atsec information security
Independent, founder-led accredited laboratory (founded 2000, Austin, TX) providing cryptographic, Common Criteria, PCI, NESAS, and IoT/medical security testing and certification services to global IT, payment, telecom, and automotive vendors.
- Company typePrivate
- Founded2000
- HeadquartersAustin, United States
- Headcount51–100
- GTM typeB2B
- OfferingServices
What atsec information security does
atsec information security is an independent, privately-owned accredited laboratory founded in 2000 and headquartered in Austin, Texas, with regional offices in Munich, Rome, Stockholm, and Beijing. The company provides information security testing, evaluation, validation, and training services to vendors of commercial hardware, software, and firmware that must demonstrate compliance with international security standards. Named customers and case studies include Intel, Qualcomm, Apple, Red Hat, SUSE, Canonical, and TSMC, spanning semiconductors, operating systems, and consumer electronics.
Core service lines span six domains: IT Product Evaluation and Assessment (Common Criteria/ISO 15408, SCAP, IEEE 2621 for medical devices, O-TTPS, SESIP for IoT); Cryptographic Testing (FIPS 140-3, CAVP, Entropy Source Validation); Telecommunications (GSMA NESAS audits, BSI NESAS, MDSCert); Identity (NPIVP/FIPS 201, FIDO); IT Product Certification (Common Criteria certification via atsec Sweden, accredited by SWEDAC under ISO/IEC 17065); and Payment Security (PCI QSA, ASV, Secure Software/Secure SLC, P2PE, 3DS, PIN Security, CPSA, PFI, plus SWIFT CSP and EMVCo SBMP). atsec Sweden is a SWEDAC-accredited certification body, and atsec China holds the broadest set of PCI assessor qualifications. The company has issued over 500 FIPS certificates cumulatively, founded the International Cryptographic Module Conference (ICMC) in 2013, and created the Crypto Module User Forum (CMUF) in 2014 (800+ members).
The business model is professional services: project-based, quote-priced engagements aligned to certification scope and product complexity. The go-to-market is enterprise field sales through direct consulting relationships, standards-body participation, and conference presence (ICMC, AutoCS, ESCAR, PCI Community Meetings). Revenue mix is essentially services-only with a minor training line. The company has been bootstrapped and founder-led since inception, with Sal La Pietra as President and Co-Founder and Dr. Yi Mao as CEO of atsec USA; it has no parent company and no external institutional investors.
atsec information security firmographics
Firmographics- Name
- atsec information security
- Legal name
- atsec information security corporation
- Website
- https://atsec.com
- Company type
- Private
- Founded year
- 2000
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Independent, founder-led accredited laboratory (founded 2000, Austin, TX) providing cryptographic, Common Criteria, PCI, NESAS, and IoT/medical security testing and certification services to global IT, payment, telecom, and automotive vendors.
- Ownership category
- akta.pro rank
Where atsec information security is headquartered
LocationHeadquarters
- HQ city
- Austin
- HQ country
- United States
- HQ region
- North America
Offices5 records
Markets served
atsec information security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Laboratory Testing Services: Fees charged for testing and validating cryptographic modules, IT products, and security implementations against established standards such as FIPS 140-3, Common Criteria, and PCI standards. Revenue is project-based, varying by product complexity and scope of evaluation.
- Certification Body Services: atsec Sweden operates as an accredited private Certification Body according to ISO/IEC 17065, specialized in Common Criteria ISO 15408 and 18045, offering certification schemes in collaboration with 17025 accredited laboratories. SWEDAC accredited.
- Training Services: Educational offerings including FIPS 'n' Chips bootcamps, PCI training workshops, and crypto module practitioner training. Events include both free and potentially fee-based training programs.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels5 records
atsec information security product offering
Product offeringCore offering
atsec information security is an independent, privately-owned laboratory that provides information security testing, evaluation, validation, and certification services. Its portfolio covers FIPS 140-3 cryptographic module validation, Common Criteria (ISO 15408) evaluation, PCI payment security assessments, GSMA NESAS telecommunications audits, medical device (IEEE 2621) and IoT (SESIP) certifications, and FIDO authentication testing, delivered through accredited labs in the US, Europe, and Asia.
Product overview
atsec information security operates as a multi-service laboratory testing and evaluation company, not a unified software product. The portfolio consists of distinct service lines: IT Product Evaluation & Assessment (including Common Criteria, IEEE 2621, O-TTPS, and SESIP); Cryptographic Testing (including FIPS 140-3, Cryptographic Algorithm Testing, and Entropy Source Assessment); Telecommunication security (GSMA NESAS, BSI NESAS, MDSCert); Identity services (NPIVP and FIDO); IT Product Certification (Common Criteria certification via SWEDAC-accredited body); and Payment Security (PCI assessments, SWIFT CSP, EMVCo). These services are delivered through their global offices in Austin, Munich, Rome, Stockholm, and Beijing.
Differentiator
Problem solved
Functional benefit
Products and services
- IT Product Evaluation & Assessment
Quantifiable outcome
- 500+ FIPS certificates issued to date
- +3 more outcomes
Companies that use atsec information security
Customer profileNamed customers7 records
Segments6 records
Ideal customer profiles5 records
atsec information security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
atsec information security partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered key, core, supporting and flagship.
- The University of Texas at Austinkeyatsec co-hosts the FIPS 'n' Chips conference with UT Austin on October 26-27, 2026 in Austin, TX. The event brings together experts from government, industry, academia, and accredited laboratories to discuss cryptographic technologies, validation programs, hardware security, post-quantum cryptography, and applied assurance engineering. atsec has also contributed to UT Austin through scholarship and student support initiatives.
- GSMA and 3GPPcoreatsec provides GSMA NESAS Audits and SCAS Testing as part of the Network Equipment Security Assurance Scheme (NESAS) jointly led by 3GPP and GSMA. These services are available to all vendors of network equipment products supporting 3GPP-defined functions.
- SWEDACcoreatsec Sweden is accredited by Sweden's national accreditation body SWEDAC as a private Certification Body according to ISO/IEC 17065, specialized in Common Criteria ISO 15408 and 18045. The accreditation enables atsec to issue legally recognized Common Criteria certificates.
- Amazon Web ServicessupportingAmazon Web Services provides the cloud platform hosting the Crypto Module User Forum (CMUF) portal, which atsec created in 2014. AWS generosity enables the CMUF resource to be freely available to the forum's 800+ members.
- International Cryptographic Module Conference (ICMC)flagshipatsec is the proud founder of ICMC, having initiated and named the conference in 2013. atsec chairs the conference and remains an exclusive and permanent Platinum Sponsor. The conference brings together vendors, labs, agencies, and academia to advance crypto module validation. While atsec has delegated conference production to an event media partner, the founding relationship remains core to atsec's identity.
Scale indicators4 records
Recent moves11 records
Expansion highlights5 records
atsec information security competitors and assessment
Company assessmentDirect peers
- EWA-Canada: EWA-Canada is an accredited IT security testing laboratory based in Ottawa operating a Common Criteria lab and Cryptographic Module Validation Program (CMVP) services. It directly competes with atsec for FIPS 140-3 and Common Criteria engagements across North America.
- SGS Brightsight: SGS Brightsight (formerly Brightsight) is a European security evaluation laboratory specialized in Common Criteria, EMVCo, payment security, and smart-card/embedded device testing. It is one of atsec's closest competitors in payment and IT security certification work.
- TrustCB: TrustCB is an accredited Common Criteria certification body operating out of the Netherlands. It serves the same vendor customer base as atsec Sweden and competes directly for issuing Common Criteria certificates under the Dutch and EUCC schemes.
- Serma Group: Serma Group is a French-based engineering and IT security evaluation firm running an accredited Common Criteria laboratory and serving payment, telecom, and embedded security customers. It competes with atsec Europe for Common Criteria and payment-related testing engagements.
- Riscure: Riscure is a Netherlands-based security testing lab specializing in side-channel analysis, fault injection, and certification of smart cards, mobile platforms, and IoT devices. It overlaps with atsec's payment and IoT (SESIP) testing practices.
Broad incumbents
- Booz Allen Hamilton: Booz Allen Hamilton operates an accredited Common Criteria evaluation lab inside a much larger US federal cybersecurity services business. It competes for selected federal and commercial certification work that would otherwise be addressed by atsec's US practice.
- Leidos: Leidos Commercial Cybersecurity runs accredited security testing labs (Common Criteria, FIPS) as part of a large US defense and IT services portfolio. It overlaps with atsec on federal-grade cryptography and IT product evaluation.
- UL Solutions: UL Solutions is a large global testing, inspection, and certification (TIC) body that has expanded into cybersecurity and IoT assurance. It competes with atsec in adjacent testing services rather than in pure-play cryptographic evaluation.
- TÜV Rheinland: TÜV Rheinland is a global TIC leader with cybersecurity and Common Criteria evaluation capabilities across Europe and Asia. It overlaps with atsec Europe and atsec China in regulatory-driven security certification.
Emerging players
- Applus+ IDIADA: Applus+ IDIADA is a Spain-based testing and certification services group with growing automotive cybersecurity and functional safety capabilities, increasingly overlapping with atsec's emerging automotive cybersecurity practice.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
atsec information security social profiles
Digital presenceatsec information security compliance and trust
Trust signalCompliance10 records
atsec information security financial estimates
Financial estimateRevenue estimate
Valuation estimate
atsec information security leadership team
Management profileNumber of profiles
Profiles11 records
atsec information security subsidiaries and ownership
Company hierarchySubsidiaries4 records
atsec information security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
atsec information security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about atsec information security
What does atsec information security do?
atsec information security is an independent, privately-owned laboratory that provides information security testing, evaluation, validation, and certification services. Its portfolio covers FIPS 140-3 cryptographic module validation, Common Criteria (ISO 15408) evaluation, PCI payment security assessments, GSMA NESAS telecommunications audits, medical device (IEEE 2621) and IoT (SESIP) certifications, and FIDO authentication testing, delivered through accredited labs in the US, Europe, and Asia.
Is atsec information security a public or private company?
atsec information security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was atsec information security founded?
atsec information security was founded in 2000. It employs 51 to 100 people.
Where is atsec information security based?
atsec information security is headquartered in Austin, United States, in the North America region.
How does atsec information security make money?
Three revenue lines are on record. Laboratory Testing Services are the primary driver. The others are certification Body Services and training Services.
Who are atsec information security's main competitors?
Direct peers on record are EWA-Canada, SGS Brightsight, TrustCB, Serma Group and Riscure. Broad incumbents are Booz Allen Hamilton, Leidos, UL Solutions and TÜV Rheinland. Applus+ IDIADA is listed as an emerging player.
Does atsec information security have an API?
No public API is recorded for atsec information security.