Assess it. Understand it. Implement it.
The Swiss ICT minimum standard has 108 measures. This app walks you through all of them, scores your maturity exactly like the official Excel tool — and, for every single measure, tells you how to actually implement it.
iPhone · iPad · Mac · iOS 17 or later, macOS 14 or later · One purchase covers all three
Screenshots
Shown in English — the app also speaks German, French, Italian and Romansh.
Dashboard · Overall maturity, every function against the target value.
Assessment · All 108 measures with priority and your current rating.
Measure · Official wording, then maturity 0–4 — as in the Excel tool.
Guidance · Steps, common mistakes, effort, and the audit evidence.
Report · Result, radar profile, gap analysis — and the PDF.
Dashboard · Overall maturity, every function against the target value.
Assessment · All 108 measures with priority and your current rating.
Measure · Official wording, then maturity 0–4 — as in the Excel tool.
Guidance · Steps, common mistakes, effort, and the audit evidence.
Report · Result, radar profile, gap analysis — and the PDF.
Everything an SME needs to get from "we should do something about cyber security" to a documented, defensible assessment.
The complete catalogue — five functions, 23 categories — with the official wording, priority and the references to CIS, COBIT, ISO 27001 and NIST SP 800-53.
Per measure: one sentence for the management, three to five concrete steps, the mistakes people actually make, and what counts as evidence in an audit.
Levels 0–4 plus "not applicable", averaged exactly the way the official workbook does it, against the target value of 2.6.
Management summary with a radar chart, category overview, gap analysis, per-measure detail with your comments — and optionally the implementation guidance for everything below target.
German, French, Italian and English from the official standard, plus an unofficial Romansh version — switchable at any time, not tied to the system language.
No account, no cloud, no analytics, no network requests at all. Your assessment stays on your device — which is rather the point for a cyber security tool.
ID.AM-1 · What it looks like
The official text tells you what is expected. Every measure in the app also carries this:
Record, once, everything that processes or stores data: servers, PCs, laptops, mobile devices, network gear, printers, industrial controllers — including devices in home offices and in production.
Note for each entry: location, responsible person, purpose, business criticality and who provides support.
Decide who updates the inventory on purchase, relocation or decommissioning — anchor that task in procurement, not only in IT.
Scan the network automatically and regularly, compare the result against the list, and clarify every unknown device.
Review the inventory in full at least once a year and document that review with a date.
Every measure names what an auditor will want to see. One tap copies that sentence into the comment field of your assessment — so the evidence you need to produce and the notes you keep are the same document.
Hours, days or weeks — and whether it lands with the management, internal IT, your IT provider or the staff. Plan the next quarter without first reading all 108 measures.
Create, duplicate and rename assessments to track progress over time or to assess sites separately. Everything can be exported as a single backup file and imported again — on the same device or another one.
Chosen at first launch, changeable at any time in the profile. The report follows the language you are in.
The free version is a real working version, not a preview: the first four measures of every function, fully readable, ratable and with the complete guidance.
20 of 108 measures, one assessment.
Per year. The usual choice.
Per month — or 199.00 once, without a subscription.
Free to download. Prices in US dollars as listed on the App Store; you pay in your own currency. Subscriptions renew until cancelled in the App Store account settings.
An independent app. treeinspired GmbH is not affiliated with, authorised by or endorsed by the Federal Office for Cyber Security (BACS/NCSC) or any other federal body. The ICT minimum standard itself is published by the Confederation and is available free of charge at bwl.admin.ch.
What you are paying for is the implementation guidance, the assessment and the report — not the standard, which stays free.
The Romansh version is a machine-assisted translation and is marked as unofficial throughout the app. The standard is officially published in German, French, Italian and English.
Not legal advice. The guidance describes common practice; it does not replace legal advice or an audit.
Support
Write to us — in German, French, Italian or English. We answer within two working days.
info@treeinspired.com