Secopan
Secopan is a German consulting firm advising enterprises on information security and data protection. It supports ISO 27001, GDPR, TISAX, NIS2, and EU AI Act compliance, and operates a Moodle-based e-learning platform for security awareness training.
- Company typePrivate
- Founded2020
- HeadquartersLeonberg, Germany
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Secopan does
Secopan GmbH is a Leonberg, Germany-based consultancy specializing in information security and data protection advisory for regulated enterprises. Founded circa 2020 and operating as a privately held GmbH, the firm advises clients across the German DACH market on ISO 27001, ISO 27019, ISO 9001, TISAX, NIS2, GDPR, the EU AI Act, ISO 42001, the Cyber Resilience Act, B3S, IEC 62443, and German-specific KRITIS requirements including attack detection systems under § 8a BSIG. Its named customers span utilities, automotive suppliers, manufacturers, logistics providers, technology firms, construction, and food/agriculture, with disclosed logos of over 100 clients.
The company's core offerings are project-based and retainer consulting engagements delivered by a small team (1-10 employees) under managing directors Dr. Jörg Kümmerlen and Jan Schmidt. A distinctive operational asset is the secopan E-Learning Plattform, a Moodle-based online training platform delivered as part of consulting engagements (notably external DPO and information security advisor mandates). The platform hosts interactive modules with video, interim questions, and final tests, automatically generating completion certificates, with content available in German and English across topics including AI Regulation, GDPR, Phishing Awareness, Document Classification, Mobile Working, and Whistleblower protection.
Commercially, Secopan operates a quote-based professional services model with multi-year contract cadences and recurring retainer components (particularly for external DPO services). The firm also offers external Data Protection Officer mandates staffed by fully qualified lawyers. Marketing and distribution rely on a bilingual content-driven website, regular newsletters, and industry events, with partnerships limited to operational vendors (IONOS hosting, Microsoft Teams, MailPoet) plus a working relationship with the ENX Association for TISAX assessment routing. The company has no disclosed funding, no subsidiaries, and no M&A activity on record.
Secopan firmographics
Firmographics- Name
- Secopan
- Legal name
- secopan gmbh
- Website
- https://secopan.de
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Secopan is a German consulting firm advising enterprises on information security and data protection. It supports ISO 27001, GDPR, TISAX, NIS2, and EU AI Act compliance, and operates a Moodle-based e-learning platform for security awareness training.
- Ownership category
- akta.pro rank
Secopan industry classification
Industry- Product category
- Information Security & Data Protection Consulting
- NAICS
- Management, Scientific, and Technical Consulting Services (5416), Other Scientific and Technical Consulting Services (54169)
- akta.pro primary industry
- Security Operations Center (SOC) as a Service (BPAEADAB)
- akta.pro secondary industry
- Governance, Risk & Compliance (GRC) & Security Management (EDAOAIAG)
Keywords
Where Secopan is headquartered
LocationHeadquarters
- HQ city
- Leonberg
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Secopan business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Consulting Services: Professional consulting engagements for information security and data protection, including external DPO services, ISMS implementation, certification preparation, and compliance advisory. Project-based and retainer arrangements.
- E-Learning and Training: Online training platform access provided as part of client engagements when commissioned as external data protection officer or information security consultant. Additional awareness training, classroom training, and educational materials offered to clients.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom consulting engagements tailored to client requirements |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels3 records
Secopan product offering
Product offeringCore offering
Secopan GmbH is a German consulting firm that advises organizations on information security and data protection. It delivers consulting engagements for ISO/IEC 27001, ISO 27019, ISO 9001, ISO 14001, ISO 42001, TISAX, NIS-2, GDPR, EU AI Act, Cyber Resilience Act, IEC 62443, B3S, IT Security Catalog (BNetzA), and Attack Detection Systems (§ 8a BSIG). It also operates a Moodle-based e-learning platform for security awareness and compliance training, and provides external Data Protection Officer (DPO) services.
Product overview
Secopan is a consulting company offering a comprehensive portfolio of information security and data protection services. The core offering consists of consulting services for regulatory compliance including GDPR, ISO 27001, ISO 27019, TISAX, NIS 2, EU AI Act, Cyber Resilience Act, ISO 14001, IEC 62443, and various German sector-specific standards (B3S, IT Security Catalog, Attack Detection Systems). Additionally, Secopan provides an e-learning platform (secopan E-Learning Plattform) for security awareness and compliance training, offering courses on AI Regulation, Data Protection, Information Security, Phishing Awareness, Document Classification, and Whistleblower protection. The company also offers External Data Protection Officer services. Secopan's services are primarily consulting/advisory focused rather than a software product platform.
Differentiator
Problem solved
Functional benefit
Brands
- secopan E-Learning Plattform: Online training platform for data protection, information security, and compliance courses including GDPR, AI Regulation, phishing awareness, and document classification.
Products and services
- Data Protection & GDPR Consulting
Quantifiable outcome
- Over 100 customers trust secopan's expertise in information security and data protection
Companies that use Secopan
Customer profileNamed customers16 records
Segments4 records
Ideal customer profiles4 records
Secopan technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature1 record
Secopan partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- ENX AssociationminorTISAX assessment body through which companies register for TISAX certifications. Secopan supports clients through the TISAX registration and audit process.
Scale indicators4 records
Recent moves5 records
Expansion highlights5 records
Secopan competitors and assessment
Company assessmentDirect peers
- usd AG: German cybersecurity consulting firm specializing in ISO 27001, KRITIS, penetration testing, and security audits. Closely comparable to Secopan in vertical focus (regulated industries), service mix (compliance advisory + training), and DACH-centric go-to-market.
- HiSolutions AG: Berlin-based German cybersecurity and risk management consultancy offering ISMS implementation, KRITIS advisory, and BSI-related consulting. Directly comparable service portfolio and target buyer (German mid-market and regulated entities), though larger in headcount than Secopan.
- SRC Security Research & Consulting GmbH: German security consultancy focused on KRITIS, ISO 27001, and information security management for critical infrastructure. Comparable mid-sized German GRC consulting profile with similar regulatory expertise and customer segments.
Broad incumbents
- TÜV Rheinland: International TIC (testing, inspection, certification) firm offering ISO 27001 certification, cybersecurity consulting, and data protection advisory. Comparable in standards expertise but with far broader scope and global delivery footprint.
- EY Germany (Cybersecurity): Big 4 cybersecurity and privacy advisory serving German enterprises on ISO 27001, GDPR, NIS2, and sector-specific frameworks. Directly competitive on enterprise regulatory mandates but with significantly broader service breadth.
- PwC Germany (Cyber & Privacy): Big 4 firm with German cyber, privacy, and regulatory practice addressing GDPR, NIS2, DORA, and ISO standards. Comparable in regulatory subject matter; competes for similar German enterprise and KRITIS clients at a larger scale.
- KPMG Germany (Cyber Security): Big 4 advisory firm with a dedicated German cybersecurity and regulatory compliance practice serving NIS2, KRITIS, ISO 27001, and DORA mandates. Overlaps directly with Secopan in regulated-entity advisory, but with enterprise-scale delivery and international reach.
- Deloitte Germany (Cyber & Strategic Risk): Big 4 cyber risk practice with established German KRITIS, NIS2, and ISO compliance advisory capabilities. Competes with Secopan for regulated-entity mandates but combines cyber with broader risk, legal, and consulting offerings.
- TÜV SÜD Management Service GmbH: Global testing, inspection, certification, and advisory firm with a substantial ISO 27001, TISAX, and cybersecurity practice. Overlaps with Secopan in certification advisory but operates at much larger scale and across all major industries.
Emerging players
- Cipherpoint Solutions GmbH: German IT security consultancy offering ISO 27001, BSI Grundschutz, and KRITIS advisory for mid-market clients. Comparable in target segment and service mix, though with stronger productized tooling component than Secopan.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
Secopan social profiles
Digital presenceSecopan financial estimates
Financial estimateRevenue estimate
Valuation estimate
Secopan leadership team
Management profileNumber of profiles
Profiles2 records
Secopan funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Secopan M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Secopan
What does Secopan do?
Secopan GmbH is a German consulting firm that advises organizations on information security and data protection. It delivers consulting engagements for ISO/IEC 27001, ISO 27019, ISO 9001, ISO 14001, ISO 42001, TISAX, NIS-2, GDPR, EU AI Act, Cyber Resilience Act, IEC 62443, B3S, IT Security Catalog (BNetzA), and Attack Detection Systems (§ 8a BSIG). It also operates a Moodle-based e-learning platform for security awareness and compliance training, and provides external Data Protection Officer (DPO) services.
Is Secopan a public or private company?
Secopan is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Secopan founded?
Secopan was founded in 2020. It employs 1 to 10 people.
Where is Secopan based?
Secopan is headquartered in Leonberg, Germany, in the Europe region.
How does Secopan make money?
Two revenue lines are on record. Consulting Services are the primary driver. The others are E-Learning and Training.
Who are Secopan's main competitors?
Direct peers on record are usd AG, HiSolutions AG and SRC Security Research & Consulting GmbH. Broad incumbents are TÜV Rheinland, EY Germany (Cybersecurity), PwC Germany (Cyber & Privacy), KPMG Germany (Cyber Security), Deloitte Germany (Cyber & Strategic Risk) and TÜV SÜD Management Service GmbH. Cipherpoint Solutions GmbH is listed as an emerging player.
Does Secopan have an API?
No public API is recorded for Secopan.
What industry is Secopan in?
Secopan's product category is Information Security & Data Protection Consulting. Its primary akta.pro industry code is BPAEADAB, Security Operations Center (SOC) as a Service, with a secondary code of EDAOAIAG, Governance, Risk & Compliance (GRC) & Security Management. Its NAICS code is 5416.