TÜV AUSTRIA Group
TÜV TRUST IT is a DACH-focused cybersecurity and information security certification subsidiary of the TÜV AUSTRIA Group, providing BSI-accredited ISMS consulting, penetration testing, ISO/BSI certifications, eIDAS trust services, and proprietary Trusted* marks to enterprise clients in healthcare, automotive, energy, manufacturing, and financial services.
- Company typePrivate
- Founded1872
- HeadquartersCologne, Germany
- Headcount51–100
- GTM typeB2B
- OfferingServices
What TÜV AUSTRIA Group does
TÜV TRUST IT is the information security and cybersecurity services subsidiary of the TÜV AUSTRIA Group, a diversified Testing, Inspection and Certification (TIC) conglomerate founded in 1872 and a member of the TIC Council. The company provides consulting, accredited certification, and technical security services from offices in Cologne (German HQ), Brunn am Gebirge (Austrian HQ), Dresden, and via a Malaysian subsidiary (TÜV AUSTRIA Cybersecurity Lab Sdn Bhd), serving enterprise clients primarily in the DACH region across healthcare, automotive, energy, manufacturing, financial services, and digital identity.
Core offerings are organized around five service pillars: (1) Information Security Management Systems (ISMS) implementations against ISO 27001, BSI IT-Grundschutz, and emerging EU regimes (NIS-2, DORA); (2) Business Continuity Management (BCM/BCMS) per ISO 22301 and BSI 200-4; (3) Cyber Security including penetration testing, red teaming, SAP BTP and Microsoft 365 security audits, and social engineering; (4) Data Privacy & Compliance (EU-DSGVO, HinSchG, DiGAV); and (5) eIDAS & Trust Services for electronic identity and trust service providers. The company operates an accredited certification body and maintains a portfolio of 13+ registered proprietary 'Trusted*' certification marks (Trusted Application, Trusted App, Trusted Data Center, Trusted Service, Trusted Development, Trusted Infrastructure, Trusted IoT-Device, Trusted Usability, Trusted Privacy, Trusted Process, Trusted Web-Accessibility, Trusted Procedure, Approved IT-Service Quality). It is also a recognized BSI TR-03161 assessor for digital health applications.
Revenue is generated through project-based professional services engagements (consulting, certification audits, penetration testing) and a recurring training and certification program (ISMS Manager/Auditor, BCM Practitioner, BSI IT-Grundschutz Practitioner, NIS-2 executive training, eIDAS training). Go-to-market is sales-led with direct enterprise engagement, organized by vertical domain (ISMS, BCM, eIDAS, Cyber Security) and supplemented by thought-leadership channels including the weekly 'Cyber Tango' podcast, a recurring webinar program, industry event participation (DMEA, NIS-2 Congress, VKU Congress, AG KRITIS hearings), and direct customer references including Siemens, Bosch, Roche, SwissSign, Centogene, Johanniter, ALHO, and ReadID. The company is privately held as a wholly-owned subsidiary of the TÜV AUSTRIA Group with no external venture or private equity capital.
TÜV AUSTRIA Group firmographics
Firmographics- Name
- TÜV AUSTRIA Group
- Legal name
- TÜV TRUST IT GmbH Unternehmensgruppe TÜV AUSTRIA
- Website
- https://it-tuv.com
- Company type
- Private
- Founded year
- 1872
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- TÜV TRUST IT is a DACH-focused cybersecurity and information security certification subsidiary of the TÜV AUSTRIA Group, providing BSI-accredited ISMS consulting, penetration testing, ISO/BSI certifications, eIDAS trust services, and proprietary Trusted* marks to enterprise clients in healthcare, automotive, energy, manufacturing, and financial services.
- Ownership category
- akta.pro rank
TÜV AUSTRIA Group industry classification
Industry- Product category
- Testing, Inspection and Certification (TIC) Services
- NAICS
- Testing Laboratories and Services (541380)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Third-Party Certification, Code Compliance & Regulatory Inspection (ASME/API/ISO) (EUAEAHAN)
Keywords
Where TÜV AUSTRIA Group is headquartered
LocationHeadquarters
- HQ city
- Cologne
- HQ country
- Germany
- HQ region
- Europe
Offices3 records
Markets served
TÜV AUSTRIA Group business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Consulting Services: Professional consulting services for information security management systems (ISMS), business continuity management (BCM), technical security, and regulatory compliance (NIS-2, DORA, KRITIS). Revenue generated through project-based engagements with enterprise clients.
- Certification Services: Accredited certification services including ISO 27001 certification, BSI IT-Grundschutz assessments, TISAX assessments, and proprietary TÜV TRUST IT certification standards (Trusted App, Trusted Data Center, Trusted Development, Trusted IoT-Device).
- Training and Education: Professional training programs including certified ISMS Manager, ISMS Auditor, Risk Manager, BCM Practitioner, BSI IT-Grundschutz Practitioner, NIS-2 training, and eIDAS training. Offered as public courses and in-house training.
- Penetration Testing and Technical Security Services: Technical security testing services including penetration tests, red teaming, vulnerability scanning, web application security testing, SAP security testing, Microsoft 365 security audits, and social engineering assessments.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels7 records
TÜV AUSTRIA Group product offering
Product offeringCore offering
TÜV TRUST IT (operating as part of TÜV AUSTRIA Group) is an accredited Testing, Inspection and Certification (TIC) body providing information security consulting, certification, and penetration testing services to enterprise clients in the DACH region. Its core offerings cover ISMS implementation per ISO 27001 / BSI IT-Grundschutz, Business Continuity Management per ISO 22301, technical security testing, data privacy and GDPR compliance, eIDAS trust service certification, and proprietary in-house certification marks (Trusted App, Trusted Data Center, Trusted Development, Trusted IoT-Device).
Product overview
TÜV TRUST IT is a cybersecurity and information security services company operating as part of the TÜV AUSTRIA Group. The company offers a comprehensive portfolio of security services organized around five core pillars: (1) Information Security Management Systems (ISMS) covering implementation, operation, and certification according to ISO 27001 and BSI IT-Grundschutz; (2) Business Continuity Management (BCM) following ISO 22301 and BSI 200-4 standards; (3) Cyber Security services including penetration testing, red teaming, and technical security assessments; (4) Data Privacy & Compliance including EU-DSGVO and regulatory requirements; and (5) eIDAS & Trust Services for electronic identity and trust service provider certification. The company also maintains a proprietary 'Trusted' certification family including Trusted Application, Trusted App, Trusted Data Center, Trusted Service, Trusted Development, Trusted Infrastructure, Trusted IoT-Device, and Trusted Usability standards. Additionally, TÜV TRUST IT offers specialized consulting for NIS-2, DORA, Cyber Resilience Act (CRA), and AI Governance compliance, along with professional training programs and educational webcasts.
Differentiator
Problem solved
Functional benefit
Brands
- Trusted App: Certification standard for mobile applications ensuring data protection and information security.
- Trusted Data Center
- Trusted Application
- Trusted Development
- Trusted Infrastructure
- Trusted IoT-Device
- Trusted Usability
- Trusted Service
- Cyber Tango Podcast
Products and services
- ISMS Implementation & Operation (ISO 27001 / BSI IT-Grundschutz) Consulting for building, operating and transitioning Information Security Management Systems per ISO 27001 and BSI IT-Grundschutz, including gap analysis, Bebauungsplan, external ISB/CISO provisioning, and §8a BSI-Gesetz audit support for enterprise clients.
- Business Continuity Management Services BCMS consulting and managed services following BSI Standard 200-4 and ISO 22301, including gap analysis, crisis management, external BC manager outsourcing, compliance monitoring and documentation services for enterprise clients.
- Penetration Testing & Red Team Assessments Technical security testing including penetration tests, red teaming, vulnerability scans, phishing simulations, web application security scans, SAP penetration tests, SAP BTP assessments, Microsoft 365 security audits, agile cybersecurity quick-tests, and Assume Breach scenarios.
- Data Privacy & Compliance Services EU-DSGVO gap analysis, external data protection officer services, DiGAV support, and whistleblower protection (HinSchG) compliance services for organizations subject to EU data protection regulation.
- eIDAS & Trust Services Certification eIDAS 2 conformity assessment, examination and certification of electronic identification services (eID) and trust service providers (VDA), and consulting for users of electronic identity and trust services, including preparation for the European Digital Identity Wallet (EUDIW).
- NIS-2 Compliance Consulting Consulting services supporting compliance with the EU NIS-2 Directive, including relevance analysis, gap assessment, and implementation support, accompanied by executive training for management bodies.
- DORA Compliance Consulting Digital Operational Resilience Act consulting for financial-sector entities, addressing ICT risk management, third-party risk, and incident reporting requirements under EU regulation.
- CRA (Cyber Resilience Act) Consulting Consulting helping manufacturers of digital products meet new EU Cyber Resilience Act security requirements, including Common Criteria advisory support.
- AI / KI Governance Services AI governance services providing transparent evaluation of AI opportunities and risks, helping organizations deploy AI securely and in compliance with emerging regulation.
- TISAX Assessment & Certification Information security assessment and certification for the automotive industry under TISAX, including gap analysis and transition support to ISA 6.
- DiGA / DiPA Certification (BSI TR-03161) Certification services for digital health applications (DiGA) and digital nursing applications (DiPA) according to BSI TR-03161 requirements, mandatory under Section 139e SGB V for reimbursement approval.
- OT-Security / IEC 62443 Industrial Security Industrial security concept development and consulting aligned to IEC 62443 for operators of industrial / OT environments.
- SWIFT Assessment SWIFT Customer Security Controls Framework assessment services for financial-sector entities operating SWIFT infrastructure.
- Training & Certification Programs Professional training including certified ISMS Manager, ISMS Auditor, Risk Manager, BCM Practitioner, BSI IT-Grundschutz Practitioner, NIS-2 executive training for management bodies, eIDAS2 basic training, eIDAS ETSI special topics, and Prüfverfahrenskompetenz nach § 8a BSI-Gesetz. Delivered as scheduled public courses and custom in-house corporate training.
- TÜV TRUST IT Trusted Application Certification Proprietary in-house certification standard for IT applications assessing security architecture, data protection, and software development process compliance, with a variant specifically for applications on the SAP BTP platform.
- TÜV TRUST IT Trusted App Certification Proprietary in-house certification mark for mobile applications and Progressive Web Apps evaluating security features, privacy, and protection of sensitive information.
- TÜV TRUST IT Trusted Data Center Certification Proprietary in-house certification standard for data center facilities evaluating physical security, infrastructure, operational resilience, and compliance with security standards.
- TÜV TRUST IT Trusted Development Certification Proprietary in-house certification standard for software development processes ensuring secure development lifecycle compliance.
- TÜV TRUST IT Trusted IoT-Device Certification Proprietary in-house certification standard for IoT devices testing and certifying device security capabilities.
- TÜV TRUST IT Trusted Service Certification Proprietary in-house certification standard for IT services evaluating service quality, security controls, and operational excellence.
- TÜV TRUST IT Trusted Infrastructure Certification Proprietary in-house certification standard for network components and infrastructure evaluating security and reliability.
- TÜV TRUST IT Trusted Usability Certification Proprietary in-house certification standard for IT product usability and accessibility.
Quantifiable outcome
- Many customer relationships lasting over a decade, demonstrating sustained trust and value delivery.
Companies that use TÜV AUSTRIA Group
Customer profileNamed customers15 records
Segments5 records
Ideal customer profiles5 records
TÜV AUSTRIA Group technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature6 records
TÜV AUSTRIA Group partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and minor.
- G DATA CyberDefense AGcoreJoint project launched June 2025 for implementing Cyber Resilience Act (CRA) regulatory requirements. The collaboration combines G DATA's cybersecurity expertise with TÜV TRUST IT's certification and assessment capabilities to provide comprehensive CRA compliance services. Project focuses on cyber resilience and quality management.
- ciphroncoreStrategic partnership announced April 2026 (anticipated) where TÜV TRUST IT and ciphron are combining their activities to create a stronger cybersecurity offering. This represents a significant business combination aimed at expanding capabilities and market presence in the DACH region.
- POTTHOFF + PARTNERcoreLong-standing client relationship where TÜV TRUST IT provides annual re-certification services for the 'KOS | ME' patient portal. The healthcare IT provider develops hospital software and digital patient solutions deployed in over 170 hospitals across the DACH region.
- SwissSigncoreTrust services customer holding multiple certificate authorities including SwissSign Gold CA-G2, SwissSign RSA SMIME Root CA, and SwissSign RSA TLS Root CA certificates certified by TÜV TRUST IT.
- Signal Iduna GruppeminorCertificate holder for Trusted Privacy certification issued by TÜV TRUST IT.
Scale indicators2 records
Recent moves6 records
Expansion highlights6 records
TÜV AUSTRIA Group competitors and assessment
Company assessmentMarket position
Strengths5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
TÜV AUSTRIA Group social profiles
Digital presenceTÜV AUSTRIA Group compliance and trust
Trust signalCompliance9 records
TÜV AUSTRIA Group financial estimates
Financial estimateRevenue estimate
Valuation estimate
TÜV AUSTRIA Group leadership team
Management profileNumber of profiles
Profiles9 records
TÜV AUSTRIA Group subsidiaries and ownership
Company hierarchySubsidiaries1 record
TÜV AUSTRIA Group funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
TÜV AUSTRIA Group M&A and investment
M&A and investmentM&A2 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about TÜV AUSTRIA Group
What does TÜV AUSTRIA Group do?
TÜV TRUST IT (operating as part of TÜV AUSTRIA Group) is an accredited Testing, Inspection and Certification (TIC) body providing information security consulting, certification, and penetration testing services to enterprise clients in the DACH region. Its core offerings cover ISMS implementation per ISO 27001 / BSI IT-Grundschutz, Business Continuity Management per ISO 22301, technical security testing, data privacy and GDPR compliance, eIDAS trust service certification, and proprietary in-house certification marks (Trusted App, Trusted Data Center, Trusted Development, Trusted IoT-Device).
Is TÜV AUSTRIA Group a public or private company?
TÜV AUSTRIA Group is a private company. It is classified as corporate owned and is currently operating.
When was TÜV AUSTRIA Group founded?
TÜV AUSTRIA Group was founded in 1872. It employs 51 to 100 people.
Where is TÜV AUSTRIA Group based?
TÜV AUSTRIA Group is headquartered in Cologne, Germany, in the Europe region.
How does TÜV AUSTRIA Group make money?
Four revenue lines are on record. Consulting Services are the primary driver. The others are certification Services, training and Education and penetration Testing and Technical Security Services.
Does TÜV AUSTRIA Group have an API?
No public API is recorded for TÜV AUSTRIA Group.
What industry is TÜV AUSTRIA Group in?
TÜV AUSTRIA Group's product category is Testing, Inspection and Certification (TIC) Services. Its primary akta.pro industry code is EUAEAHAN, Third-Party Certification, Code Compliance & Regulatory Inspection (ASME/API/ISO). Its NAICS code is 541380 and its SIC code is 8734.