ComCERT
ComCERT SA is a Warsaw-based, Asseco Group-owned cybersecurity services firm operating a 24/7 SOC/CSIRT, CTI, penetration testing, and compliance consulting practice for Polish enterprises, government institutions, and critical-infrastructure clients.
- Company typePrivate
- Founded2013
- HeadquartersWarsaw, Poland
- Headcount11–50
- GTM typeB2B
- OfferingServices
What ComCERT does
ComCERT SA is a Warsaw-based cybersecurity services firm and subsidiary of the Asseco Group, providing managed security and consulting services to Polish enterprises, government institutions, and critical-infrastructure operators. Founded in 2011 (with the company website also indicating 2013) and employing 11-50 people, ComCERT operates a 24/7 Security Operations Center (SOC) with tiered L1/L2/L3 support (15-minute to 8-hour SLAs) and a CSIRT practice, alongside Cyber Threat Intelligence (CTI), penetration testing, computer forensics, vCISO, and cyber compliance services covering NIS2/UoKSC, DORA, GDPR, ISO 27001, and ISO 22301. The company holds NATO Secret, EU Secret Confidential, and Polish first-degree Industrial Security clearances, as well as TF-CSIRT Trusted Introducer accreditation and FIRST membership, enabling it to serve classified and public-sector clients.
The technology stack integrates best-of-breed security tooling — SIEM (including Azure Sentinel), EDR, XDR, NDR, SOAR, and PAM — with proprietary assets developed in-house, most notably the DAPT APT detection and imaging system, an AI-driven platform built on MITRE ATT&CK and Cyber Kill Chain frameworks that was co-developed with Warsaw University of Technology and Cryptomage S.A. under an NCBiR-funded R&D program. ComCERT also operates a four-module CTI platform (Threat Radar, Feedy IoC, IT Visibility, Incidents) covering darknet, phishing, malware, credential exposure, and infrastructure-vulnerability monitoring. The company's revenue mix combines managed SOC/CSIRT outsourcing, professional services (penetration testing, forensics, integration), and subscription-style vCISO retainers, with all engagements sold direct via an enterprise field-sales motion targeting large organizations and government buyers.
ComCERT firmographics
Firmographics- Name
- ComCERT
- Legal name
- ComCERT SA
- Website
- https://comcert.pl
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ComCERT SA is a Warsaw-based, Asseco Group-owned cybersecurity services firm operating a 24/7 SOC/CSIRT, CTI, penetration testing, and compliance consulting practice for Polish enterprises, government institutions, and critical-infrastructure clients.
- Ownership category
- akta.pro rank
ComCERT industry classification
Industry- Product category
- Managed Cybersecurity Services
- NAICS
- Computer Facilities Management Services (541513), Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Data Security & Privacy Managed Services (DLP/Encryption) (BPAEADAL), Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC)
Keywords
Where ComCERT is headquartered
LocationHeadquarters
- HQ city
- Warsaw
- HQ country
- Poland
- HQ region
- Europe
Offices1 record
Markets served
ComCERT business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- SOC & CSIRT Outsourcing (1st, 2nd, 3rd Line): Full outsourcing of Security Operations Center services across all three support tiers. The company operates a 24/7 SOC, providing continuous threat monitoring and real-time incident response. Includes L1 monitoring with 15-minute response SLA, L2 advanced analysis with 1-hour SLA, and L3 CTAC with malware analysis, strategic threat intelligence, and 8-hour SLA.
- Professional Cybersecurity Services: Professional services including penetration testing, computer forensics, cyber threat intelligence, incident response, and security audits. Delivered by certified experts (ISO27001, CEH, OSCP and others).
- vCISO (Virtual Chief Information Security Officer): Ongoing advisory service providing strategic information security management, ISMS/BCMS oversight, compliance support (NIS2, ISO 27001, ISO 22301, DORA, CER/UZK), and management reporting. Operated as a continuous retainer-style engagement.
- Cybersecurity Implementation & Integration: Design, deployment, and integration of IT security systems including firewalls, EDR/XDR, SIEM, SOAR, NDR, PAM, and cloud security solutions (Azure Firewall, Azure Sentinel). Includes remote administration and ongoing system maintenance.
- Cyber Compliance Consulting: Regulatory compliance services including NIS2/UoKSC gap analysis, GDPR compliance, ISO/IEC 27001 ISMS implementation, ISO 22301 BCMS certification support, DORA, and audit readiness. Provided as project-based consulting engagements.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels5 records
ComCERT product offering
Product offeringCore offering
ComCERT delivers managed cybersecurity services for enterprises and public-sector organizations in Poland, operating a 24/7 Security Operations Center (SOC) and CSIRT with tiered L1/L2/L3 support. Its portfolio spans Cyber Threat Intelligence (CTI), penetration testing, computer forensics, IT security system design and integration, vCISO advisory, and cyber compliance consulting (NIS2, DORA, GDPR, ISO 27001/22301). Services are delivered by certified experts and tailored to each client's infrastructure and regulatory environment.
Product overview
ComCERT offers a comprehensive cybersecurity services portfolio delivered as an integrated managed security services offering rather than a software product. The core portfolio includes SOC & CSIRT services (24/7 threat monitoring with tiered support), Cyber Threat Intelligence (CTI), Penetration Testing, Computer Forensics, and IT Security Systems implementation. Consulting services encompass Cyber Compliance (NIS2, DORA, GDPR, ISO 27001/22301), Innovative Consulting, and vCISO (Virtual CISO). These services work together as an integrated security ecosystem - SOC services provide continuous monitoring while CTI supplies threat intelligence feeds; penetration testing identifies vulnerabilities that SOC monitors for; forensic analysis supports post-incident response; and compliance services ensure regulatory adherence across all operations. The DAPT R&D project represents a specialized AI-powered APT detection module in development.
Differentiator
Problem solved
Functional benefit
Brands
- CTAC: Cyber Threat Analysis Center - the third line of SOC providing advanced cybersecurity analysis services including malware analysis, forensic analysis, and strategic Threat Intelligence consulting.
Products and services
- SOC & CSIRT Services 24/7 Security Operations Center and Computer Security Incident Response Team providing continuous threat monitoring, incident detection, analysis, and response across L1 (15-min SLA), L2 (1-hour SLA), and L3 CTAC (8-hour SLA) tiers. Outsourced SOC operations for organizations lacking internal capabilities.
- Cyber Threat Intelligence (CTI) Threat intelligence service providing up-to-date intelligence on emerging threats including spam/phishing campaigns, malware detection, darknet monitoring, credential monitoring, certificate/domain status tracking, vulnerability assessment, and external service analysis. Includes four modules: Threat Radar, Feedy IoC, IT Visibility, and Incidents.
- Penetration Testing Security testing services including black-box, white-box, and gray-box testing approaches, sociotechnical testing (phishing campaigns), Red Teaming, and Insider Threat Testing for comprehensive security assessment.
- Computer Forensics Incident analysis, digital evidence recovery, and forensic investigation services including post-incident analysis, malware analysis, IT forensic audits, and preparation of forensic reports for legal proceedings.
- IT Security Systems Comprehensive IT security solutions including network security (NGFW, proxy systems), endpoint protection (EDR/XDR, DLP), application/database security, email security, mobile device security, and cloud security (Azure, SASE).
- Implementation and Integration of Cybersecurity Systems Design, implementation, and integration of IT security systems for organizations including consulting for on-premise, hybrid, and cloud infrastructures, plus remote administration of implemented systems.
- Cyber Compliance
Quantifiable outcome
- L1 SOC response time of 15 minutes after alert detection
- +3 more outcomes
Companies that use ComCERT
Customer profileNamed customers3 records
Segments5 records
Ideal customer profiles3 records
ComCERT technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability6 records
Feature2 records
ComCERT partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Politechnika Warszawska (Warsaw University of Technology)coreConsortium partner in the DAPT R&D project (Advanced Persistent Threat Detection System). Project number 488393, implemented under the CyberSecIdent Program. Warsaw University of Technology served as a consortium member alongside ComCERT (project leader) and Cryptomage S.A., with total project value of 12,715,528 PLN.
- Cryptomage S.A.coreConsortium partner in the DAPT R&D project alongside ComCERT (project leader) and Politechnika Warszawska. Cryptomage contributed cybersecurity expertise to the advanced threat detection and AI-based APT analysis system development.
- CERT-TG (Togo)coreComCERT and the government CERT of Togo (CERT-TG) signed a strategic cooperation agreement. This partnership represents international collaboration between two national/regional CERT teams to strengthen cyber incident response capabilities and share threat intelligence across borders.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
ComCERT competitors and assessment
Company assessmentRegional players
- Sii Poland: Large Polish IT and engineering services provider with a growing cybersecurity practice covering pentesting, security operations, and compliance. It is a domestic peer competing for similar Polish enterprise and public-sector projects, but its cybersecurity practice is one of many IT verticals.
- WithSecure (formerly F-Secure Business): Nordic-headquartered cybersecurity vendor with a strong managed detection & response and consulting practice across Europe. Like ComCERT, WithSecure sells outcome-based SOC/MDR services to enterprises and public sector, but at materially larger scale and primarily outside Poland.
- Comarch: Polish IT group with cybersecurity offerings including SOC services, identity management, and compliance platforms. Comarch is a domestic peer that competes with ComCERT on Polish enterprise and public-sector accounts and shares the conglomerate-distribution advantage similar to Asseco.
- Tietoevry Cybersecurity: Nordic-headquartered IT services group with a managed security services line covering SOC, identity, and compliance for enterprises and public sector. Comparable to ComCERT in offering managed SOC and compliance work to regulated Nordic and European customers, but with much larger scale.
Broad incumbents
- Atos Cybersecurity Services: Global systems integrator with a sizable managed security, SOC, and incident response practice serving public-sector and enterprise clients. Comparable to ComCERT in offering tiered SOC outsourcing and compliance consulting, but operating at very different scale and breadth across multiple geographies.
- Orange Cyberdefense: European MSSP and SOC operator owned by Orange, providing managed detection, incident response, and threat intelligence to large enterprises and governments. It competes with ComCERT for the same enterprise and public-sector buyers across CEE and Western Europe, with a much broader geographic and service footprint.
- Capgemini Cybersecurity: Global consulting and systems integrator with a managed security services portfolio including SOC, identity, and compliance. Competes with ComCERT for large enterprise and regulated-industry work, especially where group-level framework agreements cover multiple geographies.
Emerging players
- Sekoia.io: European cybersecurity vendor offering a SaaS SOC/CTI platform plus managed detection and response services to MSSPs and enterprises. Comparable to ComCERT's CTI and SOC offerings in terms of customer pain point, but differentiated by a product-led, multi-tenant SaaS model rather than pure services delivery.
Others
- Deloitte Cyber Risk Services: Global professional services firm with a large cyber risk advisory and managed security practice serving enterprises and public-sector clients. Competes with ComCERT for advisory, compliance, and SOC-related engagements, particularly with multinational buyers that prefer Big Four risk advisors.
Direct peers
- Exatel: Polish state-affiliated telecom and SOC operator offering managed cybersecurity, CSIRT, and SOC services to government and critical-infrastructure customers. It is the closest direct regional competitor to ComCERT, serving overlapping Polish public-sector and enterprise clients with comparable 24/7 monitoring, incident response, and compliance offerings.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
ComCERT social profiles
Digital presenceComCERT compliance and trust
Trust signalCompliance16 records
ComCERT financial estimates
Financial estimateRevenue estimate
Valuation estimate
ComCERT leadership team
Management profileNumber of profiles
ComCERT funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ComCERT M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ComCERT
What does ComCERT do?
ComCERT delivers managed cybersecurity services for enterprises and public-sector organizations in Poland, operating a 24/7 Security Operations Center (SOC) and CSIRT with tiered L1/L2/L3 support. Its portfolio spans Cyber Threat Intelligence (CTI), penetration testing, computer forensics, IT security system design and integration, vCISO advisory, and cyber compliance consulting (NIS2, DORA, GDPR, ISO 27001/22301). Services are delivered by certified experts and tailored to each client's infrastructure and regulatory environment.
Is ComCERT a public or private company?
ComCERT is a private company. It is classified as corporate owned and is currently operating.
When was ComCERT founded?
ComCERT was founded in 2013. It employs 11 to 50 people.
Where is ComCERT based?
ComCERT is headquartered in Warsaw, Poland, in the Europe region.
How does ComCERT make money?
Five revenue lines are on record. SOC & CSIRT Outsourcing (1st, 2nd, 3rd Line) is the primary driver. The others are professional Cybersecurity Services, vCISO (Virtual Chief Information Security Officer), cybersecurity Implementation & Integration and cyber Compliance Consulting.
Who are ComCERT's main competitors?
Regional players on record are Sii Poland, WithSecure (formerly F-Secure Business), Comarch and Tietoevry Cybersecurity. Broad incumbents are Atos Cybersecurity Services, Orange Cyberdefense and Capgemini Cybersecurity. Sekoia.io is listed as an emerging player. Deloitte Cyber Risk Services is listed as an others. Exatel is listed as a direct peer.
Does ComCERT have an API?
No public API is recorded for ComCERT.
What industry is ComCERT in?
ComCERT's product category is Managed Cybersecurity Services. Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services, with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 541513 and its SIC code is 7370.