Need to show how you manage access and which events you record? We will explain what evidence ChipLogin provides and how it can support an internal review or audit preparation.
The applicability of NIS2, GDPR, the Machinery Regulation or IEC 62443 requirements depends on your organisation, deployment and jurisdiction; the product alone does not ensure compliance. Verify your specific obligations with a legal adviser.
The NIS2 Directive expands cybersecurity obligations — access control, logging, incident reporting — to a much broader circle of "essential" and "important" entities than the original NIS Directive covered, including manufacturing, energy, and other industrial sectors. In the Czech Republic it's implemented as Act No. 264/2025 Coll., in force since November 1, 2025. Exact scope, deadlines, and penalties vary across other EU member states.
Access logs and card data are personal data. GDPR requires a legal basis for processing, data minimization, and clarity on who is the controller and who is the processor for any system that records who accessed what, and when.
For manufacturers and integrators, the updated Machinery Regulation tightens requirements for safety-related control systems — including who is authorized to operate a machine or override its safety interlocks.
ChipLogin provides mechanisms relevant to parts of FR1 (identification and authentication), FR2 (use control and audit records), and FR4 (data confidentiality), including named card identities, cryptographic authentication, signed records, and encrypted communication. Applicability and conformity must be assessed for the complete industrial automation and control system. FR3, FR5, FR6, and FR7 remain outside ChipLogin's component scope; this is not a certification or conformity claim.
The product includes mechanisms that can contribute evidence for access-control and audit requirements.
ChipLogin bases authorization on a registered card identity. Configuration, operating procedures, and the wider environment still determine whether a deployment meets a specific control or audit requirement.
The system records who logged in, operated a connected machine, or used a connected door and when, with cryptographic signing intended to make later changes detectable. Whether that evidence is sufficient is determined by the applicable audit scope.
ChipLogin Server runs on your own infrastructure. No copy of access and audit data ends up with a third-party cloud provider that you'd have to cover in a data processing agreement.
Revoke someone's access to Windows, machines, and doors from a single place. No orphaned permissions quietly surviving in a system nobody got around to updating.
Netajo s.r.o. (the company behind ChipLogin) is the controller of personal data it processes for its own purposes — for example, messages submitted through the contact form on this website. Roles for a customer deployment depend on its configuration and the parties' agreement. ChipLogin Server runs on the customer's infrastructure; customers should determine their own controller and processor responsibilities for access and audit data.
This page is a plain-language summary, not legal advice — verify specific obligations, scope, and deadlines under NIS2, GDPR, or the Machinery Regulation with a qualified lawyer. How we handle data you submit to us directly is described in our privacy policy.
Tell us what you need to document. We will discuss available records, access management and technical documentation.
or use the form below ↓
We will get in touch to discuss the next steps.