Secarma Ltd
Secarma Ltd is a Manchester-based cybersecurity services firm offering penetration testing, certification, and advisory services — including Cyber Essentials, red teaming, and IoT security — to enterprise and mid-market clients across the UK and EMEA under its proprietary ACT Framework.
- Company typePrivate
- Founded2001
- HeadquartersManchester, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Secarma Ltd does
Secarma Ltd is a UK-based cybersecurity services company founded in 2001 and headquartered in Manchester, operating as a private limited company (Company no. 04217114). The firm delivers professional services organised under three pillars — Advise (consultancy such as vCISO, threat modelling, incident response exercising, third-party risk assessment), Certify (Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, IoT Cyber Scheme, SecureApp, and readiness reviews), and Test (web, mobile, infrastructure, wireless, and cloud penetration testing, red teaming, adversary simulation, vulnerability scanning, and configuration security reviews). It also offers physical security services, the Secarma Engage learning management system for security awareness training, and a Secarma Labs research content hub, all coordinated through the proprietary ACT Framework methodology and a My Secarma client portal.
The technology stack centres on manual expert-led penetration testing combined with industry-standard frameworks (OWASP Top 10, ISO 27001, PCI DSS) and toolchains, rather than proprietary automation. Revenue is generated through project-based professional services engagements, quote-based pricing, annual certification cycles, and subscription-based training delivery, with a partner programme extending channel reach. Customer segments span enterprise, mid-market, and IoT/connected device manufacturers across UK and EMEA, with named clients in financial services, agriculture, and sport. Accreditations held include CREST, NCSC Assured Service Provider, ISO 27001, ISO 9001, IASME Cyber Assurance Partner, and IoT Cyber Scheme Certification Body, which collectively serve as regulatory gating for the addressable market.
Secarma has grown organically over 25 years, supplemented by the 2016 acquisition of Pentest Limited, and appears to be founder/management-owned with no disclosed external funding, parent company, or stock exchange listing. The firm positions itself on brand longevity, accreditations, and manual testing depth rather than on proprietary technology or scale advantages, with a content-driven marketing approach (blog, Secarma Labs, webinars, Cyber Brief newsletter, industry events) supporting demand generation in a trust-led category.
Secarma Ltd firmographics
Firmographics- Name
- Secarma Ltd
- Legal name
- Secarma Limited
- Website
- https://secarma.com
- Company type
- Private
- Founded year
- 2001
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Secarma Ltd is a Manchester-based cybersecurity services firm offering penetration testing, certification, and advisory services — including Cyber Essentials, red teaming, and IoT security — to enterprise and mid-market clients across the UK and EMEA under its proprietary ACT Framework.
- Ownership category
- akta.pro rank
Secarma Ltd industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Investigation, Guard, and Armored Car Services (56161)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF), Cybersecurity Awareness & Digital Safety Training for Security Personnel (BPAKAOAO)
Keywords
Where Secarma Ltd is headquartered
LocationHeadquarters
- HQ city
- Manchester
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Secarma Ltd business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Penetration Testing Services: Professional services revenue from conducting penetration testing across web applications, mobile apps, infrastructure, wireless, and cloud environments. Typically project-based engagements with clear scoping and deliverables.
- Certification Services: Revenue generated from Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, and other certification body services. Guides organisations through certification processes.
- Consultancy Services: Advisory services including vCISO engagements, incident response planning, threat modelling, and security maturity assessments.
- Training Services: Security awareness training and Secarma Engage LMS platform, along with in-person training workshops for Cyber Essentials implementors.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom project-based pricing for penetration testing services |
| One time/ perpetual license | Annual | Cyber Essentials certification |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels6 records
Secarma Ltd product offering
Product offeringCore offering
Secarma delivers cybersecurity services across three pillars: Test (penetration testing across web, mobile, infrastructure, wireless, and cloud environments plus red teaming and vulnerability scanning), Certify (Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, IoT Cyber Scheme, and SecureApp certifications), and Advise (vCISO, incident response, threat modelling, third-party risk assessment, and security maturity assessments). It also offers physical security services and the Secarma Engage learning management system for security awareness training.
Product overview
Secarma Ltd is a cybersecurity services company offering a comprehensive portfolio of penetration testing, advisory/consultancy, and certification services organised under its Advise, Certify, and Test pillars. The core Testing services include multiple penetration testing types (web application, mobile, infrastructure, wireless, cloud, red teaming, vulnerability scanning, and configuration security reviews). The Certify services help organisations achieve standards including Cyber Essentials, Cyber Essentials Plus, IoT Cyber Scheme, IASME Cyber Assurance, and SecureApp certification. The Advise consultancy services provide vCISO, incident response, threat modelling, and risk assessments. Additional offerings include physical security services, the Secarma Engage learning management system, Secarma Labs research resources, and the ACT Framework methodology. The company operates a client portal (My Secarma) for engagement management but does not offer a public API.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing Services Comprehensive penetration testing services covering web applications, mobile apps, infrastructure, wireless, cloud environments, red teaming, vulnerability scanning, and configuration security reviews to identify vulnerabilities before attackers can exploit them.
- Cyber Essentials & Cyber Essentials Plus Certification Certification services to help organisations achieve Cyber Essentials and Cyber Essentials Plus certifications, providing baseline protection against common cyber threats and demonstrating security commitment to customers and supply chains.
- Consultancy Services (Advise) Advisory cybersecurity services including vCISO engagements, security maturity assessments, incident response planning and wargaming, threat modelling, third-party risk assessments, phishing assessments, ISO 27001 gap analysis, and privacy management maturity assessments.
- IASME Cyber Assurance (ICA) Certification Cyber assurance certification based on IASME standards, including GDPR compliance assessment, delivered as an authorised IASME partner.
- IoT Cyber Scheme Certification Certification scheme to validate IoT device security and build consumer trust, including PSTI (Product Security and Telecommunications Infrastructure) compliance for connected products.
- SecureApp Certification Application security certification service to help organisations certify their applications and demonstrate their security commitment to customers and partners.
- Secarma Engage (LMS) Learning Management System platform for security awareness training delivery, enabling organisations to educate employees about cybersecurity risks and best practices on an ongoing subscription basis.
- Security Awareness Training Training services to educate employees about cybersecurity risks and best practices, plus professional security training courses leading to certification under the Secarma Certified programme.
- Physical Security Services Physical security services including surveillance, monitoring and protection, and investigations, offered alongside the firm's cybersecurity services portfolio.
Quantifiable outcome
- 31% of UK businesses skip regular security assessments, leaving web apps open to exploitation (UK Cyber Survey)
- +2 more outcomes
Companies that use Secarma Ltd
Customer profileNamed customers3 records
Segments3 records
Ideal customer profiles3 records
Secarma Ltd technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Secarma Ltd partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- CRESTcoreCREST accreditation provides Secarma with recognised quality standards for penetration testing services, enhancing credibility and market positioning in the UK cybersecurity testing market.
- NCSCcoreNCSC Assured Service Provider status demonstrates government-backed validation of Secarma's cybersecurity testing and certification capabilities.
- IASMEcorePartnership as certification body for IASME Cyber Assurance and IoT Cyber Scheme, allowing Secarma to deliver accredited certification services to clients.
Scale indicators2 records
Recent moves4 records
Expansion highlights5 records
Secarma Ltd competitors and assessment
Company assessmentDirect peers
- NCC Group: UK-listed cybersecurity services firm with a large assurance/testing division offering penetration testing, red teaming, and certification services to enterprise and government clients. Directly comparable to Secarma across the same UK customer base, accreditation stack (CREST, NCSC), and service portfolio.
- Pen Test Partners: UK-based penetration testing specialist offering web, mobile, infrastructure, cloud and IoT testing plus red teaming. Closely matches Secarma's core Test pillar and UK mid-market/enterprise positioning.
- MDSec: UK penetration testing and red team boutique known for research-led testing and tooling. Overlaps directly with Secarma's manual, expert-led testing approach and UK enterprise customer base.
- Cyberis: UK-based cybersecurity consultancy and penetration testing provider serving enterprise and public sector. Comparable in service mix (testing, advisory, certification support) and CREST accreditation.
- Bridewell (formerly Redscan): UK cybersecurity services firm providing penetration testing, managed detection, and advisory. Comparable to Secarma as a UK-headquartered, mid-sized multi-service cybersecurity provider with CREST and NCSC credentials.
- WithSecure (formerly F-Secure): European cybersecurity vendor offering consulting, penetration testing and managed services. Comparable to Secarma on testing and advisory services but with broader international reach and product portfolio.
Regional players
- Bishop Fox: US-based offensive security specialist focused on penetration testing, red teaming and attack surface management. Comparable in service depth and methodology, but primarily serves North American enterprises rather than competing directly in the UK market.
- NetSPI: US-based penetration testing and attack surface management provider serving large enterprises. Overlaps with Secarma's Test pillar but competes mainly in North America.
Broad incumbents
- Trustwave: Global cybersecurity services and MDR provider offering penetration testing alongside a wider managed security and consulting portfolio. Comparable testing capability but much broader scope and larger scale than Secarma.
- Mandiant (Google Cloud): Global incident response, threat intelligence and red team/penetration testing provider. Overlaps with Secarma's red teaming and incident response services but operates at significantly greater scale and geographic breadth.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Secarma Ltd social profiles
Digital presenceSecarma Ltd compliance and trust
Trust signalCompliance8 records
Secarma Ltd financial estimates
Financial estimateRevenue estimate
Valuation estimate
Secarma Ltd leadership team
Management profileNumber of profiles
Profiles3 records
Secarma Ltd funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Secarma Ltd M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Secarma Ltd
What does Secarma Ltd do?
Secarma delivers cybersecurity services across three pillars: Test (penetration testing across web, mobile, infrastructure, wireless, and cloud environments plus red teaming and vulnerability scanning), Certify (Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, IoT Cyber Scheme, and SecureApp certifications), and Advise (vCISO, incident response, threat modelling, third-party risk assessment, and security maturity assessments). It also offers physical security services and the Secarma Engage learning management system for security awareness training.
Is Secarma Ltd a public or private company?
Secarma Ltd is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Secarma Ltd founded?
Secarma Ltd was founded in 2001. It employs 11 to 50 people.
Where is Secarma Ltd based?
Secarma Ltd is headquartered in Manchester, United Kingdom, in the Europe region.
How does Secarma Ltd make money?
Four revenue lines are on record. Penetration Testing Services are the primary driver. The others are certification Services, consultancy Services and training Services.
Who are Secarma Ltd's main competitors?
Direct peers on record are NCC Group, Pen Test Partners, MDSec, Cyberis, Bridewell (formerly Redscan) and WithSecure (formerly F-Secure). Regional players are Bishop Fox and NetSPI. Broad incumbents are Trustwave and Mandiant (Google Cloud).
Does Secarma Ltd have an API?
No public API is recorded for Secarma Ltd.
What industry is Secarma Ltd in?
Secarma Ltd's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 56161 and its SIC code is 7381.