100 hours of AI training where every department left with something that works
Manufacturer of dehumidification and air treatment systems (HVAC)·Manufacturing SME·AI training — general + per functional area
ALBERTO SCARPA — AI · CYBERSECURITY · REGULATION
I help Italian manufacturers of machinery and embedded systems build AI and security into the product from the design stage — so they reach the European market faster, with fewer surprises and a measurable competitive edge.
45 free minutes, no preparation needed. You leave with a written diagnosis.
WHY INTEGRATING PAYS OFF
Built in at design time, it becomes a measurable advantage. That's what I see in every project — and it works on three fronts.
01 — SPEED TO MARKET
Fixing compliance at the end slows the launch, costs more and risks a product recall. Building security and regulatory requirements in from the first design review shortens timelines — compliance stops being the last-minute obstacle.
02 — SUPPLY CHAIN
OEMs and large industrial groups now require compliance from their suppliers as a contractual condition. Those already compliant win the contracts. Those who aren't are ruled out of the selection before they even submit a bid.
03 — BY DESIGN
A product with security by design and CRA and IEC 62443 compliance is more reliable, more updatable, more defensible on the market. Security done well becomes a selling point, not a hidden cost.
THE LAYERED SYSTEM
Each layer stands on its own and doesn't commit you to the next. Declared output: you know what you get before you begin.
L0 — FREE
45 minutes with the CEO or CTO. A map of your actual regulatory exposure and a recommended direction, in writing within 24 hours.
L1 — TRAINING
4-hour modules in the Learn · Practice · Build format. Your team leaves with operational skills, not slides.
L2 — ASSESSMENT
One or two days, AI or OT track. Prioritised gaps and a concrete action plan.
L3 — CONTINUOUS OVERSIGHT
Year-round oversight of the obligations that don't end with a project: CVEs, SBOM, AI register, supply chain.
Custom projects grow out of Compass: ISO 42001, CRA compliance, OT security on a specific plant.
See all servicesWHERE I WORK
My typical counterpart is the CEO or CTO of an Italian manufacturer with an in-house R&D team and its own product — where supply-chain pressure and regulation demand solid security and governance.
INDUSTRIAL & IIOT — MAIN FOCUS
Connected machines, industrial gateways, edge devices, remote access, OT platforms. IEC 62443 and CRA as the framework for security-by-design — from requirement to control to evidence.
MEDICAL & DIGITAL HEALTH
Regulated environments that demand lifecycle discipline, evidence and post-market security. Direct experience: I founded and led a medical device to EU and US certification.
CONNECTED CONSUMER
Connected products that need scalable vulnerability management, secure updates and CRA-ready processes.
WORK
Manufacturer of dehumidification and air treatment systems (HVAC)·Manufacturing SME·AI training — general + per functional area
Manufacturer of automation cells for sheet-metal processing·Manufacturing SME·CRA + IEC 62443 pre-analysis in the context of the Machinery Regulation
Fine jewellery manufacturing·Manufacturing SME·AI training — general + per functional area
FROM THE BLOG
The Regulatory Spark is a free 45-minute call with me. No preparation needed: we map your actual regulatory exposure and you leave with a written summary and a concrete next step. No commitment.
Book the Regulatory Spark