New: the first SBOM scanner for machines.Take a look
Machinery and plant engineering

You know which software is inside your machine.

Complioty reads the bill of materials out of your control project, reports only the vulnerabilities that actually affect your plant, and produces the advisories your customers ask for. You do not need a security team of your own for that.

Complioty showing the bill of materials of a flow wrapper with its assemblies and the vulnerabilities assigned to them

The software bill of materials is already in your customers' specifications today.

From 11 December 2027, without product security you will not get a CE mark and you will not be allowed to ship into the EU. The order, however, is decided earlier than that, at the next framework agreement.

The problem

You know everything about the mechanics and almost nothing about the software.

Which cylinder sits in axis 4, who supplied it and what it cost has been recorded cleanly in the ERP for years. Which firmware runs on the drive, which library version is linked into the control, and what ended up on the industrial PC during commissioning is often known only by the colleague who was there at the time.

As long as nobody asked, that was not a problem. Now you sign a declaration of conformity for a machine whose software you do not fully know and that will stand at the customer site for another twenty years.

This is not a failure on your part. There has simply been no tool that collects the answer where it has always been: in the control project, in the wiring diagram and in the image of the industrial PC.

Who is behind this

Nobody at your company was hired to maintain vulnerability lists. And the tools IT has for the job do not fit a controller.

After training as an IT specialist in machine building, I found out the hard way during my doctorate that cybersecurity in this industry is more than complex.

Dr. Markus Hornsteiner Dr. Markus Hornsteiner CEO and founder · Complioty

Funded and supported by

  • BMBF
  • Uni Regensburg
  • ATHENE
  • BayStartUP

Spin-off of the University of Regensburg. First place at ATHENE SpeedUpSecure. Based in Munich.

How it works

Set up in three steps.

  1. Extract

    The Scanner reads the control project, the wiring diagram and the IPC image directly. It runs locally on your own machine and takes minutes instead of months. You do not have to write to a single supplier.

    Scanner
  2. Monitor

    Complioty checks every new vulnerability advisory against your bill of materials. What decides the outcome is not the CVSS score but whether the component is reachable at all inside your architecture.

    Observer
  3. Report

    You publish a CSAF advisory: machine readable, versioned and served from your security.txt. Nobody at the customer has to retype anything out of a PDF.

    Notifier

Across the entire life of the machine

  1. Design

    Threat model on the wiring diagram

    Designer
  2. Engineering

    Bill of materials from the project

    Scanner
  3. Sourcing

    PSIRT maturity of suppliers

    Tracer
  4. Operation

    Vulnerabilities across twenty years

    Observer
  5. Incident

    Advisory to the operator

    Notifier

Tuesday, 9:40 am

Your customer reads the new Siemens advisory and calls you.

Siemens ProductCERT publishes SSA-019200. The operator's security team has read it before you heard about it and wants to know by tomorrow whether the line in hall 3 is affected.

The answer is already there. Complioty matched the advisory against your bill of materials the moment it appeared and assigned and assessed the affected component. You do not send a PDF, you send an advisory the security team can read straight into their own tooling.

1,284
advisories per month
3
concern your machines

Siemens Security Advisory by Siemens ProductCERT

SSA-019200: Multiple Vulnerabilities in SCALANCE W-700 IEEE 802.11n Devices Before V6.6.0

Publication Date
2026-04-14
Last Update
2026-04-14
Current Version
V1.0
CVSS v3.1 Base Score
9.1
CVSS v4.0 Base Score
9.4

Match in your bill of materials

-K4.2 · SCALANCE W-700

Multiple vulnerabilities in the Wi-Fi implementation. Siemens states that they can only be exploited within Wi-Fi range.

VEX: not_affected

The Wi-Fi module is not in operation on this machine, the access point runs over the wired connection only. That removes the radio range every listed vulnerability depends on.

  1. Received
  2. Assessed
  3. Approved
  4. Published · CSAF 2.0

The obvious objection

IT has tools for this. For the machine there are none.

There has long been a tool for every CRA duty. All of them assume the software arrives as a repository, a container or a package manifest. Yours arrives as a control project.

Bill of materials

Container scanners from software development

They read images and package manifests. A controller, however, does not hand you a file system but an engineering project file.

Risk

Threat modeling tools from application security

They model web servers, databases and trust boundaries. Security zones, PROFINET and emergency stop paths are unknown to them.

Disclosure

Bug bounty and reporting platforms

They are built to receive vulnerability reports. The CRA asks the opposite of you: that you publish advisories yourself, in CSAF format.

Evidence

Compliance automation from the cloud world

Their connectors reach into cloud, identity and endpoint. None of them reaches a machine that has stood at the customer site for eight years.

Here the parts are called switch, I/O module and controller, not npm package.

What you do not have to give up

Your project files stay where they are.

Scanner

Runs offline on your own machine

Control projects, wiring diagrams and IPC images never leave your network.

Reads

  • Siemens
  • B&R
  • Rockwell
  • Beckhoff
  • ABB
  • Schneider Electric
  • Mitsubishi
  • Bosch Rexroth

and 40+ more vendors

Produces

CycloneDX, SPDX

Scanner

Platform

Runs in the public cloud, your private cloud or on-premises

Run as a managed service, we host it in German data centres. No transfer to third countries.

Reads

CycloneDX, SPDX

Returns

Vulnerabilities, threat models, VEX assessments and CSAF advisories

Scanner and platform work in open formats. Everything that goes in comes back out.

Cyber Resilience Act

December 11, 2027.

From then on, product security is a legal obligation. No evidence, no CE marking.

486
Days
:
11
Hrs
:
19
Min
:
36
Sec

From guessing to evidence.

Start with what you already have. One existing control project is enough for the first run.