TUViT
TÜV Informationstechnik GmbH (TÜVIT) is an independent German IT security testing and certification institute, part of TÜV NORD GROUP, serving critical infrastructure operators, cloud providers, industrial firms, and financial institutions with ISO/BSI/IEC certifications, penetration testing, and managed security assessments across 50+ countries.
- Company typePrivate
- Founded1995
- HeadquartersEssen, Germany
- Headcount51–100
- GTM typeB2B
- OfferingServices
What TUViT does
TÜV Informationstechnik GmbH (TÜVIT), founded in 1995 and headquartered in Essen, Germany, is an independent IT security testing institute and certification body operating as part of the Business Unit Digital & Semiconductor within TÜV NORD GROUP. The company evaluates and certifies IT products, systems, processes, and infrastructures across six service categories: business processes and information security management (ISMS/BCM), data protection, application security testing, technology and component testing (cloud, secure chips, HSMs, post-quantum cryptography, IoT), standards-based certification (ISO 27001, IEC 62443, BSI C5, Common Criteria), and auditing/evaluation including a 450m² First Choice Lab with QKD capability. It serves critical infrastructure operators (KRITIS) as its primary segment, with additional verticals in cloud services, industrial automation/OT, digital health (DiGA/DiPA), and financial institutions.
The company's technical foundation rests on a DAkkS-accredited laboratory under ISO/IEC 17025:2018, BSI certification as an IT security service provider, ITSEF authorization for EUCC certification, and recognition across multiple BSI Technical Guidelines. It maintains proprietary methodologies including the Code Score Matrix for code evaluation and a QKD laboratory for quantum key distribution testing. A 180-person expert team delivers penetration testing, red team assessments, digital forensics and incident response (DFIR), and advisory services across the full security lifecycle from prevention through response.
TÜVIT monetizes through professional services engagements with quote-based pricing tied to scope, organization size, and audit days. Revenue streams include certification services (ISO 27001, ISO 27017, ISO 22301, IEC 62443, EUCC, BSI certifications), penetration testing and security evaluation, consulting (secure software development, DFIR, compromise assessment), and training via the TÜV NORD Akademie. Customer projects span more than 50 countries, distributed through direct enterprise sales, the TÜV NORD GROUP network, and industry associations including Allianz für Cybersicherheit, TeleTrusT, bitkom, and BDSV.
TUViT firmographics
Firmographics- Name
- TUViT
- Legal name
- TÜV Informationstechnik GmbH
- Website
- https://tuvit.de
- Company type
- Private
- Founded year
- 1995
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- TÜV Informationstechnik GmbH (TÜVIT) is an independent German IT security testing and certification institute, part of TÜV NORD GROUP, serving critical infrastructure operators, cloud providers, industrial firms, and financial institutions with ISO/BSI/IEC certifications, penetration testing, and managed security assessments across 50+ countries.
- Ownership category
- akta.pro rank
TUViT industry classification
Industry- Product category
- IT Security Certification & Testing Services
- NAICS
- Testing Laboratories and Services (54138), Testing Laboratories and Services (541380)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Integrated Management System Certification (Food Safety + Quality/Environment/OHS) (AFALACAI)
Keywords
Where TUViT is headquartered
LocationHeadquarters
- HQ city
- Essen
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
TUViT business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Certification Services: Fees from certification and audit services including ISO 27001, ISO 27017, ISO 22301, IEC 62443, BSI certifications, EUCC certification, and related compliance assessments.
- Penetration Testing & Security Evaluation: Revenue from penetration testing, red team assessments, application security testing (mobile app, web), and security evaluations of hardware and software components.
- Consulting Services: Advisory services including secure software development, compromise assessment, digital forensics & incident response (DFIR), and post-breach assessment.
- Training & Seminars: Revenue from training programs and seminars including NIS-2 executive training, FIT FOR IEC 62443 webinars, and TÜV NORD Academy offerings on IT security.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | ISO 27001 Certification – quote-based pricing dependent on company size, number of sites, process complexity, and number of audit days required. |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels8 records
TUViT product offering
Product offeringCore offering
TÜViT (TÜV Informationstechnik GmbH) is an independent IT security testing institute and certification body providing accredited testing, certification, auditing, and consulting services for IT products, systems, and processes. The company delivers ISO 27001, ISO 27017, ISO 22301, IEC 62443, IT-Grundschutz, BSI C5, EUCC, and Common Criteria certifications, along with penetration testing, red team assessments, and digital forensics & incident response, primarily to enterprise, government, and critical infrastructure clients across more than 50 countries.
Product overview
TÜVIT (TÜV Informationstechnik) is an independent IT security testing institute and IT services provider within the TÜV NORD GROUP, operating since 1995. The company offers a comprehensive portfolio of security testing, auditing, certification, and consulting services organized into six main service categories: (1) Business Processes covering ISMS (ISO 27001), Business Continuity Management (ISO 22301), and Physical Security; (2) Data & Data Protection including GDPR-compliant privacy management systems and audits; (3) Applications Security Testing for mobile apps, web apps, digital health (DiGA/DiPA), and video consultations; (4) Technology & Components testing for cloud services, secure chips, HSMs, post-quantum cryptography, IoT, and hardware; (5) Norms, Standards & Guidelines certification for ISO 27001/27017/27018/27701, IEC 62443, IT-Grundschutz, BSI C5, and various BSI Technical Guidelines; and (6) Auditing & Evaluation including penetration testing, red team assessments, and their 450m² First Choice Lab facility. Additional specialized offerings include AI Safety services (KI-Sicherheit), the CyberRisikoCheck tool for NIS-2 compliance, and EUCC certification services. The company serves critical infrastructure sectors including healthcare, energy, defense, and waste management.
Differentiator
Problem solved
Functional benefit
Brands
- ALTER: Core brand of the BU Digital & Semiconductor focused on high-tech and IT components in complex, integrated systems alongside TÜVIT.
Products and services
- ISO 27001 Information Security Certification Certification of an organization's information security management system (ISMS) against ISO/IEC 27001. Includes readiness assessment, audit, and certification issuance. Quote-based pricing dependent on company size, number of sites, process complexity, and required audit days.
- IEC 62443 Industrial Security Certification Certification of industrial automation and control systems (IACS) security per IEC 62443, targeting operators, integrators, and manufacturers. Covers defense-in-depth security approaches for OT/Industry 4.0 environments.
- ISO 27017 Cloud Security Certification Certification of cloud-specific information security controls per ISO 27017, applicable to both cloud service providers and cloud service customers.
- ISO 22301 Business Continuity Certification Certification of business continuity management systems (BCMS) per ISO 22301, enabling organizations to demonstrate the ability to maintain critical functions during disruptions.
- IT-Grundschutz Certification BSI IT-Grundschutz certification including ISO 27001 audit on the basis of IT-Grundschutz, delivered through TÜViT's licensed BSI auditors.
- BSI C5 Cloud Computing Compliance Certification Certification of cloud services against the BSI C5 (Cloud Computing Compliance Criteria Catalogue), demonstrating compliance with German BSI cloud security requirements.
- EUCC / Common Criteria Certification Security evaluation and certification of IT products under the EUCC (EU Common Criteria cybersecurity certification) scheme, delivered through TÜViT's authorized ITSEF status.
- BSI TR-03174 Financial Application Testing Security testing and certification of financial applications according to BSI Technical Guideline TR-03174, delivered through TÜViT's recognized testing facility status for banks, financial service providers, and fintechs.
- Penetration Testing Services Authorised penetration testing of IT components and applications, including mobile app pentests, web pentests, and red team assessments, delivered as part of TÜViT's BSI-certified IT security service provider capability.
- Red Team Assessments Adversary simulation engagements that emulate real-world threat actors to test organizational detection, response, and resilience capabilities.
- DiGA Certification (Digital Health Applications) Certification of digital health applications (Digitale Gesundheitsanwendungen) for entry into the German DiGA directory, including security and data protection assessment.
- DiPA Certification (Digital Care Applications) Certification of digital care applications (Digitale Pflegeanwendungen) for the German healthcare and care market, including security and data protection assessment.
- ISMS Implementation Consulting Advisory and implementation services to establish and operate an Information Security Management System (ISMS) aligned with ISO 27001, IT-Grundschutz, and related standards.
- Business Continuity Management (BCM) Consulting Consulting and certification services for Business Continuity Management Systems aligned with ISO 22301, helping organizations maintain critical functions during disruptions.
- Digital Forensics & Incident Response (DFIR) Digital forensics and incident response services to investigate cybersecurity incidents, preserve evidence, contain threats, and restore business operations.
- Compromise Assessment & Post-Breach Assessment Compromise assessment and post-breach assessment services to detect existing attacker presence, determine scope of compromise, and support remediation.
- Secure Software Development Consulting Advisory services to embed security into the software development lifecycle (SDLC), including threat modelling, secure coding guidance, and DevSecOps support.
- QKD Laboratory Security Evaluation Security testing and evaluation using Quantum Key Distribution (QKD) technology within TÜViT's dedicated QKD laboratory.
- Code Score Matrix Proprietary methodology for evaluating and scoring source code and software security quality as part of TÜViT's auditing and evaluation portfolio.
- Cloud Services Security Testing Security testing and certification of cloud services and components, building on ISO 27001 and aligned with ISO 27017, ISO 27018, ISO 27701, and BSI C5.
- Post-Quantum Cryptography Evaluation Security assessment and evaluation of post-quantum cryptography implementations and quantum-resistant encryption technologies.
- AI Safety Services (KI-Sicherheit) Comprehensive AI safety services including AI performance evaluation, hallucination detection and certification, and EU AI Act risk assessment delivered jointly with d-fine under a new AI testing organization within TÜV NORD GROUP.
- CyberRisikoCheck (CRC) Structured methodology for assessing an organization's information security posture, tailored to SMEs and municipalities and designed as a first step toward NIS-2 compliance.
Quantifiable outcome
- 30 years of experience in IT security since founding in 1995
- +2 more outcomes
Companies that use TUViT
Customer profileNamed customers1 record
Segments5 records
Ideal customer profiles5 records
TUViT technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
TUViT partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- d-finecoreTÜVIT (TÜV NORD GROUP) and d-fine established a new AI testing organization to provide joint AI security assessment and evaluation services. This partnership combines TÜVIT's testing and certification expertise with d-fine's AI consulting capabilities.
- ALTER TechnologycoreALTER and TÜVIT are the two core brands of the Business Unit Digital & Semiconductor within TÜV NORD GROUP. Together they provide technology know-how for the digital innovation-driven world, focusing on high-tech and IT components in complex integrated systems.
Scale indicators5 records
Recent moves7 records
Expansion highlights6 records
TUViT competitors and assessment
Company assessmentBroad incumbents
- SGS: Swiss-based global TIC giant offering ISO 27001 certification, cybersecurity assessments, and IoT security testing as part of its broader certification portfolio. Competes with TÜVIT in enterprise certification work but lacks the same specialized IT-security / Common Criteria focus.
- Bureau Veritas: French global TIC major with a growing cybersecurity and digital trust practice offering ISO 27001 audits and IoT security certification. Overlaps with TÜVIT in standards certification but with a much broader industrial testing legacy.
- Intertek: UK-headquartered global TIC group with cybersecurity assurance and IoT security testing. Comparable to TÜVIT's technology & components testing and certification portfolio, though IT security is a smaller piece of Intertek's broader industrial/services mix.
- Deloitte (Cyber Risk Services): Big Four advisory firm with a large cybersecurity practice offering ISO 27001 certification, penetration testing, red teaming, and managed security across Europe. Competes with TÜVIT for enterprise security testing and certification mandates.
Direct peers
- NCC Group: UK-based specialist cybersecurity testing firm providing Common Criteria evaluation, penetration testing, and red team services across Europe. Closest pure-play functional peer to TÜVIT's auditing & evaluation practice with similar ITSEF-equivalent capabilities.
- Bishop Fox: US-based elite cybersecurity testing firm specializing in penetration testing, red teaming, and product/hardware security assessments. Comparable to TÜVIT's First Choice Lab and penetration testing practice, particularly for technology & components customers.
- TÜV Rheinland: TÜV Rheinland's Digital Transformation and Cybersecurity service line offers ISO 27001 certification, IoT/industrial security testing, Common Criteria, and pen testing under the same TÜV brand family. Direct sibling competitor to TÜVIT with overlapping accreditations and customer segments.
- TÜV SÜD: German TÜV conglomerate offering IT security testing, ISMS certification (ISO 27001), penetration testing, and Common Criteria evaluations. TÜV SÜD operates the same TÜV-branded certification and cybersecurity service portfolio as TÜVIT, targeting the same German/European enterprise and critical infrastructure customers.
- DEKRA: DEKRA's Cybersecurity and Digital Services division provides ISO 27001, TISAX, IEC 62443, Common Criteria, and penetration testing across Germany and globally. Comparable as a German TIC competitor with overlapping industrial cybersecurity certifications.
Regional players
- secunet Security Networks AG: German high-security IT specialist focused on SINA products, border control, and critical infrastructure cybersecurity, also offering security evaluation and consulting. Adjacent to TÜVIT's KRITIS/BSI-trusted security service provider role with deep German public-sector ties.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
TUViT social profiles
Digital presenceTUViT compliance and trust
Trust signalCompliance17 records
TUViT financial estimates
Financial estimateRevenue estimate
Valuation estimate
TUViT leadership team
Management profileNumber of profiles
Profiles9 records
TUViT funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
TUViT M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about TUViT
What does TUViT do?
TÜViT (TÜV Informationstechnik GmbH) is an independent IT security testing institute and certification body providing accredited testing, certification, auditing, and consulting services for IT products, systems, and processes. The company delivers ISO 27001, ISO 27017, ISO 22301, IEC 62443, IT-Grundschutz, BSI C5, EUCC, and Common Criteria certifications, along with penetration testing, red team assessments, and digital forensics & incident response, primarily to enterprise, government, and critical infrastructure clients across more than 50 countries.
Is TUViT a public or private company?
TUViT is a private company. It is classified as corporate owned and is currently operating.
When was TUViT founded?
TUViT was founded in 1995. It employs 51 to 100 people.
Where is TUViT based?
TUViT is headquartered in Essen, Germany, in the Europe region.
How does TUViT make money?
Four revenue lines are on record. Certification Services are the primary driver. The others are penetration Testing & Security Evaluation, consulting Services and training & Seminars.
Who are TUViT's main competitors?
Broad incumbents on record are SGS, Bureau Veritas, Intertek and Deloitte (Cyber Risk Services). Direct peers are NCC Group, Bishop Fox, TÜV Rheinland, TÜV SÜD and DEKRA. secunet Security Networks AG is listed as a regional player.
Does TUViT have an API?
No public API is recorded for TUViT.
What industry is TUViT in?
TUViT's product category is IT Security Certification & Testing Services. Its primary akta.pro industry code is AFALACAI, Integrated Management System Certification (Food Safety + Quality/Environment/OHS). Its NAICS code is 54138 and its SIC code is 8734.