AMTSO
AMTSO is a non-profit standards organization founded in 2008 that convenes 60+ cybersecurity vendors, independent test labs, and researchers to develop transparent, standardized frameworks and guidelines for fair testing of security products, funded by tiered annual membership fees.
- Company typePrivate
- Founded2008
- HeadquartersSalt Lake City, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What AMTSO does
AMTSO (Anti-Malware Testing Standards Organization) is a California mutual benefit non-profit corporation founded in 2008 to address poor-quality and misleading IT security product testing. The organization functions as a membership community of 60+ cybersecurity vendors, independent test labs, academics, and related organizations, governed by an elected Board of Directors (four seats up annually, split between Tester and non-Tester members). Its core product is the AMTSO Testing Protocol Standard, a framework that establishes transparent, unbiased testing processes with public notifications, commentary periods, and compliance confirmation reports. The standard is paired with the "AMTSO Standard" and "AMTSO Confirmed Compliant" badges that appear on published tests listed in AMTSO's public Test Calendar.
The organization operates a portfolio of complementary products and services. The Real Time Threat List (RTTL) is a threat-intel and malware sample-sharing initiative where members contribute, augment, and enrich data interactively, with v3.0 expansion underway. The Security Features Check (SFC) is a free public tool that lets end-users verify their security protection is properly installed and operational. AMTSO also publishes formal testing guidelines developed through member working groups — including VPN Performance Testing Guidelines (Feb 2025), Sandbox Evaluation Framework (March 2025, v1.1 in June 2026), Scam & Phishing Testing Guidelines (adopted 2026), and Guidelines for Testing of Agentic Security Products (June 2026). Supporting services include the Contact List system for tester-vendor communication and the XDR Product Data tracking system.
Revenue is generated entirely through tiered annual membership fees, not product sales. Entity membership scales with member revenue: $15,000 for $100M+ companies, $8,000 for $10M–$100M, $3,500 for $1M–$10M, $1,000 for under $1M (with a $500 first-two-year concession for new small members), and $1,500 for academic/NGO members. Individual memberships are $150/year for students and $250/year for others. Additional brands within a corporate group pay half the standard fee. Distribution is community-led, relying on the AMTSO website, biweekly newsletter, monthly Testing Town Hall webinars, and the annual Cyber Research Conference. The organization is headquartered in San Francisco, California (registered office at One Montgomery Street, Suite 3000) with a Salt Lake City, Utah mailing address.
AMTSO firmographics
Firmographics- Name
- AMTSO
- Legal name
- Anti-Malware Testing Standards Organization, Inc.
- Website
- https://amtso.org
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- AMTSO is a non-profit standards organization founded in 2008 that convenes 60+ cybersecurity vendors, independent test labs, and researchers to develop transparent, standardized frameworks and guidelines for fair testing of security products, funded by tiered annual membership fees.
- Ownership category
- akta.pro rank
AMTSO industry classification
Industry- Product category
- Cybersecurity Testing Standards
- NAICS
- Testing Laboratories and Services (541380), Testing Laboratories and Services (54138)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
Keywords
Where AMTSO is headquartered
LocationHeadquarters
- HQ city
- Salt Lake City
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
AMTSO business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Membership Fees: AMTSO generates revenue through annual membership fees from entity members including corporations, non-profit organizations, academic institutions. Fees are tiered based on annual revenue: $15,000 for $100M+, $8,000 for $10M-$100M, $3,500 for $1M-$10M, $1,000 for <$1M, $1,500 for academic/NGO. Individual membership available at $150/year for students and $250/year for other individuals. New members with <$1M revenue charged $500 for first two years.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Large enterprise members with annual revenues of $100 million or more |
| Subscription | Annual | Mid-size companies with annual revenues of $10 million to $100 million |
| Subscription | Annual | Small companies with annual revenues of $1 million to $10 million |
| Subscription | Annual | Small companies with annual revenues of less than $1 million |
| Subscription | Annual | Academic institutions and non-governmental organizations |
| Subscription | Annual | Full-time students in relevant areas of study |
| Subscription | Annual | Individual members (academics and other individuals) |
| Subscription | Annual | Brand representation for multiple brands within same corporate group |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels7 records
AMTSO product offering
Product offeringCore offering
AMTSO provides the AMTSO Testing Protocol Standard, a framework for transparent, unbiased cybersecurity product testing, along with the Real Time Threat List (RTTL) malware sample-sharing platform, Security Features Check (SFC) free verification tools, a Test Calendar of upcoming and published tests, and a published library of testing guidelines covering VPN, sandbox, scam/phishing, and agentic AI security products. Its core members are security vendors, independent test labs, academics, and researchers who jointly develop and adopt industry testing standards.
Product overview
AMTSO is a non-profit standards organization (not a product company) offering a platform for knowledge-sharing and collaboration on objective standards and best practices for cybersecurity product testing. The core offering is the AMTSO Testing Protocol Standard, complemented by free Security Features Check tools, the Test Calendar tracking system, and the Contact List service for facilitating tester-vendor communication. Supporting services include the Real Time Threat List (RTTL) for threat-intel and sample sharing, and XDR Product Data for tracking XDR testing coverage. AMTSO publishes guideline documents (VPN Testing, Sandbox Evaluation, Scam & Phishing, Agentic AI) developed through member working groups. Membership spans 60+ organizations including security vendors, independent test labs, and researchers.
Differentiator
Problem solved
Functional benefit
Products and services
- AMTSO Testing Protocol Standard Core framework establishing best practices and a compliance process for transparent, unbiased cybersecurity product testing. Used by independent test labs, security vendors, and AMTSO to evaluate and confirm compliance of tests against the standard.
- Security Features Check (SFC) Free verification tools that let end users confirm their security protection is properly installed, correctly configured, and fully operational on their system.
- Real Time Threat List (RTTL) Threat-intel and malware sample-sharing platform where security vendors contribute samples to enable unbiased efficacy testing. The system is being expanded to include new data enrichment pipelines and an intel-sharing platform.
- Test Calendar Public tracking system for upcoming and published anti-malware and related tests, marking those run under the AMTSO Testing Protocol Standard compliance process to help users find relevant test data.
- Contact List Service listing contact information for security product vendors and testers, facilitating communication in compliance with AMTSO Standards. Access available to AMTSO members and non-member anti-malware testers.
- XDR Product Data Tracking system developed by the XDR Testing Working Group providing criteria for testing XDR solutions and tracking what areas tests cover.
- VPN Performance Testing Guidelines First-ever AMTSO guideline providing standardized methodologies for evaluating VPN services, covering launch/boot testing, kill switch tests, leak prevention, split tunnel testing, speed/latency, and resource consumption.
- Sandbox Evaluation Framework First standardized methodology for assessing the effectiveness of sandbox-based malware analysis solutions, covering detection capability, anti-evasion technology, speed, reporting accuracy, scalability, and security compliance.
- Scam and Phishing Testing Guidelines Official AMTSO guideline providing standardized methodologies for testing protections against online scams and phishing attacks.
- Guidelines for Testing of Agentic Security Products Working draft guidelines from the AI Security Working Group providing detailed guidance for testers evaluating security protections for agentic AI systems.
Quantifiable outcome
- Over 60 member organizations participating in standards development
- +2 more outcomes
Companies that use AMTSO
Customer profileNamed customers31 records
Segments8 records
Ideal customer profiles4 records
AMTSO technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature7 records
AMTSO partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core and minor.
- SecureIQLabcoreSecureIQLab is an AMTSO member tester that conducts independent validation of cybersecurity products. They have registered post-quantum cryptography validation methodology with AMTSO as Test ID AMTSO-LS1-TP195 for cloud-native firewall testing, incorporating NIST post-quantum cryptography standards.
- NISTminorAMTSO standards incorporate NIST post-quantum cryptography standards (ML-DSA-65/87, ML-KEM-768/1024, SHA-384/512) in testing frameworks developed by member SecureIQLab.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
AMTSO competitors and assessment
Company assessmentEmerging players
- AV-TEST: Independent test laboratory and AMTSO member that publishes widely cited antivirus and security product evaluations. Operates as both an AMTSO member and a peer reference for transparent, repeatable testing — comparable in scope but narrower (testing) versus AMTSO's broader standards-setting remit.
- SE Labs: Independent security testing laboratory and AMTSO member that runs enterprise, SMB, and consumer endpoint protection tests under the AMTSO Testing Protocol Standard. Comparable as a downstream test-lab consumer of AMTSO's standards rather than a direct standards producer.
Broad incumbents
- Gartner: Global research and advisory firm whose cybersecurity Magic Quadrants and testing evaluations are consumed by the same enterprise IT buyers and security vendors AMTSO serves. Gartner's commercial evaluation reports substitute for — and sometimes compete with — AMTSO-aligned independent test lab results.
- Cloud Security Alliance (CSA): Non-profit organization that promotes security best practices and standards for cloud computing. CSA's industry consortium structure, working-group publications, and tiered membership model are closely analogous to AMTSO's approach in an adjacent cybersecurity sub-domain.
- OASIS Open: International non-profit standards body that develops open-source standards across security, IoT, and other domains. OASIS offers a parallel model of vendor-neutral, member-funded standards development that competes for member attention in the broader cybersecurity standards ecosystem.
- MITRE Corporation: Operates foundational cybersecurity programs including CVE, CWE, and ATT&CK that are upstream dependencies of all cybersecurity product testing. MITRE's standards-setting role is broader in scope but addresses the same underlying need for neutral, widely-adopted testing and classification frameworks.
Direct peers
- ICSA Labs: Independent division of Verizon that provides third-party testing and certification for security and IT products. ICSA Labs is one of the long-established commercial alternatives to AMTSO-aligned independent test labs and competes for the same vendor testing engagement budget.
- M3AAWG (Messaging, Malware and Mobile Anti-Abuse Working Group): Industry consortium that develops collaborative standards and best practices to combat messaging abuse, malware, and mobile threats. M3AAWG's membership-driven working-group model and publication of anti-abuse guidelines closely mirrors AMTSO's structure and approach.
- Anti-Phishing Working Group (APWG): International coalition unifying the global response to cybercrime and phishing. APWG operates as a non-profit industry consortium producing data, standards, and counter-ecrime tools — a structural twin to AMTSO in a related threat-testing domain.
- FIRST.org (Forum of Incident Response and Security Teams): Global association of incident response and security teams that develops standards, frameworks (e.g., CVSS), and best practices. Shares AMTSO's non-profit, member-funded, consensus-driven approach to producing cybersecurity standards adopted across vendor, government, and research communities.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
AMTSO social profiles
Digital presenceAMTSO financial estimates
Financial estimateRevenue estimate
Valuation estimate
AMTSO leadership team
Management profileNumber of profiles
Profiles8 records
AMTSO funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
AMTSO M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about AMTSO
What does AMTSO do?
AMTSO provides the AMTSO Testing Protocol Standard, a framework for transparent, unbiased cybersecurity product testing, along with the Real Time Threat List (RTTL) malware sample-sharing platform, Security Features Check (SFC) free verification tools, a Test Calendar of upcoming and published tests, and a published library of testing guidelines covering VPN, sandbox, scam/phishing, and agentic AI security products. Its core members are security vendors, independent test labs, academics, and researchers who jointly develop and adopt industry testing standards.
Is AMTSO a public or private company?
AMTSO is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was AMTSO founded?
AMTSO was founded in 2008. It employs 11 to 50 people.
Where is AMTSO based?
AMTSO is headquartered in Salt Lake City, United States, in the North America region.
How does AMTSO make money?
One revenue line is on record: membership Fees.
Who are AMTSO's main competitors?
Emerging players on record are AV-TEST and SE Labs. Broad incumbents are Gartner, Cloud Security Alliance (CSA), OASIS Open and MITRE Corporation. Direct peers are ICSA Labs, M3AAWG (Messaging, Malware and Mobile Anti-Abuse Working Group), Anti-Phishing Working Group (APWG) and FIRST.org (Forum of Incident Response and Security Teams).
Does AMTSO have an API?
No public API is recorded for AMTSO.
What industry is AMTSO in?
AMTSO's product category is Cybersecurity Testing Standards. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 541380 and its SIC code is 8734.