CERT
CERT Division, part of Carnegie Mellon University's Software Engineering Institute, is a federally funded R&D center that conducts cybersecurity research, operates the VINCE vulnerability coordination platform and Vulnerability Notes Database, and serves U.S. federal agencies, industry, and academia as a trusted CVE Numbering Authority.
- Company typePrivate
- Founded1988
- HeadquartersPittsburgh, United States
- Headcount501–1,000
- GTM typeB2B
- OfferingServices
What CERT does
CERT (the CERT Division of Carnegie Mellon University's Software Engineering Institute) is a federally funded research and development center (FFRDC) that studies cybersecurity problems with widespread implications and develops methods, tools, and training to counter large-scale threats. Founded in 1988, the organization pioneered computer incident response and has expanded into network situational awareness, malware analysis, secure coding, insider threat mitigation, vulnerability discovery, digital investigations, and workforce development. Its core technology assets include the VINCE (Vulnerability Information and Coordination Environment) platform for coordinated vulnerability disclosure, the public CERT/CC Vulnerability Notes Database covering over 3,500 vulnerabilities across 2,300+ vendors, and a JSON API plus CSAF-formatted documents for programmatic access. CERT/CC also operates as a CVE Numbering Authority (CNA), assigning CVE IDs and managing disclosure workflows for multiple vendors and critical infrastructure sectors.
CERT's customer base spans U.S. federal government agencies (with primary sponsorship from the U.S. Department of War and coordination with DHS/CISA), industry partners, law enforcement, and academia, with documented engagements including the U.S. Postal Service on cybersecurity workforce development and joint training exercises with Air National Guard and Air Force Reserve units. Its business model is non-commercial: as an FFRDC, CERT is funded through federal contracts and grants, and services such as vulnerability coordination are provided free to vendors and the public. The organization does not sell commercial products and does not publicly disclose revenue. Go-to-market is direct engagement with government sponsors and partners rather than a traditional sales motion. Strategic emphasis is currently expanding into Autonomy Security and Resilience, addressing assurance of machine learning systems, supported by active hiring for AI security and data science roles.
CERT firmographics
Firmographics- Name
- CERT
- Legal name
- Carnegie Mellon University
- Website
- https://cert.org
- Company type
- Private
- Founded year
- 1988
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Short description
- CERT Division, part of Carnegie Mellon University's Software Engineering Institute, is a federally funded R&D center that conducts cybersecurity research, operates the VINCE vulnerability coordination platform and Vulnerability Notes Database, and serves U.S. federal agencies, industry, and academia as a trusted CVE Numbering Authority.
- Ownership category
- akta.pro rank
CERT industry classification
Industry- Product category
- Cybersecurity Research and Vulnerability Coordination Services
- NAICS
- Security Systems Services (56162)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF), Cybersecurity (General) (EDAOAIAB), Information Technology (IT) & Cybersecurity Certifications (EDAAANAA), Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH), Cybersecurity Awareness & Digital Safety Training for Security Personnel (BPAKAOAO)
Keywords
Where CERT is headquartered
LocationHeadquarters
- HQ city
- Pittsburgh
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
CERT business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure
Revenue model
- Federal Government Funding: As a federally funded research and development center (FFRDC) operated by Carnegie Mellon University and sponsored by the Department of War, CERT Division's primary funding comes from federal government sources to conduct cybersecurity research and provide services to government agencies.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels5 records
CERT product offering
Product offeringCore offering
CERT Division conducts cybersecurity research and provides coordinated vulnerability disclosure, incident response coordination, and advanced cybersecurity methods and tools to government, industry, law enforcement, and academia. The division operates the VINCE platform for vulnerability coordination, maintains the publicly accessible Vulnerability Notes Database (3,500+ notes across 2,300+ vendors), and serves as a CVE Numbering Authority. Core funded activities include 11 practice areas such as insider threat detection, malware reverse engineering, situational awareness, secure development, ML/autonomy security, and cyber workforce development.
Product overview
CERT (CERT Division of the Carnegie Mellon University Software Engineering Institute) operates as a federally funded research and development center specializing in cybersecurity. The organization offers a unified platform combining the VINCE coordination platform for vulnerability disclosure management and a publicly accessible Vulnerability Notes Database. Services include coordinated vulnerability disclosure, CVE ID assignment as a CNA, technical analysis, and cybersecurity research spanning incident response, malware analysis, insider threats, and secure development practices. The organization has operated for over 35 years, expanding from computer incident response to comprehensive cybersecurity research and workforce development.
Differentiator
Problem solved
Functional benefit
Products and services
- VINCE (Vulnerability Information and Coordination Environment) A secure platform for coordinated vulnerability disclosure that enables vendors and reporters to communicate about vulnerabilities, track remediation progress, and manage the coordination process through a web-based interface with user accounts and case management.
- Vulnerability Notes Database A searchable database containing vulnerability notes with technical details, impact assessments, affected vendor information, and remediation guidance for over 3,500 vulnerabilities affecting 2,300+ vendors.
- Vulnerability Coordination Services Coordinated vulnerability disclosure services that bring together reporters, vendors, and stakeholders to analyze vulnerabilities, develop remediation guidance, and ensure correct information reaches the public.
- CVE Numbering Authority (CNA) Services As a CVE Numbering Authority, CERT/CC assigns CVE IDs to vulnerabilities and manages the vulnerability disclosure process for multiple vendors and critical infrastructure sectors.
Quantifiable outcome
- Over 3,500 vulnerability notes published in the database
- +1 more outcomes
Companies that use CERT
Customer profileNamed customers2 records
Segments4 records
Ideal customer profiles3 records
CERT technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
CERT partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Carnegie Mellon UniversitycoreCERT Division is a division of the Software Engineering Institute at Carnegie Mellon University. This relationship creates multidisciplinary collaboration opportunities and amplifies research abilities through access to university expertise across computer science, engineering, and related fields.
- DHS/CISAcoreCERT/CC operates under DHS/CISA coordination, publishing vulnerability advisories and providing cybersecurity coordination services. The organization issues advisories that are sponsored by CISA.
- Government, Industry, Law Enforcement, and Academia PartnerscoreCERT Division explicitly states it partners with government, industry, law enforcement, and academia to advance cybersecurity and improve the security and resilience of computer systems and networks.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
CERT competitors and assessment
Company assessmentBroad incumbents
- CISA (Cybersecurity and Infrastructure Security Agency): Federal civilian cybersecurity agency that coordinates vulnerability disclosure, publishes advisories, and partners with CERT/CC on coordinated response. Directly comparable in coordination mission and explicitly cited as a CERT sponsor and partner.
- CrowdStrike: Commercial cybersecurity leader providing threat intelligence, vulnerability research, and coordinated disclosure services through its services and intelligence businesses. Comparable to CERT in vulnerability research scope but operates at global commercial scale.
- NIST (National Institute of Standards and Technology): Federal agency responsible for cybersecurity frameworks including the NIST Cybersecurity Framework, SP 800 series, and NVD vulnerability program. Comparable to CERT as a government-sponsored authority shaping cybersecurity standards and vulnerability disclosure practice.
Direct peers
- MITRE Corporation: Federally funded research and development center that operates CVE Numbering Authority functions, ATT&CK framework, and CWE/MITRE security research programs. Direct peer to CERT in mission, funding model, and cybersecurity research scope, serving as the most structurally comparable FFRDC peer.
- SANS Institute: Leading cybersecurity training and certification organization that develops cyber workforce capabilities, GIAC certifications, and security research. Comparable to CERT's Cyber Workforce Development practice and serves overlapping federal and enterprise training demand.
- RAND Corporation: Nonprofit, university-affiliated research institution conducting policy and technology research for federal sponsors. Comparable to CERT/SEI as an FFRDC-style research organization with federal sponsorship and academic affiliation.
- Johns Hopkins Applied Physics Laboratory (APL): University-affiliated FFRDC conducting sponsored cybersecurity research for federal sponsors. Comparable to CERT in operating model, sponsor relationships, and cybersecurity research depth.
- MIT Lincoln Laboratory: Federally funded research and development center operated by MIT that conducts cybersecurity, autonomous systems, and resilience research. Direct structural peer as an academic-affiliated FFRDC with comparable cybersecurity research mandate.
Emerging players
- Mandiant (Google Cloud): Commercial incident response and threat intelligence firm, now part of Google Cloud, offering vulnerability research and coordinated disclosure services at commercial scale. Comparable to CERT's incident response and vulnerability coordination work but operating under a commercial, for-profit model.
Regional players
- ENISA (European Union Agency for Cybersecurity): EU agency coordinating cybersecurity capability development, vulnerability disclosure, and CSIRT support across member states. Comparable to CERT in mission of coordinating vulnerability disclosure and CSIRT capability development, but operates in the European regulatory context.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
CERT social profiles
Digital presenceCERT financial estimates
Financial estimateRevenue estimate
Valuation estimate
CERT leadership team
Management profileNumber of profiles
Profiles3 records
CERT funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CERT M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CERT
What does CERT do?
CERT Division conducts cybersecurity research and provides coordinated vulnerability disclosure, incident response coordination, and advanced cybersecurity methods and tools to government, industry, law enforcement, and academia. The division operates the VINCE platform for vulnerability coordination, maintains the publicly accessible Vulnerability Notes Database (3,500+ notes across 2,300+ vendors), and serves as a CVE Numbering Authority. Core funded activities include 11 practice areas such as insider threat detection, malware reverse engineering, situational awareness, secure development, ML/autonomy security, and cyber workforce development.
Is CERT a public or private company?
CERT is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was CERT founded?
CERT was founded in 1988. It employs 501 to 1,000 people.
Where is CERT based?
CERT is headquartered in Pittsburgh, United States, in the North America region.
How does CERT make money?
One revenue line is on record: federal Government Funding.
Who are CERT's main competitors?
Broad incumbents on record are CISA (Cybersecurity and Infrastructure Security Agency), CrowdStrike and NIST (National Institute of Standards and Technology). Direct peers are MITRE Corporation, SANS Institute, RAND Corporation, Johns Hopkins Applied Physics Laboratory (APL) and MIT Lincoln Laboratory. Mandiant (Google Cloud) is listed as an emerging player. ENISA (European Union Agency for Cybersecurity) is listed as a regional player.
Does CERT have an API?
Yes. CERT provides a JSON API for accessing vulnerability notes data. The API endpoints return structured vulnerability information including CVE IDs, affected vendors, technical descriptions, and CSAF (Common Security Advisory Framework) formatted documents. The VINCE (Vulnerability Information and Coordination Environment) platform also provides API access for vulnerability coordination workflow. Developer documentation is at kb.cert.org/vuls/api.
What industry is CERT in?
CERT's product category is Cybersecurity Research and Vulnerability Coordination Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of EDABAFAF, Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing). Its NAICS code is 56162.