Be ready to review
who has access.

Need to show how you manage access and which events you record? We will explain what evidence ChipLogin provides and how it can support an internal review or audit preparation.

An auditor in a suit checking off items on a printed compliance checklist

Requirements to assess for your deployment

The applicability of NIS2, GDPR, the Machinery Regulation or IEC 62443 requirements depends on your organisation, deployment and jurisdiction; the product alone does not ensure compliance. Verify your specific obligations with a legal adviser.

NIS2 (EU Directive 2022/2555)

The NIS2 Directive expands cybersecurity obligations — access control, logging, incident reporting — to a much broader circle of "essential" and "important" entities than the original NIS Directive covered, including manufacturing, energy, and other industrial sectors. In the Czech Republic it's implemented as Act No. 264/2025 Coll., in force since November 1, 2025. Exact scope, deadlines, and penalties vary across other EU member states.

GDPR

Access logs and card data are personal data. GDPR requires a legal basis for processing, data minimization, and clarity on who is the controller and who is the processor for any system that records who accessed what, and when.

Machinery Regulation (EU 2023/1230)

For manufacturers and integrators, the updated Machinery Regulation tightens requirements for safety-related control systems — including who is authorized to operate a machine or override its safety interlocks.

IEC 62443 (international standard)

ChipLogin provides mechanisms relevant to parts of FR1 (identification and authentication), FR2 (use control and audit records), and FR4 (data confidentiality), including named card identities, cryptographic authentication, signed records, and encrypted communication. Applicability and conformity must be assessed for the complete industrial automation and control system. FR3, FR5, FR6, and FR7 remain outside ChipLogin's component scope; this is not a certification or conformity claim.

How ChipLogin helps

The product includes mechanisms that can contribute evidence for access-control and audit requirements.

Access control by default

ChipLogin bases authorization on a registered card identity. Configuration, operating procedures, and the wider environment still determine whether a deployment meets a specific control or audit requirement.

One signed audit trail

The system records who logged in, operated a connected machine, or used a connected door and when, with cryptographic signing intended to make later changes detectable. Whether that evidence is sufficient is determined by the applicable audit scope.

Data stays on your network

ChipLogin Server runs on your own infrastructure. No copy of access and audit data ends up with a third-party cloud provider that you'd have to cover in a data processing agreement.

Clean offboarding

Revoke someone's access to Windows, machines, and doors from a single place. No orphaned permissions quietly surviving in a system nobody got around to updating.

Our own obligations as a vendor

Netajo s.r.o. (the company behind ChipLogin) is the controller of personal data it processes for its own purposes — for example, messages submitted through the contact form on this website. Roles for a customer deployment depend on its configuration and the parties' agreement. ChipLogin Server runs on the customer's infrastructure; customers should determine their own controller and processor responsibilities for access and audit data.

This page is a plain-language summary, not legal advice — verify specific obligations, scope, and deadlines under NIS2, GDPR, or the Machinery Regulation with a qualified lawyer. How we handle data you submit to us directly is described in our privacy policy.

Need documentation for IT or an auditor?

Tell us what you need to document. We will discuss available records, access management and technical documentation.

Contact directly

Jakub Skoumal · Sales

or use the form below ↓

Please enter your name
Please enter a valid email
Please enter a message

By submitting this form, you agree to the processing of your data for the purpose of handling your inquiry, as described in our privacy policy.

Thank you. We have received your message.

We will get in touch to discuss the next steps.