Serma Safety & Security
SERMA Safety & Security is a French ANSSI-accredited cybersecurity and functional safety firm operating a Common Criteria laboratory (ranked 2nd globally) and serving critical infrastructure, industrial, and hardware manufacturers across 500+ clients via evaluations, audits, managed SOC services, and the Hardsploit NG hardware auditing tool.
- Company typePrivate
- Founded1998
- HeadquartersPessac, France
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Serma Safety & Security does
SERMA Safety & Security is a French cybersecurity and functional safety services firm and a wholly-owned subsidiary of SERMA Group. Founded in 1998 as a security evaluation laboratory, it operates as an ANSSI-accredited CESTI/ITSEF ranked 2nd globally for Common Criteria evaluations and top-5 worldwide among security laboratories. The company combines five practice areas: cybersecurity for information systems (penetration testing, SOC/CSIRT, integration), cybersecurity for industrial control systems (IEC 62443), cybersecurity for embedded systems and IoT (RED Directive, Cyber Resilience Act, Hardsploit NG), a Common Criteria security evaluation laboratory covering EMVCo, PCI PTS/MPoC/SPoC, GlobalPlatform, GSMA eSA, FIPS 140-3, EUCC and related schemes, and functional safety consulting (ISO 26262, ISO 25119, IEC 61508, EN 50126/128/129) delivered alongside formal-methods expertise under the SafeRiver brand.
The company monetizes primarily through project-based professional services — security evaluations billed per engagement, fixed-fee compliance packages for the RED Directive starting at €3,750 and scaling to €13,500+, and quote-based enterprise audits. Recurring revenue streams include managed SOC/CSIRT services adapted for SMEs and mid-cap firms (ETIs) and SERMA Academy training across 70+ cybersecurity and functional safety courses. Customer segments are organized vertically: critical infrastructure operators (OIV/OSE) subject to NIS 2 and LPM, industrial and manufacturing companies pursuing IEC 62443 and functional safety certifications, and hardware/semiconductor manufacturers requiring Common Criteria, EUCC, EMVCo, PCI, and GSMA certifications for market access. The Hardsploit / Hardsploit NG hardware auditing tools represent a proprietary product line funded by Bpifrance and France 2030.
SERMA distributes exclusively through direct enterprise field sales and inside sales (no resellers), supplemented by an event-driven presence at FIC, Hack In Paris, MWC Barcelona, European Cyber Week, and TechnoDay. A channel partnership with LCIE Bureau Veritas (Notified Body No. 0081) enables formal IEC 62443 and RED EU-type certification delivery. Approximately 200 engineers and consultants operate from three French sites (Pessac HQ, Paris/Guyancourt, Rennes), serving a 500+ client base that includes Thales, GSMA, Fime, INEO UTS, WATTALPS, ALiS, and M-Extend.
Serma Safety & Security firmographics
Firmographics- Name
- Serma Safety & Security
- Legal name
- SERMA Group
- Website
- https://serma-safety-security.com
- Company type
- Private
- Founded year
- 1998
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- SERMA Safety & Security is a French ANSSI-accredited cybersecurity and functional safety firm operating a Common Criteria laboratory (ranked 2nd globally) and serving critical infrastructure, industrial, and hardware manufacturers across 500+ clients via evaluations, audits, managed SOC services, and the Hardsploit NG hardware auditing tool.
- Ownership category
- akta.pro rank
Serma Safety & Security industry classification
Industry- Product category
- Cybersecurity and Functional Safety Services
- NAICS
- Testing Laboratories and Services (54138), Investigation and Security Services (5616)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
- akta.pro secondary industries
- Safety Systems & SIS Security (Functional Safety / Triconex-class) (HDADAJAI), Security Operations Center (SOC) as a Service (BPAEADAB), Security Training & Compliance (Guard Training, SOPs, Drills) (BPABAMAN), Safety Instrumented Systems & Machine Safety Control (SIS, Safety PLCs, Relays) (IMAGABAF)
Keywords
Where Serma Safety & Security is headquartered
LocationHeadquarters
- HQ city
- Pessac
- HQ country
- France
- HQ region
- Europe
Offices3 records
Markets served
Serma Safety & Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Infrastructure, Marketing or Sales
Revenue model
- Security Evaluation and Testing Services: Laboratory-based security evaluations (Common Criteria, EMVCo, PCI, FIPS, GSMA eSA, EUCC) and penetration testing services. Revenue generated through project-based fees per evaluation or test engagement.
- Cybersecurity Consulting and Advisory: Advisory services including NIS 2 compliance support, RED Directive guidance, Cyber Resilience Act accompaniment, Active Directory security, architecture audits, configuration audits, and source code audits. Billed as fixed-fee projects or daily rates.
- Managed Security Services (SOC/CSIRT): Ongoing security monitoring and incident response services through the SOC, adapted for SMEs and mid-sized enterprises (ETIs).
- Training Services (SERMA Academy): Professional training programs covering cybersecurity and functional safety. Over 70 courses offered in intra, inter, distance, and custom formats. ISO 9001 certified for Managed Security Services, Safety, and Industrial Embedded Cybersecurity training.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Pay-as-you-go | Quick Assessment and Roadmap (RED Directive) |
| One time/ perpetual license | Pay-as-you-go | In-depth Assessment and Risk Analysis (RED Directive) |
| One time/ perpetual license | Pay-as-you-go | In-depth Assessment and Intrusion Testing (RED Directive) |
| One time/ perpetual license | Pay-as-you-go | Complete Compliance Audit (documentary + functional) |
| One time/ perpetual license | Pay-as-you-go | EU-type Evaluation via LCIE Bureau Veritas |
| Subscription | Pay-as-you-go | Cybersecurity and IoT Compliance Training - RED Directive |
| Subscription | Pay-as-you-go | SERMA Academy Training Catalog |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
Serma Safety & Security product offering
Product offeringCore offering
SERMA Safety & Security provides cybersecurity and functional safety services to enterprises and government entities. The company operates an ANSSI-accredited security evaluation laboratory (CESTI/ITSEF) that performs Common Criteria, EMVCo, PCI, GSMA eSA, EUCC, and FIPS 140-3 product certifications. Offerings also include penetration testing, SOC/CSIRT managed security, NIS 2/RED/CRA regulatory compliance advisory, functional safety assessments for safety-critical systems, formal methods verification, and the proprietary Hardsploit hardware auditing tool.
Product overview
SERMA Safety and Security operates as a comprehensive cybersecurity and functional safety services company with a multi-product portfolio organized around five interconnected practice areas: (1) Cybersecurity for information systems — encompassing penetration testing, SOC/CSIRT managed services, and cybersecurity solutions integration; (2) Cybersecurity for industrial systems — supporting IEC 62443 certification; (3) Cybersecurity for embedded systems and IoT — covering RED Directive, Cyber Resilience Act, and hardware auditing; (4) A Common Criteria-accredited security evaluation laboratory (CESTI/ITSEF) offering product certifications across EMVCo, PCI, GSMA, GlobalPlatform, FIPS 140-3, and EUCC schemes; and (5) Functional safety (Sûreté de fonctionnement) consulting for ISO 26262, ISO 25119, IEC 61508, and railway standards, delivered alongside formal methods under the SafeRiver brand. Training is delivered through SERMA Academy with over 70 courses. The company also developed Hardsploit, a hardware auditing framework, and its next-generation Hardsploit NG incorporates AI for neural network-based electronic bus identification.
Differentiator
Problem solved
Functional benefit
Brands
- Hardsploit NG: Next generation hardware auditing tool designed to automate and simplify cybersecurity testing for embedded systems and IoT devices, incorporating advanced technologies including artificial intelligence.
- Cyber Coach 360
- SafeRiver
- SERMA NES
Products and services
- Cybersecurity for Information Systems Cybersecurity services for enterprise information systems, covering audits, penetration testing, SOC and CSIRT managed security services, NIS 2 directive compliance support, Active Directory security, Cyber Due Diligence, and Cyber Coach 360 awareness training. Targeted at enterprise IT teams.
- Cybersecurity for Industrial Systems Cybersecurity services for industrial control systems and operational technology environments, helping industrial companies achieve IEC 62443 certification through partnership with LCIE Bureau Veritas. For OT operators and industrial manufacturers.
- Cybersecurity for Embedded Systems and IoT Cybersecurity services for embedded systems and IoT devices, including RED Directive compliance support, Cyber Resilience Act (CRA) compliance, hardware security testing, and secure development lifecycle advisory. For connected product manufacturers.
- Security Evaluation Laboratory (CESTI/ITSEF) ANSSI-accredited security evaluation laboratory offering product security evaluations under Common Criteria, EMVCo, GlobalPlatform, PCI PTS/MPoC/SPoC, GSMA eSA, FIPS 140-3, SESIP, PSA Certified, and EUCC schemes. Evaluates over 200 complex security products annually. For hardware and software product manufacturers requiring certification.
- Functional Safety Consulting (Sûreté de fonctionnement) Functional safety consulting and assessment services for hardware and software systems, supporting compliance with ISO 26262 (automotive), ISO 25119 (agricultural machinery), IEC 61508, EN 50126/128/129 (railway), and ISO 21434 (automotive cybersecurity). For safety-critical system developers.
- Formal Methods (SafeRiver) Formal methods expertise delivered under the SafeRiver brand, providing mathematically rigorous verification and validation services for safety-critical and security-critical systems. For developers of critical embedded software and hardware.
- SERMA Academy Training Training organization offering over 70 courses in cybersecurity and functional safety, available in intra-company, inter-company, distance, and bespoke formats. Covers EBIOS RM, ISO 27001, NIS 2, RED Directive, IEC 62443 and related standards. ISO 9001 certified. For professionals and engineering teams.
- Hardsploit NG Next-generation automated hardware auditing tool for embedded systems and IoT cybersecurity testing. Features modular FPGA-based platform for intercepting, replaying, and sending data through electronic bus interfaces (JTAG, SPI, I2C, parallel bus). Incorporates artificial intelligence for neural network-based identification of electronic communication buses. For hardware security auditors and embedded system developers.
- Audits and Penetration Testing Structured penetration testing and security audits covering network, application, Wi-Fi, Red Team, source code, configuration, architecture, organizational, and physical security. PASSI-qualified audits compliant with ANSSI RGS and LPM requirements. For organizations requiring certified security audits.
- SOC and CSIRT Managed Services Security Operations Center and Computer Security Incident Response Team managed services providing continuous monitoring, threat detection, and incident response. Adapted for SMEs and mid-sized enterprises (ETIs). For organizations needing outsourced security operations.
- Cybersecurity Solutions Integration Sale and integration of cybersecurity solutions, offering tailored recommendations and implementation support for security technologies across IT, industrial, and embedded environments. For organizations deploying security tooling.
- NIS 2 Directive Compliance Advisory Advisory services helping companies determine NIS 2 eligibility and build compliance roadmaps for the October 2024 transposition deadline in France. For essential and important entities subject to NIS 2.
- RED Directive Compliance Advisory Compliance advisory for the Radio Equipment Directive (RED) cybersecurity amendment, with offerings starting from €3,750 covering gap analysis (EN 18031, ETSI EN 303 645), risk analysis, intrusion testing, and EU-type evaluation through LCIE Bureau Veritas. For radio equipment manufacturers.
- Cyber Coach 360 Cybersecurity awareness and training platform designed to assess and improve organizational resilience against human-targeted threats including phishing and social engineering. For organizations seeking employee security awareness programs.
- EUCC Security Evaluations Security evaluations for hardware and software products under the EUCC (European Union Common Criteria) scheme, following the first ANSSI-granted EUCC accreditation in France. Valid for five years. For product manufacturers seeking European cybersecurity certification.
Quantifiable outcome
- 200+ complex security products evaluated annually
- +3 more outcomes
Companies that use Serma Safety & Security
Customer profileNamed customers10 records
Segments5 records
Ideal customer profiles5 records
Serma Safety & Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Serma Safety & Security partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and major.
- ANSSIcoreANSSI (French National Cybersecurity Agency) granted SERMA the first EUCC accreditation in France. SERMA collaborates with ANSSI on NIS 2 Directive transposition in France and holds multiple ANSSI qualifications: PASSI RGS (all scopes), PASSI LPM, PRIS Substantiel, and CESTI accreditation.
- LCIE Bureau VeritascorePartnership with LCIE Bureau Veritas (Notified Body No. 0081) to facilitate IEC 62443 industrial cybersecurity certification for clients. SERMA provides dossier preparation, personalized advice, and compliance support; LCIE Bureau Veritas handles formal report drafting and certificate issuance. Also collaborates on EU-type evaluation under the RED Directive.
- GSMAcoreSERMA Security Laboratory joined the GSMA as an Associate Member. Collaboration on eSA (eUICC Security Assurance) scheme since its inception. GSMA represents mobile operators and ecosystem players in 220 countries. SERMA provides security assessments of SIM cards, eSIM, and mobile applications.
- FimemajorLong-standing partnership since 2015 for payment scheme certifications. Fime and SERMA Security Laboratory combine expertise and sales force to deliver security evaluations, enabling payment product certifications. Delivers over 10 projects per year.
Scale indicators10 records
Recent moves7 records
Expansion highlights6 records
Serma Safety & Security competitors and assessment
Company assessmentDirect peers
- Brightsight (SGS Brightsight): Common Criteria evaluation laboratory based in the Netherlands, acquired by SGS. Direct competitor to SERMA's CESTI/ITSEF for hardware and smart card security evaluations under Common Criteria, EMVCo, and payment schemes.
- Riscure: Dutch security lab specializing in hardware and embedded device evaluations, side-channel analysis, and penetration testing. Direct peer to SERMA's Hardsploit-driven embedded security practice and CESTI lab.
- TrustCB: Common Criteria certification body operating in the EU. Direct peer to SERMA for Common Criteria/EUCC certification schemes, with overlapping vendor relationships in smart card and secure element evaluation.
- Fime: French payment security consultancy and lab with whom SERMA already runs 10+ joint projects/year. Direct peer in EMVCo, PCI, GSMA, and payment certification evaluations with overlapping customer base.
Broad incumbents
- Bureau Veritas / LCIE: Global testing, inspection, and certification (TIC) incumbent and SERMA's IEC 62443/RED partner through LCIE Bureau Veritas. Overlaps on industrial cybersecurity certification, functional safety, and EU-type evaluation, but at significantly larger scale and broader scope.
- TÜV Rheinland: Global testing and certification conglomerate. Direct peer for Common Criteria, FIPS 140-3, automotive cybersecurity (ISO/SAE 21434), and industrial cybersecurity (IEC 62443) certification, but operates at much larger scale across multiple verticals.
- Applus+ Laboratories: International testing, inspection, and certification group with cybersecurity and functional safety capabilities. Direct overlap with SERMA's automotive (ISO 26262) and industrial cybersecurity testing, though broader in scope.
- Orange Cyberdefense: Major European managed cybersecurity services provider with SOC, CSIRT, and consulting offerings. Overlaps with SERMA's SOC/CSIRT for SMEs and ETIs and with PASSI-qualified audit services, but at much larger scale.
- Thales Cybersecurity & Digital Identity: Global defense and cybersecurity incumbent that is simultaneously a SERMA customer (Thales Canada, Thales Meyreuil) and a peer for hardware security evaluation, Common Criteria, and certified product assessments.
Emerging players
- ICTK: Korean security evaluation laboratory (ITSEF) accredited for Common Criteria, EMVCo, and payment scheme evaluations. Direct peer for certified hardware security assessments but with narrower geographic footprint and scheme coverage than SERMA.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
Serma Safety & Security social profiles
Digital presenceSerma Safety & Security compliance and trust
Trust signalCompliance15 records
Serma Safety & Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Serma Safety & Security leadership team
Management profileNumber of profiles
Profiles3 records
Serma Safety & Security subsidiaries and ownership
Company hierarchySubsidiaries3 records
Serma Safety & Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Serma Safety & Security M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Serma Safety & Security
What does Serma Safety & Security do?
SERMA Safety & Security provides cybersecurity and functional safety services to enterprises and government entities. The company operates an ANSSI-accredited security evaluation laboratory (CESTI/ITSEF) that performs Common Criteria, EMVCo, PCI, GSMA eSA, EUCC, and FIPS 140-3 product certifications. Offerings also include penetration testing, SOC/CSIRT managed security, NIS 2/RED/CRA regulatory compliance advisory, functional safety assessments for safety-critical systems, formal methods verification, and the proprietary Hardsploit hardware auditing tool.
Is Serma Safety & Security a public or private company?
Serma Safety & Security is a private company. It is classified as corporate owned and is currently operating.
When was Serma Safety & Security founded?
Serma Safety & Security was founded in 1998. It employs 51 to 100 people.
Where is Serma Safety & Security based?
Serma Safety & Security is headquartered in Pessac, France, in the Europe region.
How does Serma Safety & Security make money?
Four revenue lines are on record. Security Evaluation and Testing Services are the primary driver. The others are cybersecurity Consulting and Advisory, managed Security Services (SOC/CSIRT) and training Services (SERMA Academy).
Who are Serma Safety & Security's main competitors?
Direct peers on record are Brightsight (SGS Brightsight), Riscure, TrustCB and Fime. Broad incumbents are Bureau Veritas / LCIE, TÜV Rheinland, Applus+ Laboratories, Orange Cyberdefense and Thales Cybersecurity & Digital Identity. ICTK is listed as an emerging player.
Does Serma Safety & Security have an API?
No public API is recorded for Serma Safety & Security.
What industry is Serma Safety & Security in?
Serma Safety & Security's product category is Cybersecurity and Functional Safety Services. Its primary akta.pro industry code is BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX), with a secondary code of HDADAJAI, Safety Systems & SIS Security (Functional Safety / Triconex-class). Its NAICS code is 54138 and its SIC code is 8734.