CERT EU
CERT-EU is the inter-institutional cybersecurity service provider for all EU institutions, bodies, offices and agencies, delivering SOC services, incident response, cyber threat intelligence, and Red Team testing to 90+ constituent entities from its base in Brussels, funded by the EU budget and mandated by Regulation (EU) 2023/2841.
- Company typePrivate
- Founded2011
- HeadquartersBrussels, Belgium
- Headcount11–50
- GTM typeB2B
- OfferingServices
What CERT EU does
CERT-EU (Computer Emergency Response Team for the European Union) is the inter-institutional cybersecurity service provider for all EU institutions, bodies, offices and agencies. Founded in 2011 and administratively hosted within the European Commission's Directorate-General for Digital Services, it is governed by the Interinstitutional Cybersecurity Board (IICB), which was established in 2024 under Regulation (EU, Euratom) 2023/2841 and is chaired by the European Parliament. CERT-EU's stated mandate is to help constituents prevent, detect, handle, mitigate, respond to, and recover from cyber attacks, while acting as the cybersecurity information exchange and incident response coordination hub across the Union.
Its service portfolio spans three functional pillars: a Forensics and Operational Response (Blue Team) function delivering specialised SOC services and continuous threat monitoring and hunting; a Cyber Threat Intelligence capability that monitors, merges, analyses and contextualises threat information and publishes monthly Cyber Briefs, quarterly and yearly Threat Landscape Reports, and a Cyber Threat Intelligence Framework; and an Offensive Security (Red Team) function offering vulnerability assessments, phishing exercises, penetration tests, and Red Team engagements. Supporting tools include proprietary publications (security advisories, security guidance) and internally developed tooling such as the Morio observability data backbone (2024) and the droid Sigma detection rule management tool (2024). In 2025 the team tracked 174 threat actors and responded to nine significant incidents.
CERT-EU is funded directly by the EU budget and delivers all services free of charge to its 90+ constituent entities. It has no commercial customers, no pricing model, and no external shareholders. It earns no commercial revenue and is therefore not assessable on conventional revenue metrics. It is embedded in the global CSIRT ecosystem through membership in the CSIRTs Network, European Government CSIRTs Group (EGC), FIRST, and Trusted Introducer, structured cooperation with ENISA, and a 2016 technical agreement with the NATO Cyber Security Centre for information exchange.
CERT EU firmographics
Firmographics- Name
- CERT EU
- Legal name
- CERT-EU
- Website
- https://cert.europa.eu
- Company type
- Private
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CERT-EU is the inter-institutional cybersecurity service provider for all EU institutions, bodies, offices and agencies, delivering SOC services, incident response, cyber threat intelligence, and Red Team testing to 90+ constituent entities from its base in Brussels, funded by the EU budget and mandated by Regulation (EU) 2023/2841.
- Ownership category
- akta.pro rank
CERT EU industry classification
Industry- Product category
- Government Cybersecurity Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Investigation and Security Services (5616), Police Protection (92212)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
- akta.pro secondary industries
- Data Protection, Privacy & Cybersecurity Regulators (BPAIAOAH), Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG), Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC)
Keywords
Where CERT EU is headquartered
LocationHeadquarters
- HQ city
- Brussels
- HQ country
- Belgium
- HQ region
- Europe
Offices1 record
Markets served
CERT EU business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Others
Revenue model
- Government-funded cybersecurity services: CERT-EU is administratively hosted within the Directorate-General for Digital Services of the European Commission. As an inter-institutional service provider, it is funded by the EU budget rather than generating commercial revenue. Services are provided free of charge to Union entities.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels9 records
CERT EU product offering
Product offeringCore offering
CERT-EU is the inter-institutional cybersecurity service provider for the European Union's institutions, bodies, offices and agencies. It helps its constituents prevent, detect, handle, mitigate, respond and recover from cybersecurity incidents, and acts as the cybersecurity information exchange and incident response coordination hub for Union entities. Service lines span SOC-based threat monitoring and hunting, cyber threat intelligence, Red Team and phishing exercises, vulnerability assessments, security advisories and guidance, and a coordinated vulnerability disclosure programme.
Product overview
CERT-EU is the interinstitutional cybersecurity service provider for EU institutions, bodies, offices and agencies, offering a unified cybersecurity service portfolio. The core offerings include Security Advisories (focused on major vulnerabilities with actionable recommendations), Security Guidance Documents (pragmatic recommendations on cybersecurity topics), and Threat Intelligence Products (including Cyber Briefs as monthly executive reports and Threat Landscape Reports as quarterly and yearly comprehensive reports). Additionally, CERT-EU provides Incident Response and Coordination services through its Blue Team, Red Team/Offensive Security Services for penetration testing and vulnerability assessments, and Coordinated Vulnerability Disclosure Policy coordination with recognition through Hall of Fame. The Cyber Threat Intelligence Framework was launched in 2026 as a shared reference to classify and assess threats. All services are delivered from Brussels, Belgium, serving over 90 constituent entities.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Advisories Advisories on major vulnerabilities providing actionable technical recommendations to help Union entities patch and mitigate exposures and prevent breaches and compromises.
- Security Guidance Documents White papers and security guidance providing clear, pragmatic recommendations on cybersecurity topics of interest to Union constituents.
- Cyber Briefs Monthly executive cyber threat intelligence reports summarising the most relevant cybersecurity developments for political leadership and senior management in the EU constituency.
- Threat Landscape Reports Quarterly and yearly reports providing comprehensive situational awareness of the cyber threat landscape targeting EU institutions, bodies and agencies.
- Cyber Threat Intelligence Framework A shared reference framework for classifying, assessing and prioritising malicious cyber activity affecting Union entities and their ecosystem.
- Incident Response and Coordination (SOC Services) Forensics and Operational Response services delivering specialised SOC capabilities, continuous threat monitoring and hunting, and incident support and coordination for Union entities.
- Red Team / Offensive Security Services Ethical hacking services including vulnerability assessments, customised penetration tests, and phishing and Red Team exercises to test and harden the infrastructure of Union constituents.
- Cyber Threat Intelligence Services CTI analysts monitoring, merging, analysing and contextualising threat information from multiple sources, with regular and ad hoc reporting to support constituents against a wide variety of adversaries.
- Coordinated Vulnerability Disclosure Programme A coordinated vulnerability disclosure programme enabling security researchers to report vulnerabilities discovered in constituent systems, supported by a Hall of Fame recognition programme.
- Morio Observability Solution An end-to-end streaming data backbone designed to meet observability needs, developed and released by CERT-EU.
- droid (Sigma Detection Rule Management Tool) A tool designed to enhance the management of Sigma-based detection rules, announced at the 36th annual FIRST conference.
Quantifiable outcome
- Tracked 174 threat actors and responded to nine significant incidents in 2025
- +1 more outcomes
Companies that use CERT EU
Customer profileNamed customers3 records
Segments1 record
Ideal customer profiles1 record
CERT EU technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
CERT EU partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered major and core.
- NATO Cyber Security Centre (NCSC)majorTechnical agreement signed with the NATO Cyber Security Centre (formerly NATO Computer Incident Response Capability/NCIRC) to exchange cybersecurity information. This partnership facilitates cross-organizational threat intelligence sharing between the EU and NATO.
- CSIRTs Network (CNW)coreMember of the CSIRTs Network (CNW), an EU-wide network of Computer Security Incident Response Teams that facilitates cooperation and information sharing on cybersecurity incidents affecting Union institutions.
- European Government CSIRTs Group (EGC)coreMember of the European Government CSIRTs Group, a forum for European government CSIRTs to cooperate on cybersecurity matters.
- FIRST (Forum of Incident Response and Security Teams)coreMember of FIRST, the global forum for incident response teams that promotes coordination and information sharing among cybersecurity professionals worldwide.
- Trusted IntroducercoreMember of Trusted Introducer, a service that provides verified contact information and facilitates cooperation among European CSIRTs and security response teams.
- ENISA (EU Agency for Cybersecurity)coreStructured cooperation with ENISA, the EU Agency for Cybersecurity. Joint publications include cybersecurity mitigation measures against critical threats and coordinated vulnerability disclosure guidance. Works closely on threat intelligence and cyber exercises.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
CERT EU competitors and assessment
Company assessmentDirect peers
- BSI (Bundesamt für Sicherheit in der Informationstechnik, Germany): Germany's federal cybersecurity authority, providing SOC-style monitoring, incident response, CTI and standards to federal entities and critical infrastructure. Directly comparable in scope, regulatory mandate and services offered to a national government ecosystem.
- ENISA (European Union Agency for Cybersecurity): ENISA is the EU Agency for Cybersecurity with which CERT-EU has structured cooperation. Both serve EU-level cybersecurity needs, share intelligence, co-author guidance (e.g. on critical threats, coordinated vulnerability disclosure), and participate in joint exercises like Cyber Europe.
- NATO Cyber Security Centre (NCSC): NATO's central cyber defence hub, with which CERT-EU signed a 2016 technical agreement for cybersecurity information exchange. Operates a similar SOC, incident response and threat intelligence mandate for NATO bodies, making it a structurally comparable counterpart.
- ANSSI (Agence nationale de la sécurité des systèmes d'information, France): France's national cybersecurity authority, providing detection, response, CTI and guidance to French government entities and critical operators. Peer to CERT-EU as a national-level CERT/CSIRT with a comparable services portfolio and a strong regulatory role.
- CSIRTs Network (CNW): EU-wide network of CSIRTs in which CERT-EU is an active member. Operationally and structurally comparable as a peer collaboration that CERT-EU both participates in and coordinates with — effectively the institutional 'peer set' CERT-EU belongs to.
- NCSC UK (National Cyber Security Centre, United Kingdom): UK's national CERT and authoritative cyber-defence body. Highly comparable in mandate (protect government, provide CTI, incident response, guidance), organisational design, and tooling approach — the closest national-level analogue to CERT-EU.
- CCDCOE (NATO Cooperative Cyber Defence Centre of Excellence): NATO-accredited cyber defence hub hosting the Locked Shields exercise, in which CERT-EU regularly participates. Comparable as a multi-national cyber defence collaboration, research and training counterpart focused on advanced threats.
Broad incumbents
- FIRST (Forum of Incident Response and Security Teams): Global forum of incident response and security teams; CERT-EU is a member. Functions as a global peer/standards body for CERT-type organisations, sharing best practices, indicators of compromise and operational coordination across national CSIRTs.
- CISA (Cybersecurity and Infrastructure Security Agency, United States): US federal lead for civilian government cyber defence and critical infrastructure protection. Broader in scope than CERT-EU (covers critical infrastructure nationally) but operates an analogous SOC, incident response, vulnerability management and CTI portfolio for US federal agencies.
Regional players
- NCSC-NL (National Cyber Security Centre, Netherlands): Netherlands' national CERT/CSIRT, a co-member with CERT-EU of the CSIRTs Network and EGC. Comparable mandate at member-state level: SOC, incident response, threat intelligence and guidance for Dutch government and vital sectors.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
CERT EU social profiles
Digital presenceCERT EU financial estimates
Financial estimateRevenue estimate
Valuation estimate
CERT EU leadership team
Management profileNumber of profiles
CERT EU funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CERT EU M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CERT EU
What does CERT EU do?
CERT-EU is the inter-institutional cybersecurity service provider for the European Union's institutions, bodies, offices and agencies. It helps its constituents prevent, detect, handle, mitigate, respond and recover from cybersecurity incidents, and acts as the cybersecurity information exchange and incident response coordination hub for Union entities. Service lines span SOC-based threat monitoring and hunting, cyber threat intelligence, Red Team and phishing exercises, vulnerability assessments, security advisories and guidance, and a coordinated vulnerability disclosure programme.
Is CERT EU a public or private company?
CERT EU is a private company. It is classified as state government owned and is currently operating.
When was CERT EU founded?
CERT EU was founded in 2011. It employs 11 to 50 people.
Where is CERT EU based?
CERT EU is headquartered in Brussels, Belgium, in the Europe region.
How does CERT EU make money?
One revenue line is on record: government-funded cybersecurity services.
Who are CERT EU's main competitors?
Direct peers on record are BSI (Bundesamt für Sicherheit in der Informationstechnik, Germany), ENISA (European Union Agency for Cybersecurity), NATO Cyber Security Centre (NCSC), ANSSI (Agence nationale de la sécurité des systèmes d'information, France), CSIRTs Network (CNW), NCSC UK (National Cyber Security Centre, United Kingdom) and CCDCOE (NATO Cooperative Cyber Defence Centre of Excellence). Broad incumbents are FIRST (Forum of Incident Response and Security Teams) and CISA (Cybersecurity and Infrastructure Security Agency, United States). NCSC-NL (National Cyber Security Centre, Netherlands) is listed as a regional player.
Does CERT EU have an API?
No public API is recorded for CERT EU.
What industry is CERT EU in?
CERT EU's product category is Government Cybersecurity Services. Its primary akta.pro industry code is BPAKAHAH, Governance, Risk & Compliance (GRC) Advisory & Assessments, with a secondary code of BPAIAOAH, Data Protection, Privacy & Cybersecurity Regulators. Its NAICS code is 561621 and its SIC code is 7373.