Ein Assessment für AI Act, Maschinenverordnung, Cyber Resilience Act und NIS2. Dazu Beratung für IT- und OT-Security, vom Awareness-Training bis zur Kritischen Infrastruktur. Und ein Ökosystem, das die Umsetzung übernimmt. Hier finden Sie alle Leistungen im Detail.
A lifecycle from clarity to ongoing security. A one-time assessment and roadmap, with ongoing security and verification. A single project leads to lasting, verifiable compliance.
What regulatory frameworks do you comply with, and where do you stand today? Record it once, use it across all regulatory frameworks.
Learn morePrioritized measures featuring quick wins and a consolidated set of controls, implemented in collaboration with our partners.
Learn moreCRA documentation for your supplier base. A program provided to your suppliers to serve as the basis for your declaration of conformity.
Learn moreContinuously monitors your audit and compliance capabilities, with annual reassessments, a complete audit trail, and version control.
Learn morePractical training for production and office staff, tailored to your OT environment. Includes handouts, exercises, and sample solutions that work in everyday situations.
Assessment of compliance with the minimum ICT standards, which are already mandatory for the electricity sector. Compact, affordable, and with a clear report on the results.
A structured workshop series for manufacturers looking to enter the EU market. Topics range from manufacturer status to the Machinery Directive and the Cyber Resilience Act.
Four sets of EU regulations are affecting the mechanical and plant engineering sectors almost simultaneously. As a manufacturer and operator, you are subject to both sets of obligations. Obligations, deadlines, and liability all converge.
Cybersecurity requirements for wireless devices with Bluetooth or Wi-Fi are already in effect. They will be replaced by the CRA as of December 11, 2027.
Cybersecurity Obligations for Operators. Reporting Requirements and Liability of Management.
Transparenzpflichten nach Art. 50 gelten. Kennzeichnung bestehender Systeme bis 2.12.2026.
Actively exploited vulnerabilities and serious incidents must be reported (Art. 14).
For the first time, digital and AI risks are being considered as part of product safety.
Obligations for autonomous high-risk AI (Annex III), as newly established under the Digital Omnibus.
Security by Design for products with digital elements.
Requirements for high-risk AI in regulated products (Annex I). Machine learning is largely covered by the GDPR.
Machinery and plant manufacturers are almost always both at the same time. This is precisely where the leverage of convergence is greatest.
Security by Design, technical documentation, and product conformity assessment.
Risk management, reporting requirements, and ongoing, safe operations.
Those who manage the two separately create two separate compliance frameworks. We integrate both into a common ISMS framework based on ISO 27001, with IEC 62443 serving as a bridge between product security and operational security. Manufacturer and operator responsibilities are consolidated into a single system.
Jede Säule folgt derselben Logik aus gesetzlicher Pflicht, zertifizierbarem Nachweis und bewährter Methodik. Welche Bausteine Sie davon wirklich brauchen, hängt von Ihren Produkten, Märkten und Rollen ab.
Vier Regelwerke, elf Rahmenwerke, hunderte Einzelanforderungen. Unsere Konvergenz-Matrix verdichtet das auf 14 Maßnahmen und zeigt, welche davon mehrfach zählen. Das erspart Ihnen den drei- bis vierfachen Projektaufwand.
Eine einzige offene Lücke trifft dafür oft sieben Regelwerke zugleich. Wo Ihre größten Hebel und Ihre gefährlichsten Lücken liegen, zeigt die Matrix erst, wenn wir sie auf Ihr Unternehmen anwenden. Das gibt es nur im Gespräch, nicht im Netz.
Schedule a Quick CheckVier Vorgaben bestimmen die nächsten Jahre im Maschinen- und Anlagenbau. Wir kennen sie im Detail und übersetzen sie in einen machbaren Fahrplan.
Die KI-Kompetenz-Pflicht nach Art. 4 gilt seit Februar 2025, die Kennzeichnungspflichten nach Art. 50 seit August 2026 mit Frist bis 2.12.2026 für bestehende Systeme. Hochrisiko folgt gestaffelt bis 2028. Von zehn geplanten Normen ist erst eine veröffentlicht und keine rechtsverbindlich zitiert. Ausgerechnet die zur Sicherheit fehlt.
Security by Design for products with digital components, vulnerability management throughout the entire lifecycle, and mandatory SBOM reporting. The reporting requirement applies retroactively to products that have already been shipped. Without a declaration of conformity, sales may be suspended starting at the end of 2027.
Replaces the Machinery Directive with an abrupt transition and no grace period for selling off existing stock. For the first time, digital and AI risks are included in product safety requirements, including protection against tampering with safety-critical software and documentation requirements regarding modifications and software versions.
The Swiss benchmark for ICT resilience, based on the NIST Cybersecurity Framework and comprising over 100 specific measures. Already mandatory for the electricity sector; for other sectors, it serves as the gateway to regulated supply chains.

From ISG and the Minimum ICT Standard to PrSG/MaschV, the EU Machinery Directive, NIS2, and the Cyber Resilience Act. This white paper provides a Swiss perspective on which national and EU regulations apply, what deadlines are in effect, and how you can efficiently meet all requirements using an integrated approach.
White Paper anfordern
Im 30-Minuten-Schnell-Check zeigen wir Ihnen, welche Regelwerke Sie treffen und wo Ihr größter Hebel liegt.
SecureComply GmbH
Islerenweg 5a
8708 Männedorf
info@securecomply.ch
+41 79 746 35 88
Sitelinks
AboutUs
Services
White Papers
Contact