CERT-IS
CERT-IS is Iceland's national Computer Emergency Response Team, operating under the Ministry of Foreign Affairs to coordinate cybersecurity incident response, issue vulnerability advisories, and serve critical infrastructure providers, telecom operators, and government entities across Iceland.
- Company typePrivate
- Founded2021
- HeadquartersReykjavík, Iceland
- Headcount11–50
- GTM typeB2B
- OfferingServices
What CERT-IS does
CERT-IS (Computer Emergency Response Team – Iceland) is Iceland's national cybersecurity coordination body, operating as an organizational unit under Iceland's Ministry of Foreign Affairs. Formally established as the national CERT in 2021 (with organizational roots extending to 2013), it functions as Iceland's statutory point-of-contact for cybersecurity incidents and holds legal authority to issue binding directives to operators of critical infrastructure and registered telecommunications operators under Icelandic law (Act 78/2019 and associated regulations). Its mandated constituency comprises critical infrastructure providers, registered telecommunications operators, eligible government entities, and—on a best-effort basis—the Icelandic public. Core services include incident triage and coordination, vulnerability advisories, threat monitoring, public cybersecurity education, and incident reporting via the Island.is government portal, phone, email, and PGP/GnuPG-encrypted channels.
The organization's technology stack centers on a National Security Operations Center (SOC) announced in January 2026, which will provide 24/7 monitoring and rapid threat response and is co-funded by the European Union's Digital Europe Programme, with full operational capability targeted for the end of 2027. The SOC will connect directly to the Nordic-Baltic Cyber Consortium (NBCC) for real-time threat intelligence sharing across Nordic and Baltic countries, supplementing CERT-IS's existing memberships in FIRST (the global Forum of Incident Response and Security Teams), its accreditation by the Trusted Introducer Service, and recurring participation in NATO CCDCOE's Locked Shields exercises. Headquarters are located at Reykjastræti 8, Reykjavík, with the SOC being constructed at the Ministry of Foreign Affairs premises at Austurhöfn.
CERT-IS does not operate on a commercial revenue model. As a non-commercial government entity, it is publicly funded through Icelandic government appropriations via the Ministry of Foreign Affairs and through EU co-funding, and provides free services to its legally defined constituency. Distribution is direct: incident coordination and SOC services for constituents, vulnerability advisories via website and email, and self-serve incident reporting through Island.is for individuals and businesses. Approximately 600 cybersecurity incidents were reported to CERT-IS in 2021, with the Icelandic economy estimated to suffer around 40 billion ISK in annual losses from cyber incidents at that time. The organization operates with 11–50 staff and is led by Director Magni R. Sigurðsson.
CERT-IS firmographics
Firmographics- Name
- CERT-IS
- Legal name
- Computer Emergency Response Team – Iceland
- Website
- https://cert.is
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CERT-IS is Iceland's national Computer Emergency Response Team, operating under the Ministry of Foreign Affairs to coordinate cybersecurity incident response, issue vulnerability advisories, and serve critical infrastructure providers, telecom operators, and government entities across Iceland.
- Ownership category
- akta.pro rank
CERT-IS industry classification
Industry- Product category
- National Cybersecurity / CERT Services
- NAICS
- National Security (928110), International Affairs (92812), Computer Facilities Management Services (541513)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Data Protection, Privacy & Cybersecurity Regulators (BPAIAOAH)
- akta.pro secondary industries
- Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF), Government / Defense & High-Security Data Centers (HDABACAK)
Keywords
Where CERT-IS is headquartered
LocationHeadquarters
- HQ city
- Reykjavík
- HQ country
- Iceland
- HQ region
- Europe
Offices2 records
Markets served
CERT-IS business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Infrastructure, Operations, Others
Revenue model
- Government Funding: CERT-IS is an organizational unit under the Ministry of Foreign Affairs of Iceland. The National Security Operations Center project is co-funded by the European Union through the Digital Europe Programme.
- Contracted Cybersecurity Services: CERT-IS can enter into contracts to provide certain cybersecurity services to eligible entities, including SOC services for contracted constituents.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels5 records
CERT-IS product offering
Product offeringCore offering
CERT-IS is Iceland's national Computer Emergency Response Team operating under the Ministry of Foreign Affairs, providing incident reporting and coordination, vulnerability notifications and threat advisories, a 24/7 National Security Operations Center (being established, full operation by end of 2027), and public cybersecurity education. Services are delivered free of charge to its legally mandated constituency of critical infrastructure providers, registered telecommunications operators, and eligible government entities.
Product overview
CERT-IS (Computer Emergency Response Team – Iceland) is Iceland's national computer emergency response team operating under the Ministry of Foreign Affairs. It is not a commercial product company but rather a government coordination body that provides: incident reporting and coordination services for security incidents, vulnerability notifications and advisories, a 24/7 National Security Operations Center (SOC) for eligible government entities, and public cybersecurity education materials. The organization reduces cyber risk in Icelandic networks, monitors threats and vulnerabilities, and coordinates incident response. By law, the constituency includes registered telecommunications operators, critical infrastructure providers, certain eligible government entities, and contracted parties.
Differentiator
Problem solved
Functional benefit
Products and services
- Incident Reporting and Coordination Services Triage and coordination of reported security incidents involving constituents as defined in the CERT-IS mandate. CERT-IS handles all incidents regardless of affected sector or party, prioritizing based on affected constituency and severity.
- Vulnerability Notifications and Threat Advisories
- National Security Operations Center (SOC) Round-the-clock monitoring of Icelandic cyberspace with real-time anomaly detection and rapid threat response to minimize damage, including direct connection to the Nordic-Baltic Cyber Consortium (NBCC) for real-time threat information sharing.
- Cybersecurity Education and Public Awareness
Quantifiable outcome
- 600 cybersecurity incidents reported in 2021
- +1 more outcomes
Companies that use CERT-IS
Customer profileNamed customers10 records
Segments5 records
Ideal customer profiles4 records
CERT-IS technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
CERT-IS partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered core and minor.
- NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE)coreCERT-IS participates in NATO CCDCOE organized exercises including Locked Shields 2026, the world's largest cyber defense exercise. Iceland participated alongside Norway and NATO with a team of 17 specialists from 10 organizations.
- NorwayminorNorway partnered with Iceland and NATO in the Locked Shields 2026 cyber defense exercise organized by CCDCOE.
- ISNIC (Internet Service Providers in Iceland)minorISNIC warned about phishing campaigns targeting .is domain registrants. CERT-IS collaborates with ISNIC on domain-related security incidents and advisories.
- Nordic Baltic Cyber Consortium (NBCC)coreThe National Security Operations Center will have direct connection to the Nordic Baltic Cyber Consortium for real-time threat information sharing between Nordic and Baltic countries. This regional partnership supports coordinated cyber defense across member nations.
- FIRST (Forum of Incident Response and Security Teams)coreCERT-IS is a member of FIRST, the global Forum of Incident Response and Security Teams. This membership enables international cooperation and information sharing with other national CERTs and incident response teams worldwide.
- Trusted Introducer ServicecoreCERT-IS is an accredited team by the Trusted Introducer Service, providing formal recognition of the team's capabilities and operational standards in the European incident response community.
- National Commissioner of the Icelandic PolicecoreCERT-IS is obliged by law to notify the National Commissioner of the Icelandic Police of incidents and risks that may lead to serious impact on critical infrastructure, national security, or the general public.
- National Cyber Security Council (Iceland)coreCERT-IS is obliged to notify the National Cyber Security Council of incidents and risks affecting national cyber security. Regular reports are disseminated to the council.
- Ministry of Foreign Affairs (Iceland)coreCERT-IS is an organisational unit under the Ministry of Foreign Affairs of Iceland. The Ministry provides administrative oversight and the headquarters is located at Ministry premises.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
CERT-IS competitors and assessment
Company assessmentDirect peers
- CERT-EE (Estonian CERT): Estonia's national CERT under the Information System Authority (RIA). Direct peer in national incident response and a fellow NBCC member; comparable scope serving a small digitally advanced EU member state.
- CFCS (Center for Cyber Security, Denmark): Denmark's national cyber security authority under the Danish Defence Intelligence Service. Directly comparable mandate around national threat intelligence, incident coordination, and SOC services for critical sectors, and an NBCC partner.
- NorCERT (Norwegian National CERT): Norway's national CERT, operated under the Norwegian National Security Authority (NSM). Directly comparable as a Nordic national CERT providing 24/7 incident response, SOC services, vulnerability advisories, and threat intelligence to critical infrastructure — and a fellow NBCC partner.
- CERT-SE (Swedish National CERT): Sweden's national CERT, part of the Swedish Civil Contingencies Agency (MSB). Direct Nordic peer delivering national incident coordination, vulnerability notifications, and SOC capabilities, and a partner within the NBCC threat-sharing consortium.
- NCSC-FI (Finnish National Cyber Security Centre): Finland's national CERT within Traficom, providing incident response, situational awareness, and SOC-like services to Finnish critical infrastructure. Closely comparable in mandate and Nordic-Baltic regional cooperation.
Broad incumbents
- ENISA (European Union Agency for Cybersecurity): EU-level agency coordinating cybersecurity across member states including Iceland-adjacent partners. Comparable at the policy, capacity-building, and pan-European coordination layer; supports EU funding mechanisms (e.g., Digital Europe) that finance CERT-IS's SOC.
- NCSC UK (National Cyber Security Centre): The UK's national technical authority on cyber security, part of GCHQ. Directly comparable national CERT mandate, but at vastly greater scale, budget, and operational scope.
- NCSC-NL (National Cyber Security Centre, Netherlands): Broader European national CERT/CSIRT providing incident response, advisories, and SOC capabilities to Dutch critical infrastructure. Comparable in mandate but operates at significantly larger scale and resource depth than CERT-IS.
- CISA (Cybersecurity and Infrastructure Security Agency, US): The US federal national cyber and infrastructure security agency. Comparable function as the national coordination body for incident response, advisories, and critical infrastructure protection, but at enormously greater scale.
Others
- CSIRTs Network (via ENISA): Network of national and governmental CSIRTs across the EU, mandated under NIS/NIS2 for cross-border incident coordination. CERT-IS participates in this network, making it a structural peer group rather than a single comparable organization.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
CERT-IS financial estimates
Financial estimateRevenue estimate
Valuation estimate
CERT-IS leadership team
Management profileNumber of profiles
Profiles1 record
CERT-IS funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CERT-IS M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CERT-IS
What does CERT-IS do?
CERT-IS is Iceland's national Computer Emergency Response Team operating under the Ministry of Foreign Affairs, providing incident reporting and coordination, vulnerability notifications and threat advisories, a 24/7 National Security Operations Center (being established, full operation by end of 2027), and public cybersecurity education. Services are delivered free of charge to its legally mandated constituency of critical infrastructure providers, registered telecommunications operators, and eligible government entities.
Is CERT-IS a public or private company?
CERT-IS is a private company. It is classified as state government owned and is currently operating.
When was CERT-IS founded?
CERT-IS was founded in 2021. It employs 11 to 50 people.
Where is CERT-IS based?
CERT-IS is headquartered in Reykjavík, Iceland, in the Europe region.
How does CERT-IS make money?
Two revenue lines are on record. Government Funding is the primary driver. The others are contracted Cybersecurity Services.
Who are CERT-IS's main competitors?
Direct peers on record are CERT-EE (Estonian CERT), CFCS (Center for Cyber Security, Denmark), NorCERT (Norwegian National CERT), CERT-SE (Swedish National CERT) and NCSC-FI (Finnish National Cyber Security Centre). Broad incumbents are ENISA (European Union Agency for Cybersecurity), NCSC UK (National Cyber Security Centre), NCSC-NL (National Cyber Security Centre, Netherlands) and CISA (Cybersecurity and Infrastructure Security Agency, US). CSIRTs Network (via ENISA) is listed as an others.
Does CERT-IS have an API?
No public API is recorded for CERT-IS.
What industry is CERT-IS in?
CERT-IS's product category is National Cybersecurity / CERT Services. Its primary akta.pro industry code is BPAIAOAH, Data Protection, Privacy & Cybersecurity Regulators, with a secondary code of BPAHAFAF, Privacy, Data Protection & Cyber Governance (GRC). Its NAICS code is 928110 and its SIC code is 7370.