SIZ
SIZ GmbH is a Bonn-based IT services company founded in 1990 that delivers information security, compliance, data protection, payments (EBICS/ISO 20022), and internal-audit services as the central Methodengeber for the German Sparkassen-Finanzgruppe's 350+ savings banks.
- Company typePrivate
- Founded1990
- HeadquartersBonn, Germany
- Headcount101–250
- GTM typeB2B
- OfferingServices
What SIZ does
SIZ GmbH is a Bonn-based, privately held IT services company (GmbH) founded in 1990 that operates as the central service provider and Methodengeber for information security, compliance, data protection, payments, and internal audit across the German Sparkassen-Finanzgruppe. It is owned by the Sparkassen organisations themselves — regional Sparkassenverbände, Landesbanken, DekaBank, and individual Sparkassen — and holds a wholly owned subsidiary, SIZ Service GmbH, which markets telecommunications and card-damage services to the group. SIZ's portfolio spans seven thematic areas: Information Security (Sicherer IT-Betrieb ISO 27001 certification, Sichere IT-Plattform audits, BCM/IT-Notfall planning), S-CERT cybersecurity operations (including PPZV phishing prevention and SAFE Operations), Payments (the TRAVIC EBICS-based family — TRAVIC-EBICS-API, TRAVIC-Corporate, TRAVIC-Interbank, TRAVIC-Link, TRAVIC-Port, TRAVIC-Retail — plus SWIFT Assessments and ISO 20022 / FinTS / EBICS standards work), IT Steering (IDV-Suite, IKS-Miner), Data Protection (Sicherer Datenschutz, RiMaGo content support), Compliance (SIZ Compliance-Suite for AML and WpHG-MaRisk), and Revision services.
Underlying technology includes S/MIME encrypted email infrastructure, EBICS and ISO 20022-based payment processing, ISO 27001-aligned ISMS methodology, automated threat monitoring via S-CERT, and proprietary workflow and risk tools. SIZ monetises through consulting and advisory mandates, certification audits, recurring S-CERT subscriptions, and paid training events; pricing is predominantly quote-based for services, with publicly disclosed fees for the annual SIZ Forums and Online-Fachtagungen. Go-to-market is direct enterprise sales via six regional offices (Bonn, Mainz, Halle, Kiel, Munich, Wuppertal) plus a central customer manager, complemented by the SIZ Support Portal and industry forums that drive thought leadership and regulatory updates within the Sparkassen ecosystem.
The company reports approximately €45 million in revenue for 2023 (Zahlen und Fakten page), 400-450+ employees as of 2025, and has been led since 2014 by Managing Director Jens Bartelt, joined in January 2025 by Ingo Kühling as a second Managing Director, with Roman Frank (Sparkassenverband Rheinland-Pfalz) chairing the Aufsichtsrat. SIZ also participates in the German National CERT-Verbund (co-founded 2002) and serves as SPOC between BSI and the Sparkassen-Finanzgruppe.
SIZ firmographics
Firmographics- Name
- SIZ
- Legal name
- SIZ GmbH
- Website
- https://siz.de
- Company type
- Private
- Founded year
- 1990
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- SIZ GmbH is a Bonn-based IT services company founded in 1990 that delivers information security, compliance, data protection, payments (EBICS/ISO 20022), and internal-audit services as the central Methodengeber for the German Sparkassen-Finanzgruppe's 350+ savings banks.
- Ownership category
- akta.pro rank
SIZ industry classification
Industry- Product category
- Banking IT Compliance Services
- NAICS
- Other Computer Related Services (541519), Computer Systems Design and Related Services (54151)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Computer Programming Services (7371)
- akta.pro primary industry
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK)
- akta.pro secondary industries
- ESG, Sustainability Reporting & Compliance (BPAEAPAM), SIEM Platforms & Log Management (HDADAGAA)
Keywords
Where SIZ is headquartered
LocationHeadquarters
- HQ city
- Bonn
- HQ country
- Germany
- HQ region
- Europe
Offices6 records
Markets served
SIZ business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Consulting and Advisory Services: Professional consulting services for information security, compliance, data protection, anti-money laundering, and fraud prevention. Includes outsourcing of beauftragten functions (compliance officers, data protection officers, money laundering officers).
- Certification Services: ISMS certification services based on the 'Sicherer IT-Betrieb' standard, audits, and compliance assessments.
- S-CERT Security Services: Security monitoring, vulnerability assessments, incident response coordination, and phishing prevention services including SAFE Operations.
- Training and Events: Online Fachstagungen, Forums (Datenschutz360°, Informationssicherheit360°, Banking/Karte/Payment), webinars, and workshops on compliance and security topics.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Annual | SIZ Forum Informationssicherheit360° - Two-day professional forum |
| One time/ perpetual license | Annual | SIZ Forum Banking, Karte und Payment - Two-day professional forum |
| One time/ perpetual license | Annual | SIZ Online-Fachtagungen 2026 - Four days of webstream seminars |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
SIZ product offering
Product offeringCore offering
SIZ GmbH provides information security, data protection, compliance, cybersecurity (S-CERT), and payment processing services and software tools to the German Sparkassen-Finanzgruppe (savings banks financial group). The company delivers outsourced compliance officer functions, ISO 27001-based ISMS certification, EBICS-based electronic banking solutions (TRAVIC family), anti-money laundering and fraud prevention support, and business continuity management consulting.
Product overview
SIZ GmbH operates as a multi-product, service-oriented company serving the Sparkassen-Finanzgruppe with a portfolio of interrelated products and services. The core offerings span seven thematic areas: Information Security (with Sicherer IT-Betrieb certification, Sichere IT-Plattform audits, and BCM/IT-Notfall planning), IT Steering (IDV-Suite, IKS-Miner), S-CERT cybersecurity services (including PPZV phishing prevention and SAFE Operations), Payments (the TRAVIC product family with multiple variants: TRAVIC-EBICS-API, TRAVIC-Corporate, TRAVIC-Interbank, TRAVIC-Link, TRAVIC-Port, TRAVIC-Retail), Data Protection (Sicherer Datenschutz with RiMaGo DSM module), Compliance (SIZ Compliance-Suite for AML/WpHG compliance), and Revision services. The TRAVIC family serves different market segments (corporate, retail, interbank), while the PPZV/SAFE Operations form a layered fraud prevention module. The SIZ Compliance-Suite digitizes and professionalizes the commissionairewesen, integrating with the broader compliance and anti-money laundering service portfolio.
Differentiator
Problem solved
Functional benefit
Brands
- S-CERT: Sparkassen Computer Emergency Response Team - cybersecurity unit providing incident response, security advisories, and threat intelligence for Sparkassen-Finanzgruppe
- Sicherer IT-Betrieb
- Sichere IT-Plattform
- Sicherer Datenschutz
- SIZ Compliance-Suite
- IDV-Suite
- TRAVIC-Produktfamilie
- PPZV
- RiMaGo
- IKS-Miner
Products and services
- Sicherer IT-Betrieb (Secure IT Operations) Certification service for secure IT operations based on ISO 27001 standards, providing comprehensive information security management system (ISMS) audits and certification for Sparkassen and financial institutions.
- Sichere IT-Plattform (Secure IT Platform) Technology consulting service that conducts on-site audits to assess and improve IT security infrastructure and platform security for financial institution customers.
- Sicherer Datenschutz (Secure Data Protection) Comprehensive data protection services including outsourcing of Data Protection Officer functions, consulting, audits, and document management for GDPR compliance in financial institutions.
- SIZ Compliance-Suite Tool supporting compliance officers with qualitative upgrades in commissionaire services, digitization advancement, and specialized support for AML (anti-money laundering) and WpHG (Securities Trading Act) compliance officers.
- IDV-Suite Solution for managing risks in all risk areas in handling IDV (Individual Data Processing / Individualverarbeitung) applications, optimizing software documentation efforts through structured procedures.
- IKS-Miner Tool for identifying and analyzing internal control system (IKS) components, supporting internal audit and risk management functions.
- TRAVIC-EBICS-API API product within the TRAVIC family enabling EBICS-based electronic banking communication for developers and corporate customers in the Sparkassen-Finanzgruppe.
- TRAVIC-Corporate Corporate banking EBICS solution for corporate customers within the TRAVIC product family.
- TRAVIC-Interbank Interbank payment solution within the TRAVIC product family for interbank settlement.
- TRAVIC-Port Portal solution within the TRAVIC product family for centralized payment management.
- TRAVIC-Retail Retail payment solution within the TRAVIC product family for retail banking customers.
- PPZV (Phishing-Prävention im Zahlungsverkehr) Phishing prevention module for payment transactions, including SAFE Operations support for fraud case legal proceedings.
- S-CERT Services Computer Emergency Response Team services for the Sparkassen-Finanzgruppe including security vulnerability assessments, automated situation monitoring, malware analysis, and coordination of phishing incident handling.
- BCM und IT-Notfall (Business Continuity Management) Business Continuity Management and IT emergency planning services including emergency exercise support and business impact analysis for financial institutions.
Quantifiable outcome
- Over 80,000 successful L+R (Lage- und Reaktionsmechanismus) activations since 2010
- +3 more outcomes
Companies that use SIZ
Customer profileNamed customers7 records
Segments6 records
Ideal customer profiles2 records
SIZ technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
SIZ partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core and flagship.
- Sparkassen-Finanzgruppe (SFG)coreCore customer base and ecosystem partner. SIZ serves as Methodengeber (method provider) for information security within the SFG. The partnership encompasses all major stakeholders including DSGV, 12 regional associations, 350+ Sparkassen, and Landesbanken. SIZ develops standards and provides services that are widely adopted across the entire Sparkassen network.
- Finanz Informatik GmbH & Co. KGcorePrimary technology partner for core banking systems and IT infrastructure. Collaborates on DORA implementation projects and coordinates on PPS (Prüfungsnachweis-System) processes and tools.
- PPI AGflagshipJoint organizer of Payments 360° conference. PPI AG is a leading payment specialist that co-hosts the annual payments forum with SIZ, bringing together experts from the German banking sector.
- Tricept AGcoreTechnology partner for RiMaGo compliance tool. SIZ transferred its shares in the RiMaGo application to Tricept AG in December 2024. Tricept handles technical aspects while SIZ provides compliance methodology.
- bit InformatikcoreTechnology partner for bit-Compliance tool, referenced for DORA implementation. SIZ coordinates with bit Informatik for technical implementation of compliance requirements.
- BSI (Bundesamt für Sicherheit in der Informationstechnik)coreS-CERT serves as SPOC (Single Point of Contact) between BSI and Sparkassen-Finanzgruppe. Active collaboration in national CERT network since S-CERT co-founded the CERT-Verbund in 2002.
- Nationaler CERT-Verbund (German CERT Network)coreS-CERT co-founded the national CERT network in 2002, which now includes 40+ members including BSI, Deutsche Telekom, Bosch, Siemens, VW, and Bundeswehr. Network enables cross-organizational threat intelligence sharing.
- SIZ Service GmbHcore100% subsidiary of SIZ GmbH that markets telecommunications solutions and provides central services for Sparkassen-Finanzgruppe, such as card damage claim processing.
- DSGV (Deutscher Sparkassen- und Giroverband)corePrimary governance body of Sparkassen-Finanzgruppe. SIZ receives strategic direction and coordinates on major projects including DORA implementation, EBICS standards development, and S-CERT operations.
- Sparkassenverbände (12 Regional Associations)core12 regional Sparkassen associations (including Bayern, Baden-Württemberg, Niedersachsen, Rheinland-Pfalz, Westfalen-Lippe, etc.) serve as shareholders and governance partners.
Scale indicators7 records
Recent moves6 records
Expansion highlights5 records
SIZ competitors and assessment
Company assessmentDirect peers
- GFT Technologies: German-headquartered IT services firm focused on digital transformation for banks and insurance companies, particularly compliance, payments, and core banking modernization. Directly comparable as a specialized IT partner for regulated financial institutions in Germany.
- msg systems: German IT consulting and software firm with a strong financial-services practice serving banks and insurance companies. Comparable to SIZ in delivering IT solutions, compliance tools, and consulting services to regulated German financial institutions.
- PPI AG: German payment specialist and SIZ's joint organizer of the Payments 360° conference. Highly comparable in EBICS, ISO 20022, and payment processing expertise serving the Sparkassen ecosystem and broader German banking market.
- Finanz Informatik: Core IT service provider for the Sparkassen-Finanzgruppe and SIZ's primary technology partner. Both firms deliver IT services to the same Sparkassen customers, with Finanz Informatik owning core banking platforms and SIZ owning compliance/security/payments specialization.
- adesso SE: German IT services company with a dedicated banking practice providing software development, consulting, and compliance solutions to banks and insurance carriers. Comparable in serving German financial-services customers with technology and compliance expertise.
Emerging players
- AKQUINET: German IT services firm with a banking practice providing compliance, security, and software development services. Comparable as a mid-sized German IT services competitor pursuing similar banking-sector compliance and digitalization mandates.
Regional players
- DATEV: German cooperative IT services provider for tax advisors, auditors, and small/medium enterprises. Comparable as a centralized, member-owned IT service organization with deep regulatory and compliance expertise, though serving a different customer segment than SIZ's banking focus.
- Fiducia & GAD (Fiducia): Central IT service provider for the cooperative banking sector (Volksbanken/Raiffeisenbanken), analogous to Finanz Informatik for Sparkassen. Plays a similar central-provider role for a parallel German banking ecosystem, with comparable compliance and security mandates.
Broad incumbents
- Sopra Steria: Large European IT services group with a German banking practice providing consulting, software development, and managed services to financial institutions. Overlaps with SIZ on GRC, digital transformation, and regulatory compliance mandates for German banks.
Others
- Tricept AG: Technology partner that acquired SIZ's RiMaGo data-protection application in December 2024. Adjacent player delivering compliance and document-management tooling that integrates with SIZ's compliance methodology.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat7 records
Key risks5 records
Key highlights6 records
Customer concentration
SIZ social profiles
Digital presenceSIZ financial estimates
Financial estimateRevenue estimate
Valuation estimate
SIZ leadership team
Management profileNumber of profiles
Profiles11 records
SIZ subsidiaries and ownership
Company hierarchySubsidiaries1 record
SIZ funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SIZ M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SIZ
What does SIZ do?
SIZ GmbH provides information security, data protection, compliance, cybersecurity (S-CERT), and payment processing services and software tools to the German Sparkassen-Finanzgruppe (savings banks financial group). The company delivers outsourced compliance officer functions, ISO 27001-based ISMS certification, EBICS-based electronic banking solutions (TRAVIC family), anti-money laundering and fraud prevention support, and business continuity management consulting.
Is SIZ a public or private company?
SIZ is a private company. It is classified as corporate owned and is currently operating.
When was SIZ founded?
SIZ was founded in 1990. It employs 101 to 250 people.
Where is SIZ based?
SIZ is headquartered in Bonn, Germany, in the Europe region.
How does SIZ make money?
Four revenue lines are on record. Consulting and Advisory Services are the primary driver. The others are certification Services, S-CERT Security Services and training and Events.
Who are SIZ's main competitors?
Direct peers on record are GFT Technologies, msg systems, PPI AG, Finanz Informatik and adesso SE. AKQUINET is listed as an emerging player. Regional players are DATEV and Fiducia & GAD (Fiducia). Sopra Steria is listed as a broad incumbent. Tricept AG is listed as an others.
Does SIZ have an API?
No public API is recorded for SIZ.
What industry is SIZ in?
SIZ's product category is Banking IT Compliance Services. Its primary akta.pro industry code is HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms, with a secondary code of BPAEAPAM, ESG, Sustainability Reporting & Compliance. Its NAICS code is 541519 and its SIC code is 8700.