SCHUHFRIED's technical and organizational measures are aligned with internationally recognized security and quality frameworks. This page outlines the certifications currently held by SCHUHFRIED (ISO 9001:2015 and ISO 13485:2016) as well as those currently being pursued (Cybertrust Austria – Standard Level). In addition, this page provides information on the extent to which the measures we have implemented comply with key security frameworks (NIS 1 and NIS 2 Directives).
ISO 9001:2015 – Quality management system
ISO 9001:2015 is the internationally recognized standard for Quality Management Systems (QMS). Certification requires an organization to demonstrate consistent control over its processes, a commitment to continual improvement, and the ability to meet customer and regulatory requirements systematically.
SCHUHFRIED holds ISO 9001:2015 certification, issued by SIQ Ljubljana (IQNET member). The certificate covers research, design and development, production and sales of computer assisted psychological assessment and cognitive rehabilitation.
|
Detail |
|
|---|---|
|
Certificate number |
Q-2335 / IQNET SI-Q-2335 |
|
Certification body |
SIQ Ljubljana (IQNET member) |
|
First issue date |
2021-12-29 |
|
Issue date (current issue) |
2024-12-24 |
|
Valid until |
2027-12-29 |
|
Scope |
Research, design and development, production and sales of computer assisted psychological assessment and cognitive rehabilitation |
For customers, ISO 9001:2015 certification means that SCHUHFRIED's development, validation, support, and release processes are defined, documented, regularly reviewed, and subject to independent third-party audit. This provides a structural foundation for reliable and consistent software delivery.
ISO 13485:2016 – Medical devices quality management system
ISO 13485:2016 is the QMS standard specifically designed for the medical devices sector. It goes beyond ISO 9001 by adding requirements for regulatory compliance, risk management, device traceability, and post-market surveillance — reflecting the heightened safety obligations that apply to diagnostic products under frameworks such as the EU Medical Device Regulation (MDR 2017/745).
SCHUHFRIED holds ISO 13485:2016 certification, issued by SIQ Ljubljana (IQNET member). The certificate covers design and development, production and sales of biofeedback and stimulant current devices.
|
Detail |
|
|---|---|
|
Certificate number |
M-138 / IQNET SI-M-138 |
|
Certification body |
SIQ Ljubljana (IQNET member) |
|
First issue date |
2018-10-30 |
|
Issue date (current issue) |
2025-01-17 |
|
Valid until |
2028-02-22 |
|
Scope |
Design and development, production and sales of biofeedback and stimulant current devices |
Holding ISO 13485:2016 demonstrates that SCHUHFRIED operates under a rigorous, audited quality system that accounts for the particular demands of medical-grade products, including structured design controls, risk management throughout the product lifecycle, and systematic post-market follow-up.
Cybertrust Austria – Standard level (certification pending)
Cybertrust Austria is a cybersecurity label operated jointly by the Austrian Federal Economic Chamber (WKO) and the Austrian Federal Chancellery, and is endorsed by the Austrian government as a benchmark for organizational cybersecurity maturity. It is designed for Austrian companies and is increasingly referenced in public procurement and B2B trust assessments.
SCHUHFRIED is actively working towards obtaining the Cybertrust Austria Standard level certificate. The certification is currently in progress. Once awarded, this will provide customers with independent third-party confirmation of SCHUHFRIED's organizational cybersecurity posture.
General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) is the central legal framework for the protection of personal data in the European Union. It applies directly in all EU Member States and establishes binding requirements for the collection, processing, storage, and transfer of personal data—with particular emphasis on the rights of data subjects, the security of processing, and transparency toward customers and data subjects.
As a provider of a system for psychological assessment, SCHUHFRIED is directly affected by the GDPR. For VTS online, SCHUHFRIED acts as a processor on behalf of its customers, which act as controllers within the meaning of the GDPR. SCHUHFRIED confirms full compliance with the applicable GDPR requirements in all relevant areas. The technical and organizational measures pursuant to Art. 32 GDPR are documented in detail on the Technical Measures and Organizational Measures pages. The contractual basis of the processing relationship, including provisions on data subject rights, data breaches, and sub-processing, is established in the Data Processing Agreement (DPA), which applies to all VTS online customers. The sub-processors used are listed on the Sub-processors page.
EU Artificial Intelligence Act (EU 2024/1689)
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689, also known as the AI Act) is the first comprehensive regulation of artificial intelligence in the European Union. It classifies AI systems according to their risk level and establishes corresponding requirements for developers and operators. Particular attention is paid to so-called high-risk AI systems, including systems explicitly used in the area of psychological assessments or for making decisions about natural persons.
The Vienna Test System contains no components that would qualify as AI systems within the meaning of the EU AI Act. The psychological test procedures available in the WTS are scientifically established instruments developed on the basis of established psychological theories and tested and normed for their psychometric properties. Results are evaluated and interpreted using purely rule-based, scientifically established methods and norms. Machine learning, neural networks, and automated decision-making systems are not used. The EU AI Act therefore does not give rise to any immediate regulatory obligations for SCHUHFRIED in relation to the WTS.
NIS1 Directive (EU 2016/1148)
The first Network and Information Security Directive (NIS1, Directive 2016/1148/EU), transposed into Austrian law as the Netz- und Informationssystemsicherheitsgesetz (NISG), introduced mandatory security and incident reporting obligations for two categories of organization: Operators of Essential Services (OES) (in sectors such as energy, transport, banking, healthcare, and digital infrastructure) and Digital Service Providers (DSPs) (online marketplaces, online search engines, and cloud computing services meeting certain scale thresholds).
SCHUHFRIED is not classified as an Operator of Essential Services under NIS1, nor does it qualify as a regulated Digital Service Provider under the directive's scale and category thresholds. Accordingly, NIS1 does not impose direct legal obligations on SCHUHFRIED. Nevertheless, the security measures SCHUHFRIED has implemented, covering access control, encryption, logging, incident response, and business continuity, are substantively aligned with the security baseline that NIS1 requires of in-scope organizations.
NIS2 Directive (EU 2022/2555)
The NIS2 Directive (Directive 2022/2555/EU) significantly expands the scope and requirements of the original NIS1 framework. It introduces a broader set of covered sectors, lowers the size threshold for in-scope entities, introduces new categories (Essential Entities and Important Entities), and strengthens requirements around supply chain security, vulnerability disclosure, incident reporting, and management accountability. In Austria, NIS2 is being transposed as the NISG 2024 (with provisions taking full effect progressively through 2024–2026).
SCHUHFRIED does not fall within the NIS2 Directive's scope of Essential or Important Entities based on its sector classification and organizational size. Direct regulatory obligations under NIS2 therefore do not apply to SCHUHFRIED as a software vendor in the psychological assessment domain.