CSOC
CSOC (Certified Security Operations Center GmbH) is a German managed security services provider offering 24/7 SOC monitoring, MDR, vulnerability management, DFIR, and OT/ICS security to mid-to-large European enterprises requiring NIS2/DORA-compliant, EU-sovereign cybersecurity.
- Company typePrivate
- Founded2020
- HeadquartersBornheim, Germany
- Headcount11–50
- GTM typeB2B
- OfferingServices
What CSOC does
CSOC (Certified Security Operations Center GmbH) is a German managed security services provider headquartered in Bornheim, Germany (Adenauerallee 45-49, 53332). The company delivers 24/7 cybersecurity services built around three operational pillars — PROTECT (proactive hardening), DETECT (continuous monitoring and anomaly identification), and RESPOND (automated and analyst-led incident response). Its portfolio centers on Managed Detection and Response (MDR) supported by a Security Operations Center staffed by certified analysts, with add-on modules covering vulnerability management, digital forensics and incident response (DFIR), and specialized OT/ICS security for industrial environments.
The platform is differentiated by proprietary AI components — SIREN (Search for IRregular Events in your Network) for real-time network anomaly detection and ISA (Intelligent Security Analysis) for event correlation and analyst augmentation — alongside an "Active Response" capability that isolates affected systems within seconds of threat detection, before human intervention is required. CSOC emphasizes an open-source technology stack, EU-exclusive data processing (no third-country access, including protection from the US CLOUD Act), and alignment with NIS2, DORA, and GDPR requirements. The company holds DIN EN ISO/IEC 27001 and ISAE 3402 (Certificate 5545_2025) certifications, holds CompTIA CySA+ and Security+ staff certifications, and is authorized under § 21 Abs. 5 Satz 1 (KHSFV) for hospital cybersecurity work; in April 2026 it announced a strategic partnership with PHYSEC GmbH to extend into cyber-physical OT security.
CSOC operates a subscription-based, recurring managed services revenue model with annual billing and custom-configured packages selected through an online Security Configurator on its website. Its go-to-market is sales-led, combining a self-service configuration tool (top-of-funnel) with direct consultative sales (bottom-of-funnel) targeting mid-to-large European enterprises — particularly organizations with regulatory exposure under NIS2/DORA or those lacking in-house 24/7 security operations. Leadership is held by Managing Directors Joerg Lammerich and Dr. Jürgen Kohr, supported by functional heads across sales, customer management, internationalization, operations, and technology; the company is privately held as a GmbH with no disclosed external investors or funding history.
CSOC firmographics
Firmographics- Name
- CSOC
- Legal name
- Certified Security Operations Center GmbH
- Website
- https://csoc.de
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CSOC (Certified Security Operations Center GmbH) is a German managed security services provider offering 24/7 SOC monitoring, MDR, vulnerability management, DFIR, and OT/ICS security to mid-to-large European enterprises requiring NIS2/DORA-compliant, EU-sovereign cybersecurity.
- Ownership category
- akta.pro rank
CSOC industry classification
Industry- Product category
- Managed Security Services
- NAICS
- Computer Facilities Management Services (541513)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
- akta.pro secondary industry
- Managed Detection & Response (MDR) (BPAEADAA)
Keywords
Where CSOC is headquartered
LocationHeadquarters
- HQ city
- Bornheim
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
CSOC business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Security Services: Recurring managed security services including 24/7 SOC monitoring, MDR, vulnerability management, and incident response. Services are delivered as managed subscriptions with continuous monitoring and support.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Custom configurable security packages |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels2 records
CSOC product offering
Product offeringCore offering
CSOC delivers managed cybersecurity services centered on a 24/7 Security Operations Center, combining continuous monitoring, AI-assisted threat detection, and incident response for European enterprises. The portfolio covers MDR, vulnerability management, DFIR, and OT/ICS security, built on an open-source technology stack with data processed exclusively within EU data centers. Customers can configure individual service packages via an online configurator and receive annual subscriptions for managed delivery.
Product overview
CSOC (Certified Security Operations Center GmbH) offers a unified cybersecurity platform built around three core pillars: PROTECT (proactive security measures), DETECT (continuous threat monitoring), and RESPOND (automated and manual incident response). The portfolio centers on Managed Detection & Response (MDR) as the primary service, supported by a 24/7 Security Operations Center staffed by certified analysts. AI capabilities are delivered through two proprietary tools: SIREN for real-time network anomaly detection and ISA for intelligent security analysis. Additional modules include Vulnerability Management, Incident Response & DFIR, and specialized OT/ICS Security. The service emphasizes European data sovereignty, open-source transparency, and compliance with NIS2 and DORA regulations.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Detection & Response (MDR) 24/7 threat detection and automated response service that combines continuous monitoring, automated containment, and human analyst investigation to protect enterprise IT infrastructure from cyber attacks.
- Security Operations Center (SOC) Round-the-clock monitoring service staffed by certified security analysts who collect, prioritize, and analyze security events from client environments, with defined escalation and response procedures.
- Vulnerability Management (Schwachstellenmanagement) Continuous vulnerability scanning service that identifies weaknesses in client systems and provides prioritized remediation recommendations based on actual risk assessment.
- Incident Response & DFIR Digital forensics and incident response service that rapidly contains security incidents, performs forensic analysis, restores secure operations, and provides recommendations to prevent recurrence.
- OT/ICS Security Specialized security monitoring service for operational technology and industrial control systems, designed to protect production and control environments without disrupting ongoing operations.
Companies that use CSOC
Customer profileSegments1 record
Ideal customer profiles1 record
CSOC technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature3 records
CSOC partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- PHYSEC GmbHcoreCSOC and PHYSEC announced a strategic partnership to holistically address cyber-physical security in OT environments for the first time in an integrated operations model. PHYSEC brings expertise in physical security and operational technology, while CSOC contributes its SOC capabilities and intelligent analysis platforms. The cooperation enables comprehensive protection of IT and OT environments through a single integrated provider.
Scale indicators2 records
Recent moves5 records
Expansion highlights5 records
CSOC competitors and assessment
Company assessmentBroad incumbents
- Deutsche Telekom Security: Large German telecom-owned security services provider offering managed SOC, MDR, and compliance services to enterprises. Comparable in German market focus and regulated customer base, but with substantially broader portfolio and scale.
- Sophos (Sophos MDR): Global cybersecurity vendor with a dedicated 24/7 MDR service line and acquired Secureworks. Comparable MDR offering but part of a much broader endpoint and network security portfolio.
- CrowdStrike (Falcon Complete MDR): Global endpoint and cloud security leader with its own managed detection and response service (Falcon Complete). Overlaps with CSOC on MDR/SOC delivery but is part of a much broader security platform portfolio.
Direct peers
- Secureworks: Global MSSP/MDR provider offering 24/7 SOC, threat detection, and incident response, now part of Sophos. Comparable in subscription-based MDR delivery and mid-to-large enterprise customer focus.
- Trustwave: Global MSSP offering managed SOC, MDR, vulnerability management, and DFIR services. Comparable in service breadth (PROTECT/DETECT/RESPOND structure) and enterprise customer targeting.
- Arctic Wolf: Leading pure-play MDR provider offering 24/7 SOC-as-a-service with security operations platform. Direct competitor in the MDR space targeting mid-market and enterprise customers with subscription-based managed security services.
- Withsecure (formerly F-Secure): Finnish-headquartered cybersecurity company with a dedicated MDR/SOC business and strong European presence. Comparable in European positioning, mid-market enterprise targeting, and recurring service model.
- Expel: US-based MDR provider delivering transparent, 24/7 managed detection and response with a focus on cloud and SaaS environments. Comparable in subscription MDR delivery model and mid-to-large enterprise target market.
- eSentire: Pure-play MDR provider offering 24/7 SOC, threat hunting, and incident response services to mid-market and enterprise customers. Closely comparable service model and customer segment to CSOC.
- Orange Cyberdefense: European-headquartered MSSP/MDR provider offering 24/7 SOC, threat detection, and incident response across multiple countries. Directly comparable to CSOC in service portfolio, European focus, and regulated-customer orientation, but at significantly larger scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
CSOC social profiles
Digital presenceCSOC compliance and trust
Trust signalCompliance5 records
CSOC financial estimates
Financial estimateRevenue estimate
Valuation estimate
CSOC leadership team
Management profileNumber of profiles
Profiles7 records
CSOC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CSOC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CSOC
What does CSOC do?
CSOC delivers managed cybersecurity services centered on a 24/7 Security Operations Center, combining continuous monitoring, AI-assisted threat detection, and incident response for European enterprises. The portfolio covers MDR, vulnerability management, DFIR, and OT/ICS security, built on an open-source technology stack with data processed exclusively within EU data centers. Customers can configure individual service packages via an online configurator and receive annual subscriptions for managed delivery.
Is CSOC a public or private company?
CSOC is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was CSOC founded?
CSOC was founded in 2020. It employs 11 to 50 people.
Where is CSOC based?
CSOC is headquartered in Bornheim, Germany, in the Europe region.
How does CSOC make money?
One revenue line is on record: managed Security Services.
Who are CSOC's main competitors?
Broad incumbents on record are Deutsche Telekom Security, Sophos (Sophos MDR) and CrowdStrike (Falcon Complete MDR). Direct peers are Secureworks, Trustwave, Arctic Wolf, Withsecure (formerly F-Secure), Expel, eSentire and Orange Cyberdefense.
Does CSOC have an API?
No public API is recorded for CSOC.
What industry is CSOC in?
CSOC's product category is Managed Security Services. Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services, with a secondary code of BPAEADAA, Managed Detection & Response (MDR). Its NAICS code is 541513 and its SIC code is 7370.