Skip to content
MAWT Logo
Security

Compliance that wins contracts instead of slowing them down.

Overview

nLPD and GDPR documentation, processing registers, ISO 27001 preparation and credible answers to your large clients' security questionnaires.

Compliance services help a Swiss SME meet its data protection obligations — nLPD and, where relevant, GDPR — with a register of processing activities, clear documentation and proportionate measures. MAWT also prepares companies toward ISO 27001 (certification itself is issued by accredited bodies) and helps answer the security questionnaires that large clients increasingly require.

Target

For Swiss SMEs that handle personal data, sell to larger organizations, or serve EU clients — software vendors, fiduciaries, healthcare providers, service companies — and need their compliance to be real, documented and defensible, without hiring a full-time compliance officer.

Details

Data protection compliance has become a commercial requirement for Swiss SMEs: large clients send security questionnaires, tenders demand documentation, and the nLPD expects you to demonstrate — not just claim — that personal data is protected. Most SMEs do not need more paper; they need documentation that matches reality.

MAWT builds that with you: a register of processing activities based on your actual data flows, policies your team can follow, preparation toward ISO 27001 when a market requires it — certification itself belongs to accredited bodies — and a reusable, evidence-backed base for client questionnaires. Senior compliance and security expertise from our network, one point of contact.

Compliance is now a sales requirement, not just a legal one

The pressure rarely comes from the regulator first. It comes from your clients: a large account sends a forty-question security form, a public tender asks for your data protection documentation, an EU prospect wants proof of GDPR alignment. Companies without answers lose deals quietly.

Done pragmatically, compliance becomes an asset. A clean register of processing activities, honest policies and documented measures let you answer in days instead of scrambling for weeks — and signal to demanding clients that you take their data seriously.

nLPD and GDPR without the paper factory

The Swiss nLPD expects you to know what personal data you process, why, where it goes and how it is protected — and to be able to demonstrate it. If you serve EU residents, GDPR adds its own requirements. Neither law rewards volume: a hundred pages of copied templates protect no one.

We work from your actual data flows. We map processing activities, write the register, produce privacy notices and internal rules your team can actually follow, and identify where technical measures — access control, retention, hosting choices — need to catch up with the paperwork. Where systems need changing, our development and automation teams can implement directly.

ISO 27001: preparation, honestly framed

More and more Swiss SMEs pursue ISO 27001 because a key client or market demands it. Let us be precise about roles: certification is issued by accredited certification bodies after an independent audit. MAWT does not certify anyone — we prepare you, which is most of the work.

Preparation means building an information security management system that fits your size: risk assessment, a statement of applicability, policies, controls and the evidence trail an auditor will ask for. We run this with senior security experts from our network who have been through the process, and we keep it proportionate — an SME's ISMS should not look like a bank's.

  • Gap analysis against ISO 27001, with a realistic effort estimate
  • Risk assessment and statement of applicability
  • Policies and controls sized for an SME, not copied from a corporate template
  • Evidence collection organized so the audit is not a fire drill
  • Support during the certification audit itself, alongside your team

Security questionnaires: answer once, reuse forever

Vendor security questionnaires are repetitive by design. We build you a base of honest, evidence-backed answers — your measures, your hosting, your subcontractors, your incident process — and adapt it per client. The first questionnaire takes effort; the next ones take hours.

Where a questionnaire reveals a genuine gap, we say so, and propose the proportionate fix rather than creative wording. Credibility with a large client's security team is worth more than a perfect-looking answer sheet.

What it includes
  • nLPD and GDPR gap analysis in plain language
  • Register of processing activities, built and maintained
  • Privacy notices, policies and internal guidelines that fit reality
  • Preparation toward ISO 27001 with a realistic roadmap
  • Answers to client security questionnaires, backed by evidence
  • Support on subcontractor and data transfer agreements
Deliverables
  • A register of processing activities that reflects your real data flows
  • Privacy notices and internal data protection rules your team can follow
  • A gap analysis with a prioritized, costed action plan
  • An ISO 27001 preparation roadmap and the ISMS documents to match, when relevant
  • A reusable, evidence-backed base for client security questionnaires
Takeaways
  • Compliance pressure comes from clients and tenders before regulators.

  • The nLPD expects a documented, defensible posture — not template volume.

  • MAWT prepares you toward ISO 27001; accredited bodies certify.

  • A good questionnaire answer base turns weeks of scrambling into hours.

  • Documentation only counts if the technical measures behind it are real.

You might also need

Cybersecurity

Pragmatic cybersecurity for Swiss SMEs: risk assessment, MFA and backup hardening, team awareness and a rehearsed incident response plan. One contact.

Penetration Testing

Targeted penetration tests for Swiss SMEs: web applications, APIs and infrastructure, with a clear contractual scope, a prioritized report and a re-test after fixes.

Frequent questions

Does the nLPD apply to small companies?

Yes. The nLPD applies as soon as you process personal data — clients, employees, prospects — regardless of company size. Some obligations scale with risk, and companies under 250 employees benefit from limited exemptions on the register for low-risk processing, but the core duties of protection and transparency apply to everyone.

What is the difference between the nLPD and GDPR?

They share the same philosophy: transparency, proportionality, documented protection. The GDPR is stricter on legal bases and sanctions; the nLPD has Swiss specifics, including personal criminal liability for responsible individuals in some cases. If you serve EU residents, you likely need to comply with both — much of the work overlaps, so we build the documentation once and map it to each.

Can MAWT certify us ISO 27001?

No — and be wary of anyone who claims otherwise. ISO 27001 certification is issued exclusively by accredited certification bodies after an independent audit. What we do is the preparation: gap analysis, risk assessment, policies, controls and evidence, so that you arrive at the audit ready. That preparation is typically the bulk of the effort.

How long does ISO 27001 preparation take for an SME?

Commonly six to twelve months from gap analysis to audit readiness, depending on your starting point and how much time your team can invest. Rushing it produces a paper ISMS that falls apart at the surveillance audit. We give you a realistic estimate after the gap analysis, not before.

What is a register of processing activities?

A structured inventory of the personal data you process: what data, for what purpose, on what basis, who accesses it, where it is stored, how long you keep it, and which subcontractors are involved. It is the backbone of nLPD and GDPR compliance — most other documents derive from it, which is why we always start there.

A large client sent us a security questionnaire. Where do we start?

Do not answer line by line from scratch. We first establish what is actually true about your setup — hosting, access, backups, incident handling — then answer from evidence. Honest answers with a short remediation plan for the gaps consistently land better with security teams than polished claims that unravel in a follow-up call.
Next steps

Make compliance something you can show, not something you fear.