Service · Compliance & security

Compliance & Security by Design

Requirements, architecture, and evidence that stand up to audits — instead of compliance glued on afterwards.

Typical starting point

  • IEC 62443 is becoming a purchasing condition for your customers, but nobody can say how far away you are.
  • Requirements live in prose and hallways; auditors ask for traceability from requirement to test.
  • Audit trail, data integrity, and deletion obligations (GDPR) are in the specification — but not in the architecture.

What you get

  • IEC 62443 gap analysis against 62443-4-1 with a prioritized closure list and implementation plan — phrased for the standard, designed for developers.
  • Requirements engineering at URS/NFR level: auditable, test-linked requirements instead of prose; quality uplift of existing requirements.
  • Audit-trail architectures: tamper-evident, hash-chained logging with as-of reconstruction (“What did the data look like on inspection day?”).
  • GDPR deletion concepts for immutable data stores — deletability through key destruction (crypto-shredding) without breaking the integrity chain.

How we proceed

  1. Readiness check. Fixed-price gap analysis: where you stand against IEC 62443-4-1, what is critical, what can wait.
  2. Closure plan. Prioritized measures with effort and sequence — aligned with your release planning.
  3. Implementation with evidence. We implement or accompany your team; every measure ends with auditable evidence.

Entry product

62443 Readiness Check

Fixed-price gap analysis against IEC 62443-4-1: documented maturity level, prioritized gap list, concrete closure plan. So you know where you stand before the next customer audit.

Fixed price €12,900 plus VAT · results report with prioritization

Request readiness check

Related services

Instrument Software & Control · Lab IT & Integration · AI-Native Development Organization