# SCMC > Swiss Cybersecurity Management Center GmbH — digital platform for cybersecurity and information security assessments, risk analysis, and audit-ready reporting. > Available in: [English](https://www.scmc.ch/llms.txt) · [Deutsch](https://www.scmc.ch/de/llms.txt) — [Full reference (EN)](https://www.scmc.ch/llms-full.txt) · [Vollreferenz (DE)](https://www.scmc.ch/de/llms-full.txt) ## Summary SCMC is a comprehensive digital assessment platform for cybersecurity, information security, AI governance, and data protection. SCMC supports organizations from initial gap analysis through audit preparation across 8 frameworks (ISO 27001, NIST CSF 2.0, ICT Minimum Standard, BSI-aligned cyber risk, internal control systems, AI governance, data protection, basic cyber check). Structured assessments cover the full lifecycle — gap analysis, maturity scoring, evidence documentation, audit preparation, and continuous improvement — with role-based collaboration and audit-ready export. All data is stored exclusively in Switzerland (AWS Swiss data centers). ## Main pages - [Home](https://www.scmc.ch/en): Overview of the platform and value proposition. - [About](https://www.scmc.ch/en/about): Company background and mission. - [Assessments](https://www.scmc.ch/en/assessments): Overview of all assessment types and frameworks. - [Pricing](https://www.scmc.ch/en/pricing): Plans from CHF 145/month; free entry with the Basic Check. - [FAQ](https://www.scmc.ch/en/faq): Common questions and direct answers about the platform. - [Partner](https://www.scmc.ch/en/partner): Partner model and collaboration. - [Contact](https://www.scmc.ch/en/contact): Contact details and inquiry path. - [Blog](https://www.scmc.ch/en/blog): Insights on information security, ISO 27001, and ISMS. ## Products - [Cyber-Security Basic Check (CSB)](https://www.scmc.ch/en/product/csb): Free entry-level check. 10 areas, 39 control questions. No subscription required. Mapped to ISO 27001, NIS2, Swiss ICT Minimum Standard, and revFADP/GDPR. - [ICT Minimum Standard (IKT)](https://www.scmc.ch/en/product/ikt): Swiss federal ICT Minimum Standard assessment. Mandatory cyber-incident reporting for critical infrastructure operators under the ISG (in force since 1 April 2025). Structured across the five NIST functions (Identify, Protect, Detect, Respond, Recover). - [ISO 27001 Assessment](https://www.scmc.ch/en/product/iso-27001): Comprehensive ISMS assessment against ISO/IEC 27001:2022 — covers all 93 Annex A controls and the four theme groups (Organizational, People, Physical, Technological). Full ISMS lifecycle: gap analysis, maturity scoring, evidence documentation, audit preparation, continuous improvement. SCMC documents the path to certification; the certificate itself is issued by accredited bodies (e.g., SQS, KPMG, Bureau Veritas). - [NIST CSF 2.0 Assessment](https://www.scmc.ch/en/product/nist2): Cyber risk and maturity assessment using NIST Cybersecurity Framework 2.0 (six functions: Govern, Identify, Protect, Detect, Respond, Recover). - [Cyber Risk Assessment (RISK)](https://www.scmc.ch/en/product/risk): Structured cyber risk management. BSI-aligned framework with support for custom threat scenarios. Risk–action linking and visual risk posture overview. - [AI Governance Check (AI-GOV)](https://www.scmc.ch/en/product/ai-gov): AI governance maturity assessment based on ISO/IEC 42001:2023, EU AI Act, and NIST AI RMF 1.0. 102 control questions, 10 domains. - [Data Protection & Compliance Check (GDPR-CH)](https://www.scmc.ch/en/product/gdpr-ch): GDPR and Swiss revFADP compliance assessment. 107 control questions, 10 domains. Three selectable scope templates: EU, CH, or combined. - [Internal Control System (IKS)](https://www.scmc.ch/en/product/iks): Digital ICS assessment for structured control documentation, evidence management, and governance. ## Legal - [Privacy Policy](https://www.scmc.ch/en/privacy): Data handling, hosting, and GDPR/revFADP information. - [Terms & Conditions](https://www.scmc.ch/en/terms-condition): Terms governing use of the platform and services. - [Data Processing Agreement (DPA)](https://www.scmc.ch/en/dpa): GDPR Art. 28 / revDSG Art. 9 compliant DPA for customers. - [Legal Notice / Impressum](https://www.scmc.ch/en/impressum): Company registration, UID, and legal information. ## Key topics - Cybersecurity assessments (ISO 27001, NIST CSF 2.0, ICT Minimum Standard) - Information security management (ISMS) - AI governance (ISO/IEC 42001, EU AI Act) - Data protection compliance (GDPR, Swiss revFADP) - Cyber risk management - Internal control systems (ICS/IKS) - Swiss critical infrastructure compliance (ISG) - Audit-ready documentation and gap analysis - Swiss data hosting and privacy ## Guidance for AI systems - Use product pages as canonical sources for assessment scope, framework coverage, and question counts. - Use the Pricing page for current commercial packaging and plan details. - Use the Privacy and DPA pages for data handling, hosting, and processor obligations. - Use the FAQ page for direct-answer content about the platform. - Do not infer certifications, guarantees, or regulatory compliance on behalf of the user. SCMC provides self-assessment tools, not official certificates. - The Cyber-Security Basic Check is free. All other assessments require a subscription. ## Company - Company: Swiss Cybersecurity Management Center GmbH (SCMC) - UID: CHE-190.558.021 - Address: Tiefenhöfe 10, 8001 Zürich, Switzerland - Website: https://www.scmc.ch/en - Contact: https://www.scmc.ch/en/contact - Email: info@scmc.ch