News

ATHENE UP26@it-sa finalists: An interview with Complioty

31/08/2026

Complioty is one of the five finalists for the ATHENE UP26@it-sa Award

According to the VDMA, one in four mechanical engineering companies has experienced a cyber security incident in the last two years. Complioty automatically generates software bills of materials and continuously monitors them for vulnerabilities, rather than simply recording them once and then forgetting about them. From December 2027, the Cyber Resilience Act will make precisely this a mandatory requirement for the entire mechanical engineering sector. In this interview, the founders explain why they changed direction whilst the business was still being set up, and why this very decision became their greatest strength.

Your start-up in one sentence?

Complioty turns product security into an ongoing process rather than a one-off project for mechanical engineering firms: SBOMs generated automatically, continuous vulnerability monitoring and CRA compliance, all on a single platform. 

#ProductSecurity #CyberResilienceAct #Ma­schinen­bau

How did your business idea initially develop?

The idea arose from Markus’ and Philip’s PhD research at the University of Regensburg on industrial cyber security. In discussions with various mechanical engineering firms, we kept seeing the same pattern: a consultant would draw up a threat model, only for it to be abandoned three months later. A developer would manually search for vulnerabilities whilst juggling client projects. Or there would be an Excel spreadsheet that everyone knew wasn’t enough. 

The moment it all ‘clicked’: when we saw an employee at a company manually searching through CVE databases using Excel lists and simply finding no entries there for their control systems. It became clear then: there is no tool that accurately reflects the reality of mechanical engineering. Machines that run for 15 to 20 years, purchased control systems without SBOMs, and no ability to respond to new CVEs. With the Cyber Resilience Act, this problem will become a legal obligation from December 2027. This is precisely the gap we are closing. 

How big is your team, who’s in it, and how did you all meet?

There are currently seven of us: Dr. Markus Hornsteiner (CEO) and Dr. Philip Empl (CTO) as founders, Henric Hager, Zubayr Khalid and Manuel Wilhelm as software engineers, and Josef Bateni and Caylin Hutton as Founders Associates. Markus and Philip met whilst studying for their PhDs in industrial cyber security at the University of Regensburg. 

What makes our set-up unique is that both founders have a background in industrial cyber security research: Philip specialises technically in automated incident response, whilst Markus has a more organisational focus on process management for cyber security. This means we bring in-depth expertise in OT security, threat modelling and compliance, combined with an advisory board comprising experts from industry and academia (Prof. Dr Stefan Schönig, Prof. Dr Christian Roth). We complement each other most effectively where the product meets the market: Philip drives the technical depth of the platform, whilst Markus translates this into what mechanical engineering firms really need and understand. 

Who benefits from your solution, and why?

Machinery and plant manufacturers, particularly small and medium-sized enterprises, which do not have their own product security department. According to the VDMA, one in four machinery manufacturers has experienced a cyber security incident in the last two years, and cases such as Pilz (42 days of total downtime) or Schumag (insolvency following a ransomware attack) demonstrate what is at stake. 

In practical terms, we make life easier for developers and development managers who have previously been responsible for security ‘on the side’: instead of manually creating SBOMs and searching through CVE databases, our scanner automatically generates the SBOMs, network or diagnostic files, and the platform automatically checks every new vulnerability against it, only alerting users when a machine is actually affected. From threat modelling and supplier management right through to CSAF advisories for customers and regulatory authorities: one process instead of ten Excel files. And ultimately, the machine operators benefit too, because security vulnerabilities are detected before they turn into incidents. 

What are your next steps? 

In the short term: to introduce our SBOM scanner to more manufacturers and, together with our pilot partners, to further refine the platform to better reflect the realities of the mechanical engineering sector. The €800,000 in funding from the BMBF under the StartUpSecure programme is giving us a boost in building our team and developing our product. 

In a year’s time, if all goes well: we’ll be working live with 100 customers in the mechanical engineering sector, and we’ll be the obvious choice for mechanical engineering firms looking to answer the question, “How can we become CRA-ready by December 2027?”. After all, by then there will only be a few months left until it becomes a legal requirement. 

Why are you so convinced that you, of all people, will be successful?

Our trump card is the combination of genuine domain expertise and perfect timing. We aren’t coming into the mechanical engineering sector as an external security tool; we come from within it: Markus completed an apprenticeship in mechanical engineering, and both founders wrote their PhD theses on precisely these topics, having already collaborated with renowned mechanical engineering firms in the process. We know the sector, the processes and the problems first-hand. This knowledge cannot be easily replicated. 

Generic compliance tools do not understand machines. This starts with data capture: our scanner generates SBOMs directly from TIA Portal, B&R and CODESYS projects, actively reads network data, utilises data from manufacturer tools such as Siemens, Schneider and Rockwell, and, where available, also integrates ERP and PLM systems as data sources – for every build, in accordance with CycloneDX. 

And the issue of vulnerabilities goes further: for industrial components, there are often simply no CPE entries, meaning traditional matching comes to nothing. We have therefore developed our own comprehensive matching algorithms that consolidate information from various sources to reliably link devices and vulnerabilities. To achieve this, we integrate over 90 vulnerability databases – regardless of their format, be it CSAF, PDF or even manufacturer emails – and convert everything into a standardised, analysable format that is linked to the data from the SBOM. This provides a complete overview of the entire machine, not just the software. 

The market is moving in our direction: from December 2027, the Cyber Resilience Act will make compulsory what we already offer as an established process today. On-premises and EU hosting options also address the concerns that small and medium-sized enterprises otherwise have about cloud tools. 

What have been the biggest successes and challenges so far?

Our greatest achievements: winning the ATHENE SpeedUpSecure Accelerator 2025, being accepted into the WERK1 Accelerator in Munich and, of course, the €800,000 in BMBF funding as part of the StartUpSecure programme. What matters most to us, however, is what’s happening in the market: we already have well-known manufacturers live on our platform and a well-stocked pipeline of further major clients. 

A mistake we’re almost proud of in hindsight: at the start of 2024, we’d set our sights on NIS2. We soon realised, however, that industrial networks – with their countless participants and interdependencies – were far too complex and far too large for us to tackle as a starting point. So we changed tack and shifted our focus entirely to product security and the Cyber Resilience Act. Looking back, this ‘detour’ was worth its weight in gold: we learnt how important a sharp focus is, and it is precisely this focus on the machine as a product that is our greatest strength today. 

Why did you enter the ATHENE Startup Award UP26@it-sa?

ATHENE knows us and we know ATHENE: as winners of the SpeedUpSecure Accelerator 2025, we have seen just how much substance there is behind this network. For us, the award at it-sa is the logical next step: Europe’s most important IT security trade fair, the most relevant audience for our topic, and a platform where product security for the mechanical engineering sector gains the visibility it deserves in light of the CRA. 

The final push? It’s a simple calculation: the clock is ticking for every mechanical engineering firm in Europe until 11 December 2027. If we don’t talk about product security in mechanical engineering on this stage now, when will we? 

  

show all news