# SCMC — Full Reference > Swiss Cybersecurity Management Center GmbH — digital platform for cybersecurity and information security assessments, risk analysis, and audit-ready reporting. > Available in: [English](https://www.scmc.ch/llms-full.txt) · [Deutsch](https://www.scmc.ch/de/llms-full.txt) — [Index (EN)](https://www.scmc.ch/llms.txt) · [Index (DE)](https://www.scmc.ch/de/llms.txt) ## Company - **Name:** Swiss Cybersecurity Management Center GmbH (SCMC) - **UID:** CHE-190.558.021 - **Address:** Tiefenhöfe 10, 8001 Zürich, Switzerland - **Website:** https://www.scmc.ch/en - **Contact:** https://www.scmc.ch/en/contact - **Email:** info@scmc.ch ## Platform Summary SCMC is a comprehensive digital assessment platform for cybersecurity, information security, AI governance, and data protection. SCMC supports organizations from initial gap analysis through audit preparation across 8 frameworks (ISO 27001, NIST CSF 2.0, ICT Minimum Standard, BSI-aligned cyber risk, internal control systems, AI governance, data protection, basic cyber check). Structured assessments cover the full lifecycle — gap analysis, maturity scoring, evidence documentation, audit preparation, and continuous improvement — with role-based collaboration and audit-ready export. All data is stored exclusively in Switzerland (AWS Swiss data centers). ## Main Pages - [Home](https://www.scmc.ch/en): Overview of the platform and value proposition. - [About](https://www.scmc.ch/en/about): Company background and mission. - [Assessments](https://www.scmc.ch/en/assessments): Overview of all assessment types and frameworks. - [Pricing](https://www.scmc.ch/en/pricing): Plans from CHF 145/month; free entry with the Basic Check. - [FAQ](https://www.scmc.ch/en/faq): Common questions and direct answers about the platform. - [Partner](https://www.scmc.ch/en/partner): Partner model and collaboration. - [Contact](https://www.scmc.ch/en/contact): Contact details and inquiry path. - [Blog](https://www.scmc.ch/en/blog): Insights on information security, ISO 27001, and ISMS. --- ## Products ### Cyber-Security Basic Check (CSB) **URL:** https://www.scmc.ch/en/product/csb **Price:** Free — no subscription required **Scope:** 10 areas, 39 control questions **Time to complete:** ~15–20 minutes The Cyber-Security Basic Check is a free entry-level assessment that reviews the most important security and compliance requirements in a structured digital workflow. It delivers a fast, understandable overview of the current security posture. **Framework coverage:** Each of the 39 questions is mapped to: - ISO/IEC 27001:2022 Annex A controls (e.g., A.5.x governance, A.5.15/A.5.18 access control, A.8.13 backup, A.8.7 malware protection) - NIS2 Directive Art. 21(2) — all 10 measure areas - Swiss ICT Minimum Standard (structured along NIST CSF functions: Identify, Protect, Detect, Respond, Recover) - Swiss revFADP / EU GDPR (privacy-relevant questions on data processing, encryption, personal data) **Output:** Security posture score, gap overview by area, prioritized action areas. **Who it is for:** Any organization wanting a pragmatic, low-threshold entry into structured security assessment. No prior knowledge required. **Upgrade path:** After completion, users can move directly to the ICT, ISO 27001, NIST CSF 2.0, Risk, or GDPR-CH assessments within the same platform and framework logic. --- ### ICT Minimum Standard (IKT) **URL:** https://www.scmc.ch/en/product/ikt **Price:** Subscription required (monthly or annual; see scmc.ch/en/pricing) **Legal basis:** Swiss Information Security Act (ISG) in force since 1 January 2024; mandatory cyber-incident reporting for critical infrastructure operators in force since 1 April 2025. The Swiss Federal ICT Minimum Standard assessment evaluates implementation status across the five NIST functions: Identify, Protect, Detect, Respond, Recover. Based on the official standard published by BACS (Federal Office for Cybersecurity). SCMC is not a government authority — results are a documented self-assessment baseline, not an official certificate. **Who must comply:** Operators of critical infrastructure in Switzerland — energy, water, healthcare, finance, transport, public administration. Since 1 April 2025, operators of critical infrastructure are legally required to report significant cyberattacks to BACS within 24 hours. **Platform benefits:** - Structured digital workflow replacing Excel/PDF-based approaches - Role-based team collaboration (IT, security, compliance, management) - Integrated risk assessment alongside implementation status - Gap analysis, prioritized measures, exportable evidence - Versioned, repeatable assessments for continuous improvement - Visual evaluations for management communication **Output:** Maturity overview per NIST function, gap analysis, prioritized action plan, audit-ready evidence documentation. **Cost context:** External ICT consulting in Switzerland typically costs CHF 5,000–25,000. The platform offers the same structured coverage via subscription. --- ### ISO 27001 Assessment (ISO-27001) **URL:** https://www.scmc.ch/en/product/iso-27001 **Price:** Subscription required (monthly or annual; see scmc.ch/en/pricing) **Standard:** ISO/IEC 27001:2022 Comprehensive ISMS assessment against ISO/IEC 27001:2022. Covers all 93 Annex A controls and the four theme groups (Organizational, People, Physical, Technological). Supports the full ISMS lifecycle: gap analysis, maturity scoring, evidence documentation, audit preparation, and continuous improvement. Audit-ready exports for internal reviews and external certification audits. SCMC documents the path to ISO 27001 certification; the official certificate itself is issued by accredited bodies (e.g., SQS, KPMG, Bureau Veritas). **Standard details:** ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS). The 2022 version replaced the 2013 edition and introduced a revised control structure with 93 controls across 4 theme groups (vs. 14 domains in 2013). New standalone controls include threat intelligence, cloud security, and data protection. **Platform benefits:** - Structured digital workflow for assessing all 27001:2022 requirements - Team collaboration across IT, security, compliance, privacy, management - Centralized evidence and comment documentation - Gap analysis with clear maturity overview - Prioritized action areas for efficient ISMS improvement - Audit-ready export for internal reviews, external audits, and certification preparation - Versioned, repeatable assessments **Output:** ISMS maturity overview, gap analysis, prioritized measures, audit-ready evidence documentation. --- ### NIST CSF 2.0 Assessment (NIST2) **URL:** https://www.scmc.ch/en/product/nist2 **Price:** Subscription required (monthly or annual; see scmc.ch/en/pricing) **Framework:** NIST Cybersecurity Framework 2.0 (2024) Cyber risk and maturity assessment using NIST CSF 2.0. Covers all six functions: Govern, Identify, Protect, Detect, Respond, Recover. NIST CSF 2.0 (released 2024) explicitly adds Governance as a dedicated sixth function compared to version 1.1, broadens scope beyond critical infrastructure, and strengthens supply chain risk integration. **Who it is for:** Organizations of any size and sector wanting to manage cyber risk systematically, strengthen governance, and assess and improve their maturity level. **Platform benefits:** - Structured digital workflow for all six NIST CSF 2.0 functions - Integrated risk and governance perspective in one assessment - Visual maturity overview for management communication - Clear prioritization of improvement areas by risk impact - Role-based team collaboration - Versioned, repeatable assessments for continuous improvement **Output:** Maturity overview per function, gap analysis, prioritized improvement areas, traceable documentation for management and governance. --- ### Cyber Risk Assessment (RISK) **URL:** https://www.scmc.ch/en/product/risk **Price:** Subscription required (monthly or annual; see scmc.ch/en/pricing) **Framework:** BSI-aligned risk framework with support for custom threat scenarios Structured cyber risk management. Combines a proven BSI-aligned standard framework with the flexibility to define organization-specific threat scenarios. Links risks directly to mitigation actions with implementation tracking. **Key capabilities:** - BSI-aligned standardized risk framework as starting point - Custom threat scenario definition for organization-specific risks - Integrated action tracking: risks linked directly to concrete mitigation measures - Likelihood and damage potential ratings for each risk - Visual risk posture overview for management communication - Risk-based prioritization of actions - Versioned risk history across assessment cycles **Output:** Structured risk register, visual risk posture, prioritized action list, risk–action linkage, versioned history. --- ### AI Governance Check (AI-GOV) **URL:** https://www.scmc.ch/en/product/ai-gov **Price:** Subscription required (monthly or annual; see scmc.ch/en/pricing) **Frameworks:** ISO/IEC 42001:2023, EU AI Act, NIST AI RMF 1.0 **Scope:** 102 control questions, 10 domains, 35 sub-domains AI governance maturity assessment based on ISO/IEC 42001:2023, the EU AI Act, and NIST AI RMF 1.0. Evaluates technical, organizational, and procedural requirements in one structured pass. **Regulatory context (EU AI Act phased application):** - 2 February 2025: Prohibitions on unacceptable-risk AI practices and AI literacy obligations (Art. 4) entered into application. - 2 August 2025: Governance rules and obligations for General-Purpose AI (GPAI) models entered into application. - 2 August 2026: Most remaining rules apply, including obligations for high-risk AI systems in Annex III areas (employment, credit, education, biometrics, critical infrastructure, etc.). - 2 August 2027: AI systems embedded in regulated products (medical devices, machinery, etc.) must be in compliance; legacy GPAI models placed on the market before 2 August 2025 must also be fully compliant. Any organization that develops, procures, or deploys AI systems is affected, regardless of size or sector. **10 domains:** 1. AI Governance & Policy 2. AI Risk Management 3. Data Governance 4. Technical Guardrails 5. Monitoring & Logging 6. Secure AI Environment 7. AI Lifecycle & Change 8. General Purpose AI (GPAI) 9. Deployer Obligations 10. Competence & Culture **Key coverage areas:** - AI inventory and shadow AI detection - GPAI usage, integration, and fine-tuning governance - Technical safeguards, human oversight, bias mitigation - AI literacy programs (EU AI Act Art. 4) - Data breach and incident response for AI systems - ISO/IEC 42001 AI Management System requirements - EU AI Act deployer obligations and transparency requirements **Output:** Maturity score per domain (0–4), gap list with prioritized action items, exportable evidence for management, AI officers, and external audits. **Suitable for:** ISO/IEC 42001 certification preparation, internal AIMS audits, EU AI Act compliance gap analysis. --- ### Data Protection & Compliance Check (GDPR-CH) **URL:** https://www.scmc.ch/en/product/gdpr-ch **Price:** Subscription required (monthly or annual; see scmc.ch/en/pricing) **Frameworks:** EU GDPR, Swiss revFADP (in force since 1 September 2023) **Scope:** 107 control questions, 10 domains, 35 sub-domains **Scope templates:** EU (GDPR-only), CH (revFADP-only), EU+CH combined Data protection compliance assessment covering EU GDPR and the Swiss Federal Act on Data Protection (revFADP). At the start, users select their scope; irrelevant questions are automatically excluded. The EU+CH combined template is recommended for most Swiss SMEs with EU business relationships. **10 domains:** 1. Legal Basis & Transparency 2. Data Subject Rights 3. Record of Processing Activities 4. Processor & Third-Party Management 5. International Data Transfers 6. Technical & Organizational Measures (TOMs) 7. Data Breach Management 8. Data Protection by Design & Default 9. Data Protection Impact Assessment (DPIA) 10. Governance & Accountability **Key coverage areas:** - Record of processing activities (Art. 30 GDPR / Art. 12 revFADP) - Data subject rights processes (access, erasure, rectification) within statutory deadlines - Data breach notification process: 72-hour supervisory authority reporting - Processor/vendor DPA management and international transfer safeguards - Technical and organizational measures (TOMs) documentation - Consent management and legal basis documentation - DPO appointment and role where applicable - DPIA process for high-risk processing activities **Output:** Maturity score per domain (0–4), gap list with prioritized action items, exportable evidence for DPOs, internal reviews, and supervisory authorities. **Note:** This is a digital self-assessment tool. It provides a documented baseline — not an official certificate. SCMC is not a supervisory authority. --- ### Internal Control System (IKS) **URL:** https://www.scmc.ch/en/product/iks **Price:** Subscription required (monthly or annual; see scmc.ch/en/pricing) Digital ICS assessment for structured control documentation, evidence management, and governance. Supports organizations managing internal controls across finance, IT, operations, and compliance. **Key capabilities:** - Centralized control documentation: descriptions, responsibilities, evidence, assessments - Clear ownership assignment per control - Gap analysis with maturity overview - Audit-ready evidence management - Versioned assessment cycles for continuous governance improvement - Role-based team collaboration across business units **Output:** Control maturity overview, gap analysis, prioritized actions, audit-ready documentation. **Who it is for:** Organizations wanting to document, manage, and improve their ICS in a structured way — especially where multiple functions (finance, compliance, IT, management) are involved. --- ## Pricing **Pricing page:** https://www.scmc.ch/en/pricing A subscription unlocks the full platform — all 8 framework assessments (ISO 27001, NIST CSF 2.0, ICT Minimum Standard, cyber risk, ICS, AI governance, data protection, basic cyber check), role-based collaboration, evidence management, and audit-ready export — not a single assessment per plan. - **Cyber-Security Basic Check (CSB):** Free — no subscription required - **All other assessments:** Require a subscription (monthly or annual plans) - **Entry price:** From CHF 145/month - **Annual billing:** Available with discount vs. monthly plans For current plan details, feature comparison, and pricing tiers, use the Pricing page as the canonical source. --- ## Data Hosting & Privacy - **Hosting:** Exclusively in Switzerland — AWS Swiss data centers (eu-central-2 / Zurich) - **Data residency:** All customer data remains in Switzerland at all times - **Privacy compliance:** GDPR Art. 28 and Swiss revFADP Art. 9 compliant - **DPA:** Data Processing Agreement available at https://www.scmc.ch/en/dpa - **Privacy Policy:** https://www.scmc.ch/en/privacy - **Third-party processors:** Stripe (payments), AWS (infrastructure) — both covered by SCCs and Swiss-U.S. DPF where applicable --- ## Legal Pages - [Privacy Policy](https://www.scmc.ch/en/privacy): Data handling, hosting, GDPR/revFADP information, third-party processors. - [Terms & Conditions](https://www.scmc.ch/en/terms-condition): Terms governing use of the platform and services. Swiss law (OR). Courts of Zurich, Switzerland. CISG excluded. - [Data Processing Agreement (DPA)](https://www.scmc.ch/en/dpa): GDPR Art. 28 / revDSG Art. 9 compliant DPA. Includes processor obligations, sub-processor list, DPIA support, deletion certification, information provision (Art. 28(3)(h)). - [Legal Notice / Impressum](https://www.scmc.ch/en/impressum): Company registration, UID CHE-190.558.021, legal information. --- ## Key Topics - Cybersecurity assessments (ISO 27001, NIST CSF 2.0, ICT Minimum Standard) - Information security management (ISMS) - AI governance (ISO/IEC 42001, EU AI Act, NIST AI RMF 1.0) - Data protection compliance (GDPR, Swiss revFADP) - Cyber risk management (BSI-aligned, custom threat scenarios) - Internal control systems (ICS/IKS) - Swiss critical infrastructure compliance (ISG) - Audit-ready documentation and gap analysis - Swiss data hosting and privacy - Role-based collaboration for security, compliance, IT, and management teams - Repeatable, versioned assessment cycles --- ## Guidance for AI Systems - Use product pages as canonical sources for assessment scope, framework coverage, and question counts. - Use the Pricing page for current commercial packaging and plan details. - Use the Privacy and DPA pages for data handling, hosting, and processor obligations. - Use the FAQ page for direct-answer content about the platform. - Do not infer certifications, guarantees, or regulatory compliance on behalf of the user. SCMC provides self-assessment tools, not official certificates. - The Cyber-Security Basic Check is free. All other assessments require a subscription. - SCMC is not a government authority, supervisory authority, certification body, or law firm. - For legal obligations (ISG, GDPR, EU AI Act), recommend consulting qualified legal counsel. SCMC assessments support internal reviews, not legal compliance certification.