Fraunhofer AISEC
Fraunhofer AISEC is a German applied cybersecurity research institute within Fraunhofer-Gesellschaft, serving manufacturers, public institutions, semiconductor firms, and KRITIS operators with hardware security labs, open-source security tools, CRA/NIS-2 compliance software, and PQC migration consulting.
- Company typePrivate
- Founded1990
- HeadquartersGarching bei München, Germany
- Headcount101–250
- GTM typeB2B
- OfferingServices
What Fraunhofer AISEC does
Fraunhofer AISEC (Fraunhofer-Institut für Angewandte und Integrierte Sicherheit) is a constituent applied-research institute of the Fraunhofer-Gesellschaft, headquartered in Garching bei München with additional sites in Berlin and Weiden in der Oberpfalz. Founded in 1990 and operating with 151 employees, it focuses on applied cybersecurity across hardware security, software security, cryptography, AI security, and quantum cybersecurity. The institute runs ten IT security laboratories spanning Automotive and Hardware Security, Industry 4.0 and IoT, and Software, Cloud and Smart Sensor Security, with the Hardware Security Lab Common Criteria certified up to EAL7. Customer segments include manufacturing and industrial companies (automotive, machinery, aerospace, medical devices), public institutions and government, the semiconductor industry, and KRITIS operators facing EU regulatory obligations.
The institute's portfolio is research-driven rather than commercially packaged, consisting of open-source security analysis tools (Codyze, Code Property Graph, IntelliSecTest), compliance and risk-assessment tools (Confirmate, QuBA, QuBA-libre, MoRA), supply-chain integrity components (CMC, kotlin-csaf), the GyroidOS secure execution platform, a Post-Quantum Cryptography Competence Center, and the jointly developed RISC-V Secure Element hardware root-of-trust. Service offerings span commissioned research, technology development, security analyses and penetration testing, feasibility studies, trainings, and IT security consulting. Marketing channels emphasize thought leadership (Cybersecurity Blog, GitHub, YouTube, LinkedIn, newsletter) and industry events (it-sa trade fair, PQC-Update conference, FIRST by FMD).
Revenue is generated through two streams: industrial contract research with enterprise and public-sector clients, and publicly funded research from BMBF and EU programs (including the EU Chips Act). As a legally non-autonomous entity of Fraunhofer-Gesellschaft — a registered nonprofit — the institute has no traditional venture capital or private equity ownership. Strategic positioning centers on European digital sovereignty, with active participation in OpenHW Foundation, OpenTitan Coalition, Semiconductor-X consortium, APECS (EU Chips Act pilot line), and the Research Fab Microelectronics Germany, reflecting an explicit shift from pure cybersecurity services toward semiconductor and open-source hardware trust.
Fraunhofer AISEC firmographics
Firmographics- Name
- Fraunhofer AISEC
- Legal name
- Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC
- Website
- https://aisec.fraunhofer.de
- Company type
- Private
- Founded year
- 1990
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Fraunhofer AISEC is a German applied cybersecurity research institute within Fraunhofer-Gesellschaft, serving manufacturers, public institutions, semiconductor firms, and KRITIS operators with hardware security labs, open-source security tools, CRA/NIS-2 compliance software, and PQC migration consulting.
- Ownership category
- akta.pro rank
Fraunhofer AISEC industry classification
Industry- Product category
- Cybersecurity Research & Consulting
- NAICS
- Computer Systems Design and Related Services (54151), Computer Systems Design Services (541512), Other Scientific and Technical Consulting Services (54169), Other Computer Related Services (541519)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- IT Risk Management (ITRM) (HDADAIAD)
- akta.pro secondary industries
- Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001) (HDAAAMAE), Cybersecurity & Identity Consulting (BPAHAEAG), Application Security & Secure Software (DevSecOps) (EDAOAIAK)
Keywords
Where Fraunhofer AISEC is headquartered
LocationHeadquarters
- HQ city
- Garching bei München
- HQ country
- Germany
- HQ region
- Europe
Offices3 records
Markets served
Fraunhofer AISEC business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Infrastructure, Operations, Others
Revenue model
- Industrial Contract Research: Fraunhofer AISEC generates revenue through commissioned research from industry partners, technology development projects, and security testing services for companies and public institutions.
- Publicly Funded Research: As part of the Fraunhofer-Gesellschaft, the institute receives government funding for research projects, particularly from BMBF (Federal Ministry of Education and Research) and EU programs.
Go-to-market motion2 records
Distribution channels4 records
Marketing channels11 records
Fraunhofer AISEC product offering
Product offeringCore offering
Fraunhofer AISEC is an applied cybersecurity research institute that conducts commissioned research, develops proprietary security analysis and compliance tools (e.g., Codyze, Confirmate, GyroidOS), performs hardware security evaluations up to EAL7 in a Common Criteria-certified laboratory, and provides consulting on EU regulatory compliance (NIS-2, Cyber Resilience Act) and post-quantum cryptography migration for industrial and public-sector clients.
Product overview
Fraunhofer AISEC is a research institute (part of the Fraunhofer-Gesellschaft) focused on applied and integrated cybersecurity. Rather than a single commercial product, its portfolio consists of a layered suite of research-driven cybersecurity tools, platforms, and services. The core offerings include: security analysis tools (Codyze, Code Property Graph, IntelliSecTest) for static and AI-based source code vulnerability detection; compliance and risk management tools (Confirmate, QuBA, MoRA, QuBA-libre) for CRA and security concept support; open-source security components (CMC, kotlin-csaf) for supply chain verification and CSAF integration; the secure platform GyroidOS for container isolation and certification; a CC-certified Hardware Security Lab offering hardware penetration testing up to EAL7; a PQC Competence Center providing quantum-resistant cryptography migration consulting; a Learning Laboratory (Lernlabor) with training seminars and the 'Charlie und die Quantenfabrik' serious game; and a RISC-V Secure Element (hardware root of trust) developed in partnership with other Fraunhofer institutes. Fraunhofer AISEC also publishes an expert Cybersecurity Blog and operates GitHub repositories for its open-source tools.
Differentiator
Problem solved
Functional benefit
Products and services
- Codyze Open-source static source code analysis tool that checks security properties of program code and identifies vulnerabilities using AI-based procedures to automatically search for patterns representing potential weaknesses.
- Confirmate Software solution for automated Cyber Resilience Act (CRA) compliance checking of software components, combining static code analysis with automated compliance evaluation to identify vulnerabilities and determine individual remediation needs. First demonstrated at it-sa 2024.
- IntelliSecTest Security testing tool using AI-based procedures to automatically search for patterns in source code that may represent potential vulnerabilities.
Quantifiable outcome
- Security evaluations up to EAL7 level for hardware components
- +1 more outcomes
Companies that use Fraunhofer AISEC
Customer profileSegments4 records
Ideal customer profiles4 records
Fraunhofer AISEC technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability13 records
Feature11 records
Fraunhofer AISEC partnerships and signals
Strategic signalPartnerships
16 partnerships are on record, tiered core, major and moderate.
- lowRISC C.I.C.coreFraunhofer AISEC collaborates with lowRISC on the OpenTitan Coalition, serving as the central partner for security testing and independently evaluating the physical resilience of the world's first open-source hardware root of trust.
- GooglecoreCollaboration with Google and lowRISC to investigate the hardware security of the OpenTitan chip (OpenTitan Silicon Root of Trust).
- Semiconductor-X ConsortiummajorFraunhofer AISEC and Fraunhofer IOSB joined the Semiconductor-X consortium as cybersecurity partners, developing a roadmap for secure data spaces.
- OpenHW FoundationcoreFraunhofer AISEC joined the OpenHW Foundation to drive open, trusted, and highly secure hardware platforms, strengthening a central building block for digital sovereignty in Europe.
- Fraunhofer IIScoreCollaboration on RISC-V-based Secure Element development and OpenTitan-based security solutions. Fraunhofer IIS provides chip design expertise.
- Fraunhofer EMFTcoreCollaboration on RISC-V-based Secure Element and trusted electronics solutions. Fraunhofer EMFT contributes electronic microsystems expertise.
- VDE (Informationstechnische Gesellschaft ITG)moderateCoordinated through VDE-Fachgruppe 'Vertrauenswürdige Elektronik' to bundle and sustain work on trusted electronics.
- BayQS (Bayerisches Kompetenzzentrum Quanten Security and Data Science)moderateBayQS develops foundational concepts, solutions, and prototypes in quantum computing with focus on secure QC programming and platforms, robust QC, and QC-supported (hybrid) optimization.
- Munich Quantum Valley (MQV)moderateMQV promotes quantum science and technologies in Bavaria, building competitive quantum computers and strengthening knowledge transfer between research and industry.
- Fraunhofer Competence Network Quantum ComputingmoderateNational Fraunhofer network pursuing joint goals in quantum computing research and development across regional competence centers.
- Trusted Electronic Bayern (TrEB)majorCenter developing tailored technology and system solutions for reliable and trusted electronics with partners from various industries.
- Bayerisches Chip-Design-Center (BCDC)majorProvides companies, especially startups and SMEs, facilitated access to chip design and supply chains in collaboration with Fraunhofer AISEC, EMFT, IIS, and Bavarian universities.
- VelektronikmoderateNetworking platform for trusted electronics creating interface between companies and research institutions from Fraunhofer-Gesellschaft and Leibniz-Gemeinschaft.
- APECS (EU Chips Act)majorPilot line under EU Chips Act to drive chiplet innovation and increase semiconductor research and manufacturing capacity in Europe. Fraunhofer AISEC develops security features.
- SICK AGmoderateCollaboration with SICK AG to develop and implement the QuBA questionnaire-based risk assessment method for Cyber Resilience Act compliance.
- Research Fab Microelectronics Germany (FMD)majorCollaboration through FMD for semiconductor research and manufacturing capacity in Europe, including the FIRST conference organization.
Scale indicators4 records
Recent moves10 records
Expansion highlights6 records
Fraunhofer AISEC competitors and assessment
Company assessmentBroad incumbents
- Thales: Global cybersecurity and defense group with hardware security modules, cryptography consulting, and compliance services. Comparable as a broad incumbent with overlapping cryptography and cybersecurity consulting capabilities, but operates at much larger scale and across many verticals.
- NXP Semiconductors: Global semiconductor company with strong secure element and hardware root-of-trust portfolio. Comparable to AISEC's RISC-V Secure Element and trusted electronics research, but at vastly larger scale and as a commercial product company.
- Infineon Technologies: German semiconductor leader in hardware security (TPMs, secure elements, OPTIGA family). Operates adjacent to AISEC's trusted electronics domain and as a Munich-area peer, but is a commercial product company rather than a research institute.
- TÜV SÜD: Large German certification and testing conglomerate with cybersecurity and industrial security testing practices. Comparable as a broader German-based security certification/consulting incumbent, but operates across many industries rather than specializing in applied cybersecurity research.
Direct peers
- SGS Brightsight: Netherlands-based security evaluation lab offering CC, EMVCo, and payment security certifications with strong hardware security testing. Directly comparable to AISEC's CC-certified lab offering security evaluations up to EAL7.
- Trail of Bits: US-based applied cybersecurity research consultancy building security tools (Slither, Echidna, Manticore) and conducting audits for blockchain, cryptography, and software systems. Directly comparable to AISEC's mix of research-led tooling and consulting services.
- Quarkslab: French cybersecurity research firm providing binary analysis, reverse engineering, and security consulting, including open-source tools (e.g., BinaryNinja, Triton). Comparable to AISEC's code analysis tooling (Codyze, Code Property Graph) and applied security research.
- Riscure: Dutch security lab specializing in hardware security evaluation, side-channel analysis, and Common Criteria certifications for embedded systems. Most direct comparable to Fraunhofer AISEC's CC-certified Hardware Security Lab and side-channel/fault-injection testing capabilities.
- CryptoExperts: French cryptography consulting firm specializing in cryptographic implementations, post-quantum migration, and security audits. Closely comparable to AISEC's PQC Competence Center and applied cryptography research.
Regional players
- Bundesamt für Sicherheit in der Informationstechnik (BSI): German federal cybersecurity agency that defines certification frameworks (BSI standards, IT-Grundschutz) and oversees approvals. Adjacent comparable as the regulatory anchor whose standards (and NIS-2, CRA frameworks) drive much of AISEC's compliance consulting demand.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Fraunhofer AISEC social profiles
Digital presenceFraunhofer AISEC compliance and trust
Trust signalCompliance1 record
Fraunhofer AISEC financial estimates
Financial estimateRevenue estimate
Valuation estimate
Fraunhofer AISEC leadership team
Management profileNumber of profiles
Profiles9 records
Fraunhofer AISEC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Fraunhofer AISEC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Fraunhofer AISEC
What does Fraunhofer AISEC do?
Fraunhofer AISEC is an applied cybersecurity research institute that conducts commissioned research, develops proprietary security analysis and compliance tools (e.g., Codyze, Confirmate, GyroidOS), performs hardware security evaluations up to EAL7 in a Common Criteria-certified laboratory, and provides consulting on EU regulatory compliance (NIS-2, Cyber Resilience Act) and post-quantum cryptography migration for industrial and public-sector clients.
Is Fraunhofer AISEC a public or private company?
Fraunhofer AISEC is a private company. It is classified as state government owned and is currently operating.
When was Fraunhofer AISEC founded?
Fraunhofer AISEC was founded in 1990. It employs 101 to 250 people.
Where is Fraunhofer AISEC based?
Fraunhofer AISEC is headquartered in Garching bei München, Germany, in the Europe region.
How does Fraunhofer AISEC make money?
Two revenue lines are on record. Industrial Contract Research is the primary driver. The others are publicly Funded Research.
Who are Fraunhofer AISEC's main competitors?
Broad incumbents on record are Thales, NXP Semiconductors, Infineon Technologies and TÜV SÜD. Direct peers are SGS Brightsight, Trail of Bits, Quarkslab, Riscure and CryptoExperts. Bundesamt für Sicherheit in der Informationstechnik (BSI) is listed as a regional player.
Does Fraunhofer AISEC have an API?
No public API is recorded for Fraunhofer AISEC.
What industry is Fraunhofer AISEC in?
Fraunhofer AISEC's product category is Cybersecurity Research & Consulting. Its primary akta.pro industry code is HDADAIAD, IT Risk Management (ITRM), with a secondary code of HDAAAMAE, Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001). Its NAICS code is 54151 and its SIC code is 7373.