureComply, LLC