Brightsight
Brightsight by SGS is a Netherlands-based cybersecurity evaluation laboratory and licensed certification body, performing 700+ Common Criteria, EUCC, SESIP, PCI, FIDO and EMVCo security assessments annually for regulated manufacturers of semiconductors, payment devices, IoT products and government identity documents worldwide.
- Company typePrivate
- Founded1982
- HeadquartersDelft, Netherlands
- Headcount101–250
- GTM typeB2B
- OfferingServices
What Brightsight does
Brightsight B.V., operating as "Brightsight by SGS," is a Netherlands-headquartered cybersecurity evaluation laboratory and certification body founded in 1982 and acquired by SGS Group in 2021. The company employs 250+ specialist security evaluators across 11 locations in Europe (Delft, Barcelona, Madrid, Graz, Meyreuil), Asia-Pacific (Beijing, Singapore), and North America, and executes more than 700 security evaluations annually across 50+ international schemes. Its service portfolio covers Common Criteria (ISO/IEC 15408:2022), EUCC, SESIP, FIDO, PCI PTS/MPoC/SPoC/CPoC/3DS SDK, EMVCo, RED (EN 18031), ISA/IEC 62443, FIPS 140-3 and PSA Certified evaluations, delivered under a structurally differentiated model that integrates an IT Security Evaluation Facility (ITSEF) and a licensed Certification Body under one roof.
The technical platform rests on more than 55 specialized laboratory setups supporting side-channel analysis, perturbation (fault injection) attacks, reverse engineering, physical attack labs and IT vulnerability analysis. Noteworthy proprietary capabilities include the industry's first Common Criteria EAL5+ evaluation of a secure IC implementing Post-Quantum Cryptography (Samsung), the first commercial FIDO2 Authenticator Level 3+ certification (Eviden/Infineon SECORA ID V2), the first EUCC 'High' certification from the Netherlands (NXP SN300 eUICC) and the first SESIP Level 3+ certificates for microprocessors (STMicroelectronics STM32MP13xx) and UWB modules (Samsung U100). Brightsight is also a founding member of SESIP under GlobalPlatform, an elected Eurosmart board member, an OCP S.A.F.E. Security Review Provider and a board participant in EUCC ISAC technical working groups.
Brightsight monetizes through professional-services fees for each evaluation project, certification issuance fees as a licensed Certification Body (EUCC, SESIP, PSA Certified), and standalone advisory and training engagements covering Security Target writing, gap analysis and scheme-specific certification readiness. Customers are regulated product manufacturers and developers in semiconductors and ICs, payment (terminals, mobile acceptance, EMV), IoT (consumer, industrial, automotive, MedTech), government identity, digital identity and authentication (FIDO2 authenticators) and telecommunications. Distribution is direct enterprise sales supported by localized accredited labs and scheme-recognized certification pathways, with go-to-market amplified through the SGS parent network and thought-leadership channels including the Bright Insight podcast, Brightsight Bulletin newsletter, and presence at ICCC, OCP EMEA, Embedded World and MWC.
Brightsight firmographics
Firmographics- Name
- Brightsight
- Legal name
- SGS Société Générale de Surveillance SA
- Website
- https://brightsight.com
- Company type
- Private
- Founded year
- 1982
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Brightsight by SGS is a Netherlands-based cybersecurity evaluation laboratory and licensed certification body, performing 700+ Common Criteria, EUCC, SESIP, PCI, FIDO and EMVCo security assessments annually for regulated manufacturers of semiconductors, payment devices, IoT products and government identity documents worldwide.
- Ownership category
- akta.pro rank
Brightsight industry classification
Industry- Product category
- Cybersecurity Evaluation and Certification Services
- NAICS
- Other Computer Related Services (541519)
- SIC
- Services-Services, Nec (8900)
- akta.pro primary industry
- Security Maturity Assessments & Benchmarking (BPAKADAO)
Keywords
Where Brightsight is headquartered
LocationHeadquarters
- HQ city
- Delft
- HQ country
- Netherlands
- HQ region
- Europe
Offices8 records
Markets served
Brightsight business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales
Revenue model
- Security Evaluations: Brightsight performs IT security evaluations of ICT products as an accredited IT Security Evaluation Facility (ITSEF), providing compliance assessments against standards such as Common Criteria, EUCC, SESIP, FIDO, PCI PTS, EMVCo, RED, and ISA/IEC 62443. These evaluations are billed as professional services, typically on a per-project basis.
- Certification Body Services: Brightsight operates as a licensed Certification Body (CB) under schemes including EUCC, PSA Certified, and SESIP, issuing certificates for compliant products. Revenue is generated through certification review and issuance fees, integrated with the ITSEF evaluation services.
- Professional Advisory & Training: Brightsight offers pre-evaluation services, document creation support, Security Target writing, developer support, and tailored training programs for various certification schemes. These advisory services are offered as standalone consulting engagements.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels7 records
Brightsight product offering
Product offeringCore offering
Brightsight provides accredited cybersecurity evaluation and certification services for ICT products as an IT Security Evaluation Facility (ITSEF) and licensed Certification Body (CB). The company performs independent security assessments under schemes including Common Criteria (ISO/IEC 15408:2022), EUCC, SESIP, FIDO, PCI PTS, EMVCo, RED, ISA/IEC 62443, and FIPS 140-3, supported by 55+ specialized laboratory setups for side channel, perturbation, reverse engineering, and vulnerability analyses.
Product overview
Brightsight is a leading global cybersecurity evaluation laboratory and certification body offering integrated evaluation and certification services under one roof. The portfolio centers on security evaluations (Common Criteria, EUCC, SESIP, PCI, RED, FIDO, EMVCo, FIPS, IEC 62443) and certification body services, supplemented by professional advisory, training, and pre/post-evaluation support. The company serves IoT/Consumer, Automotive, MedTech, Industrial, Government ID, Payment, Telecommunication, Network, Space, and Integrated Circuit sectors across 11 global locations.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Evaluations
- Certification Body Services
- Professional Advisory
- Training Services
- Common Criteria Evaluations
- EUCC Certification
- SESIP Certification
- PCI Security Evaluations
- RED Certification
- ISA/IEC 62443 Evaluation
- FIDO Certification
- EMVCo Security Evaluations
- FIPS 140-3 Evaluations
- BSI Certification Services
- OCP S.A.F.E. Security Reviews
- PSA Certified Certification
Quantifiable outcome
- 700+ security evaluations completed per year
- +6 more outcomes
Companies that use Brightsight
Customer profileNamed customers12 records
Segments6 records
Ideal customer profiles6 records
Brightsight technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Brightsight partnerships and signals
Strategic signalPartnerships
16 partnerships are on record, tiered core, major and notable.
- Open Compute Project (OCP)coreBrightsight participated in the OCP EMEA Pre-Summit Cybersecurity Workshop (28 April 2026, Barcelona) exploring how OCP S.A.F.E. security reviews can contribute to EU Cyber Resilience Act (CRA) compliance. Brightsight serves as an OCP S.A.F.E. Security Review Provider (SRP) and accredited CRA Notified Body.
- Infineon TechnologiesmajorBrightsight evaluated Infineon's SECORA ID V2 platform in partnership with Eviden's cryptovision ePasslet Suite, achieving the world's first commercial FIDO2 Authenticator Level 3+ certification. Brightsight also conducted Common Criteria training for Infineon development teams.
- Eviden (cryptovision)majorBrightsight evaluated Eviden's cryptovision ePasslet Suite FIDO2 application running on Infineon's SECORA ID V2 platform, achieving the highest FIDO2 Level 3+ certification — the first commercial product to reach this level globally.
- Owlet Baby CarenotableBrightsight performed cybersecurity testing for Owlet's Dream Sight baby monitor, enabling it to earn the first SGS Cybersecurity Mark for a baby monitor, under the EU Radio Equipment Directive. Brightsight testing preceded SGS-mark issuance by SGS.
- STMicroelectronicsmajorBrightsight CB issued its first SESIP certificate to STMicroelectronics for the STM32MP13xx microprocessor product line at SESIP Level 3, confirming the microprocessor meets stringent security requirements for IoT platforms. Certificate maintained for continued market access.
- NXP SemiconductorsmajorBrightsight completed the first EUCC 'High' evaluation using NXP's SN300 secure element, resulting in the first EUCC certification from the Netherlands, the first EUCC certificate under CC:2022 release, and the first eUICC certified under the EUCC scheme. Certificate issued by TrustCB under Dutch NCCA.
- Penumbra SecuritynotableBrightsight partnered with Penumbra Security to expand its service portfolio with FIPS 140-3 conformance testing services, strengthening Brightsight's expansion within the USA market for cryptographic module conformance testing.
- SGS Group (Société Générale de Surveillance SA)coreBrightsight joined the SGS Group — the world's leading testing, inspection, and certification company — in 2021. The acquisition strengthened Brightsight's global Digital Trust portfolio, providing access to SGS's worldwide network, resources, and cross-selling opportunities across TIC (Testing, Inspection, Certification) services.
- GlobalPlatformcoreBrightsight is a founding member of SESIP (Security Evaluation Standard for IoT Platforms), developed by GlobalPlatform. SESIP provides an optimized version of Common Criteria methodology for IoT platforms. Brightsight actively contributes to GlobalPlatform's standards development and SESIP community.
- EurosmartcoreBrightsight has been elected as a board member of Eurosmart, representing the TIC community. Carlos Serratos, Senior Director Strategy, Policy and Advocacy, serves in a representative role. Brightsight contributes to technical and expert groups in high-end security domain and brings expertise in emerging IoT markets.
- Samsung Electronics Semiconductor (System LSI)majorBrightsight conducted the industry's first Common Criteria EAL5+ evaluation of a secure IC implementing a Post-Quantum Cryptography (PQC) algorithm for Samsung. Samsung was the first in the industry to receive CC certification for PQC implementation.
- ENISA (European Union Agency for Cybersecurity)coreBrightsight supports ENISA in strengthening the EUCC and other EU cybersecurity developments. ENISA drives EUCC guidance and maintains the central website with scheme documents, protection profiles, and certificates. Brightsight participates in EUCC ISAC working groups.
- Dutch National Accreditation Council (RvA)coreRvA accredited Brightsight as an EUCC ITSEF laboratory (April 2025), and accredited Brightsight CB for EUCC certification (November 2025). All five European Brightsight labs hold RvA-accredited EUCC ITSEF status at assurance level HIGH.
- Dutch Authority for Digital Infrastructure (RDI / Dutch NCCA)coreRDI licensed Brightsight as an EUCC ITSEF (May 2025) and licensed Brightsight CB as EUCC Certification Body (December 2025). RDI acts as National Cybersecurity Certification Authority (NCCA) monitoring CAB compliance with quality standards.
- Dutch NCCA (RDI) and French ANSSInotableGermany's BSI and France's ANSSI mutually recognize CSPN and BSZ certificates with possible exemptions. Brightsight operates under German BSI and French ANSSI accreditation frameworks alongside Dutch RDI, enabling cross-border EUCC certifications.
- FIDO AlliancecoreBrightsight is an accredited FIDO security laboratory authorized to conduct FIDO2 Authenticator certification evaluations. Brightsight conducted the world's first commercial FIDO2 Level 3+ evaluation, demonstrating expertise in phishing-resistant passwordless authentication standards.
Scale indicators9 records
Recent moves9 records
Expansion highlights5 records
Brightsight competitors and assessment
Company assessmentBroad incumbents
- TÜV Rheinland: Global TIC conglomerate with accredited Common Criteria testing labs in multiple jurisdictions, providing security evaluations for IT products, industrial systems, and payment terminals as part of its broader certification portfolio.
- UL Solutions: Large TIC firm with cybersecurity testing and evaluation services including Common Criteria, payment security, and IoT certification, competing with Brightsight across multiple scheme families through its global lab network.
- Bureau Veritas: Global TIC conglomerate with cybersecurity and product certification services across multiple industries including IoT, automotive, and industrial, competing for similar enterprise customers in regulated markets.
- TÜV SÜD: International TIC provider with Common Criteria and cybersecurity evaluation capabilities across automotive, IoT, and industrial sectors, serving overlapping customer base in semiconductor and connected device markets.
- DEKRA: Global TIC company offering cybersecurity evaluation and certification services for connected products, automotive security, and industrial systems, with growing Common Criteria lab presence in Europe.
Direct peers
- FIME: Specialized testing laboratory focused on payment, smartcard, and mobile transaction security with EMVCo, PCI, and Common Criteria accreditations, directly overlapping with Brightsight in payment and identity certification services.
- jtsec Beyond IT Security: Spanish cybersecurity evaluation lab accredited under CCN/LINCE schemes and active in Common Criteria, publishing the Global CC Statistics report that ranks Brightsight as #1. Direct competitor in EU smartcard and IT product evaluations.
- Riscure: Riscure is a specialized security evaluation lab focused on side-channel analysis, fault injection, and embedded device testing, serving semiconductor and mobile payment customers with overlapping CC, EMVCo, and FIDO services.
- Thales (Thales Cybersecurity & Digital Identity): Thales operates one of the largest accredited Common Criteria ITSEFs in Europe, providing security evaluations for smartcards, secure elements, and HSMs - directly competing with Brightsight in the semiconductor and payment certification space.
- TrustCB: Independent Certification Body operating under EUCC framework, issuing certificates for products evaluated by various ITSEFs including Brightsight's evaluations. Closely intertwined as a counterpart/competitor in the EUCC certification ecosystem.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Brightsight social profiles
Digital presenceBrightsight compliance and trust
Trust signalCompliance20 records
Brightsight financial estimates
Financial estimateRevenue estimate
Valuation estimate
Brightsight leadership team
Management profileNumber of profiles
Profiles9 records
Brightsight subsidiaries and ownership
Company hierarchySubsidiaries8 records
Brightsight funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Brightsight M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Brightsight
What does Brightsight do?
Brightsight provides accredited cybersecurity evaluation and certification services for ICT products as an IT Security Evaluation Facility (ITSEF) and licensed Certification Body (CB). The company performs independent security assessments under schemes including Common Criteria (ISO/IEC 15408:2022), EUCC, SESIP, FIDO, PCI PTS, EMVCo, RED, ISA/IEC 62443, and FIPS 140-3, supported by 55+ specialized laboratory setups for side channel, perturbation, reverse engineering, and vulnerability analyses.
Is Brightsight a public or private company?
Brightsight is a private company. It is classified as corporate owned and is currently operating.
When was Brightsight founded?
Brightsight was founded in 1982. It employs 101 to 250 people.
Where is Brightsight based?
Brightsight is headquartered in Delft, Netherlands, in the Europe region.
How does Brightsight make money?
Three revenue lines are on record. Security Evaluations are the primary driver. The others are certification Body Services and professional Advisory & Training.
Who are Brightsight's main competitors?
Broad incumbents on record are TÜV Rheinland, UL Solutions, Bureau Veritas, TÜV SÜD and DEKRA. Direct peers are FIME, jtsec Beyond IT Security, Riscure, Thales (Thales Cybersecurity & Digital Identity) and TrustCB.
Does Brightsight have an API?
No public API is recorded for Brightsight.
What industry is Brightsight in?
Brightsight's product category is Cybersecurity Evaluation and Certification Services. Its primary akta.pro industry code is BPAKADAO, Security Maturity Assessments & Benchmarking. Its NAICS code is 541519 and its SIC code is 8900.