ICS-CERT
CISA's ICS-CERT is the U.S. federal industrial control systems cybersecurity division within DHS that coordinates critical infrastructure protection across 16 sectors, providing no-cost incident response, vulnerability advisories, threat intelligence, and coordinated cyber defense to government, industry, and the public.
- Company typePrivate
- Founded2018
- HeadquartersWashington, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What ICS-CERT does
ICS-CERT is the Industrial Control Systems Cyber Emergency Response Team, operating as a division within the Cybersecurity and Infrastructure Security Agency (CISA), itself part of the U.S. Department of Homeland Security. Its functional mandate is to reduce the cybersecurity risk to U.S. industrial control systems and the 16 designated critical infrastructure sectors by serving as a national coordination point for industrial cybersecurity. The agency was established under the Cybersecurity Act of 2015 and CISA itself was stood up in November 2018; it is organized around 10 regional offices covering all 50 states and territories. The core service offering is delivered at no cost to recipients and includes incident response, vulnerability advisories (such as the ICS-CERT Advisory series), threat intelligence alerts, coordinated disclosure support, and a portfolio of free cybersecurity services and tools — including open-source defensive tools hosted on a CISA GitHub presence.
The product portfolio spans ICS-specific advisories, ransomware defense resources (StopRansomware.gov), the Joint Cyber Defense Collaborative (JCDC) platform, the SAFECOM government emergency communications program, the K-12 school security suite, and the developing CIRCIA cyber incident reporting framework. Technical components primarily take the form of written guidance, alert bulletins, binding operational directives (e.g., BOD 26-04 on risk-based vulnerability remediation), and downloadable tooling rather than a single integrated commercial platform. The business model is non-commercial: ICS-CERT is funded through congressional appropriations to DHS/CISA, with no pricing model, no go-to-market function, and no revenue-generation mechanism in the private-sector sense. Its customer base spans federal, state, local, tribal, and territorial governments; owners and operators across 16 critical infrastructure sectors; educational institutions; small businesses; executives; and the general public — including high-risk communities and families.
ICS-CERT firmographics
Firmographics- Name
- ICS-CERT
- Legal name
- Cybersecurity and Infrastructure Security Agency
- Website
- https://us-cert.cisa.gov
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CISA's ICS-CERT is the U.S. federal industrial control systems cybersecurity division within DHS that coordinates critical infrastructure protection across 16 sectors, providing no-cost incident response, vulnerability advisories, threat intelligence, and coordinated cyber defense to government, industry, and the public.
- Ownership category
- akta.pro rank
ICS-CERT industry classification
Industry- Product category
- Government Cybersecurity Services
- NAICS
- National Security (928110), Regulation and Administration of Communications, Electric, Gas, and Other Utilities (92613)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Industrial Control System (ICS) & SCADA Security (HDADAJAA)
- akta.pro secondary industries
- Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC), OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN), Grid Cyber Risk Management, Governance, Compliance & Audit (NERC CIP/IEC 62443) (EUADANAC), Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
Keywords
Where ICS-CERT is headquartered
LocationHeadquarters
- HQ city
- Washington
- HQ country
- United States
- HQ region
- North America
Markets served
ICS-CERT business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales
Distribution channels4 records
Marketing channels7 records
ICS-CERT product offering
Product offeringCore offering
ICS-CERT operates as a division of the Cybersecurity and Infrastructure Security Agency (CISA), publishing Industrial Control Systems advisories that provide vulnerability alerts, mitigation guidance, and threat intelligence for control systems and operational technology. It coordinates incident response across U.S. critical infrastructure sectors, issues Binding Operational Directives to federal agencies, and operates programs including StopRansomware.gov, the Joint Cyber Defense Collaborative (JCDC), SAFECOM, CIRCIA, and free cybersecurity services and tools—all delivered at no cost.
Product overview
CISA (Cybersecurity and Infrastructure Security Agency), including its ICS-CERT division, operates as a federal government agency providing a comprehensive portfolio of cybersecurity and critical infrastructure protection services. The offering is structured as a platform of interconnected programs rather than a commercial product suite. Core offerings include ICS-CERT Advisories for industrial control system vulnerability management, StopRansomware.gov for ransomware defense resources, the Joint Cyber Defense Collaborative (JCDC) for coordinated cyber defense, SAFECOM for emergency communications, the Services Catalog for technical assistance and assessments, K-12 School Security Product Suite for educational institutions, and CIRCIA for incident reporting compliance. The agency also provides free cybersecurity tools, Zero Trust Architecture guidance, and Secure by Design initiatives—all offered at no cost as part of federal critical infrastructure protection mission.
Differentiator
Problem solved
Functional benefit
Products and services
- ICS-CERT Advisories Industrial Control Systems Computer Emergency Readiness Team advisories providing vulnerability alerts, mitigation guidance, and threat intelligence for control systems and operational technology, targeted at critical infrastructure owners and operators.
- StopRansomware.gov U.S. Government's official centralized resource hub providing ransomware guidance, prevention tips, response procedures, and reporting mechanisms for organizations and individuals.
- Joint Cyber Defense Collaborative (JCDC) Unified collaboration platform that gathers, analyzes, and shares actionable cyber risk information to enable synchronized cybersecurity planning, cyber defense, and response across organizations worldwide.
- SAFECOM Emergency communications interoperability program that works to improve communications across local, regional, tribal, state, territorial, and international borders with federal government entities.
- CISA Services Catalog Centralized resource providing access to CISA services including technical assistance, cybersecurity assessments, exercises, and free training across all mission areas.
- K-12 School Security Product Suite Comprehensive cybersecurity guidance and resources specifically designed to help K-12 educational institutions protect against cyber threats and protect student data.
- Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Rulemaking and reporting framework requiring critical infrastructure entities to report cyber incidents to CISA, including virtual town halls for stakeholder engagement on implementation.
- Free Cybersecurity Services and Tools No-cost cybersecurity services including assessments, scanning tools, and protective services available to organizations across all critical infrastructure sectors.
Quantifiable outcome
- CISA issues Binding Operational Directives that require federal agencies to remediate high-risk vulnerabilities within prescribed timeframes
- +1 more outcomes
Companies that use ICS-CERT
Customer profileSegments8 records
Ideal customer profiles5 records
ICS-CERT technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
ICS-CERT partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Joint Cyber Defense Collaborative (JCDC)coreJCDC unifies cyber defenders from organizations worldwide. This team proactively gathers, analyzes, and shares actionable cyber risk information to enable synchronized, holistic cybersecurity planning, cyber defense, and response. CISA has expanded JCDC to include industrial control systems stakeholders, integrating private sector and government partners for coordinated defense against cyber threats to critical infrastructure.
Scale indicators1 record
Recent moves6 records
Expansion highlights5 records
ICS-CERT competitors and assessment
Company assessmentRegional players
- Australian Cyber Security Centre (ACSC): The Australian Signals Directorate's public-facing cyber authority, providing threat intelligence, incident response, and the Essential Eight maturity model for critical infrastructure. It is comparable because it is a Five Eyes partner that co-issues advisories with CISA and operates a national CERT-style coordination function.
- European Union Agency for Cybersecurity (ENISA): ENISA is the EU agency dedicated to achieving a high common level of cybersecurity across member states, supporting incident response, certification, and cooperation. It is comparable because it is the EU counterpart to CISA, coordinating cross-border cyber defense and working with national CSIRTs on critical infrastructure protection.
- UK National Cyber Security Centre (NCSC): The UK's national technical authority for cyber incidents, providing advice, incident response, and threat intelligence to government and critical infrastructure. It is comparable because it performs the same national coordinator role in the UK, jointly issues Five Eyes advisories with CISA, and operates a CERT-style incident response function.
Direct peers
- Transportation Security Administration (TSA) Cybersecurity Division: The TSA issues binding cybersecurity directives to passenger and freight rail, pipeline, and aviation operators and coordinates with CISA on critical infrastructure cyber risk. It is comparable because it is a fellow sector risk management agency with overlapping authority, particularly on pipelines where TSA Security Directives intersect with CISA's ICS advisories.
- Carnegie Mellon University Software Engineering Institute CERT Division: A federally funded research and development center that operates the original CERT/CC, providing vulnerability analysis, coordinated disclosure, and incident response support. It is comparable because it is the historical model for the CERT concept that ICS-CERT itself follows, and operates the public-private partnership model CISA relies on.
- DOE Office of Cybersecurity, Energy Security, and Emergency Response (CESER): A U.S. Department of Energy office that leads cybersecurity for the energy sector, including grid and pipeline infrastructure. It is directly comparable because it operates as a sector risk management agency with overlapping ICS/SCADA security, NERC CIP coordination, and OT incident response responsibilities alongside CISA.
Broad incumbents
- National Security Agency (NSA) Cybersecurity Directorate: A U.S. federal agency under the Department of Defense that operates the nation's signals intelligence and cybersecurity mission, including defense of national security systems and cryptography. It is directly comparable because it shares government cybersecurity responsibilities and collaborates with CISA on adversary pursuit and threat intelligence sharing.
- U.S. Cyber Command (USCYBERCOM): A unified combatant command under the Department of Defense responsible for defending national interests in cyberspace through offensive and defensive operations. It is comparable because it shares national cyber mission responsibilities with CISA and jointly conducts adversary disruption and threat intelligence activities.
- National Institute of Standards and Technology (NIST): A U.S. federal agency within the Department of Commerce that develops cybersecurity standards, guidelines (including the CSF), and the NICE workforce framework. It is comparable because it co-develops the technical foundation (e.g., NERC CIP-related standards, ICS guidance) that CISA operationalizes and disseminates to operators.
- Federal Bureau of Investigation (FBI) Cyber Division: The FBI's Cyber Division leads domestic cyber investigations, intelligence collection, and attribution for nation-state and criminal cyber actors. It is comparable because it is a primary federal partner that co-coordinates with CISA on incident response, ransomware disruption, and critical infrastructure threat advisories.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks1 record
Key highlights1 record
Customer concentration
ICS-CERT social profiles
Digital presenceICS-CERT financial estimates
Financial estimateRevenue estimate
Valuation estimate
ICS-CERT leadership team
Management profileNumber of profiles
ICS-CERT funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ICS-CERT M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ICS-CERT
What does ICS-CERT do?
ICS-CERT operates as a division of the Cybersecurity and Infrastructure Security Agency (CISA), publishing Industrial Control Systems advisories that provide vulnerability alerts, mitigation guidance, and threat intelligence for control systems and operational technology. It coordinates incident response across U.S. critical infrastructure sectors, issues Binding Operational Directives to federal agencies, and operates programs including StopRansomware.gov, the Joint Cyber Defense Collaborative (JCDC), SAFECOM, CIRCIA, and free cybersecurity services and tools—all delivered at no cost.
Is ICS-CERT a public or private company?
ICS-CERT is a private company. It is classified as state government owned and is currently operating.
When was ICS-CERT founded?
ICS-CERT was founded in 2018. It employs 11 to 50 people.
Where is ICS-CERT based?
ICS-CERT is headquartered in Washington, United States, in the North America region.
Who are ICS-CERT's main competitors?
Regional players on record are Australian Cyber Security Centre (ACSC), European Union Agency for Cybersecurity (ENISA) and UK National Cyber Security Centre (NCSC). Direct peers are Transportation Security Administration (TSA) Cybersecurity Division, Carnegie Mellon University Software Engineering Institute CERT Division and DOE Office of Cybersecurity, Energy Security, and Emergency Response (CESER). Broad incumbents are National Security Agency (NSA) Cybersecurity Directorate, U.S. Cyber Command (USCYBERCOM), National Institute of Standards and Technology (NIST) and Federal Bureau of Investigation (FBI) Cyber Division.
Does ICS-CERT have an API?
No public API is recorded for ICS-CERT.
What industry is ICS-CERT in?
ICS-CERT's product category is Government Cybersecurity Services. Its primary akta.pro industry code is HDADAJAA, Industrial Control System (ICS) & SCADA Security, with a secondary code of HDADAJAC, Critical Infrastructure Protection (CIP) & NERC-CIP Compliance. Its NAICS code is 928110 and its SIC code is 7370.