CERT-SE
CERT-SE is Sweden's national CSIRT, operating as a government agency within NCSC at FRA, providing free incident coordination, vulnerability monitoring (ANTS), proactive scanning, and the national MISP-SE threat intelligence sharing platform to Swedish government, critical infrastructure, and private sector organizations.
- Company typePrivate
- Founded-
- HeadquartersSolna, Sweden
- Headcount1–10
- GTM typeB2B
- OfferingServices
What CERT-SE does
CERT-SE is Sweden's national CSIRT (Computer Security Incident Response Team), operating as a government agency within the National Cyber Security Centre (Nationellt cybersäkerhetscenter, NCSC) at the Swedish Defence Radio Establishment (Försvarets radioanstalt, FRA). Its mandate, codified under Ordinance (2025:237), covers incident coordination, vulnerability management, and threat intelligence sharing for Swedish government authorities, regional and municipal entities, critical infrastructure operators, and the broader Swedish constituency. On July 1, 2026, CERT-SE's operations transferred from the Swedish Civil Contingencies Agency (MCF) to NCSC at FRA, consolidating national cyber operations.
The core product portfolio comprises three free services: ANTS (Automatisk sårbarhetsnotifiering), which delivers daily CSV-formatted email notifications identifying exposed services, DDoS-amplification vectors, vulnerable services, and suspected compromised devices; Proactive Scanning, which provides a summary of known attack surface plus on-demand intrusive scanning (including credential testing and vulnerability verification) for NIS entities; and MISP-SE, a national instance of the open-source Malware Information Sharing Platform enabling Swedish organizations to share IoCs via API or SAML 2.0/OpenID Connect federation. Supporting capabilities include a 24/7 incident hotline, an RFC-2350-compliant incident handling process aligned with SANS/NIST frameworks, "Blixtmeddelande" critical threat flash alerts (1–3 per year), a weekly "Veckobrev" newsletter, and cybersecurity tabletop exercises. The organization is a full member of FIRST, Trusted Introducer, TF-CSIRT, the EU CSIRTs Network, EGC, and IWWN.
CERT-SE operates under a non-commercial model: all services are free of charge to the Swedish constituency, with funding flowing through FRA appropriations. There is no pricing, no commercial sales motion, and no revenue generation; the distribution model is direct-to-constituency through the cert.se website, email subscriptions, phone hotline, sector-specific forums (FIDI, GovSec), and a Cyberportalen incident reporting portal. The effective date of Sweden's NIS2 cybersecurity law (January 2026) expanded the mandatory reporting constituency and formalized rights to free proactive scanning under Article 23, broadening CERT-SE's mandate.
CERT-SE firmographics
Firmographics- Name
- CERT-SE
- Legal name
- CERT-SE
- Website
- https://cert.se
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- CERT-SE is Sweden's national CSIRT, operating as a government agency within NCSC at FRA, providing free incident coordination, vulnerability monitoring (ANTS), proactive scanning, and the national MISP-SE threat intelligence sharing platform to Swedish government, critical infrastructure, and private sector organizations.
- Ownership category
- akta.pro rank
CERT-SE industry classification
Industry- Product category
- National Cybersecurity / CSIRT Services
- NAICS
- Investigation and Security Services (5616), Security Systems Services (except Locksmiths) (561621), National Security (928110)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Security Incident Response (IR) & Digital Forensics Services (BPAEADAI)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Border Security & Homeland Security (BPAIAHAI)
Keywords
Where CERT-SE is headquartered
LocationHeadquarters
- HQ city
- Solna
- HQ country
- Sweden
- HQ region
- Europe
Offices2 records
Markets served
CERT-SE business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure
Revenue model
- Public Services — No Revenue Generation: CERT-SE is a government agency (part of FRA — Försvarets radioanstalt, the National Defence Radio Establishment) providing all services free of charge to Swedish organizations. The organization is fully financed by FRA. There is no commercial revenue model; services are funded through government appropriations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | ANTS — Free for all Swedish organizations |
| Freemium | Monthly | MISP-SE — Free national threat intelligence sharing platform |
| Freemium | Annual | Proaktiv skanning — Free proactive scanning services |
| Freemium | Monthly | Blixtmeddelande, Veckobrev, MISP-SE nyhetsbrev — Free email subscriptions |
Go-to-market motion2 records
Distribution channels6 records
Marketing channels7 records
CERT-SE product offering
Product offeringCore offering
CERT-SE is Sweden's national CSIRT providing free-of-charge incident coordination, vulnerability monitoring, and threat intelligence sharing services to Swedish government authorities, NIS entities, and critical infrastructure operators. Its core operational offerings include ANTS (automated daily vulnerability notifications), Proactive Scanning (attack surface assessment for NIS entities), and MISP-SE (a national threat intelligence sharing platform), complemented by 24/7 incident response coordination, ransomware/phishing/DDoS advisory services, tabletop exercises, and subscription-based critical threat alerts and weekly newsletters.
Product overview
CERT-SE (Computer Emergency Response Team – Sverige) is Sweden's national CSIRT, operating within the National Cyber Security Centre (NCSC) at the Swedish Defence Radio Establishment (FRA). CERT-SE's portfolio consists of a coordinated set of free services aimed at helping Swedish organizations prevent and manage IT security incidents. The core offerings include: ANTS (Automatisk Nätverksbaserad Teknisk Sårbarhetsövervakning), an automated notification service for internet-facing vulnerabilities; Proaktiv skanning, proactive scanning of internet attack surfaces; and MISP-SE, a national MISP instance for structured threat intelligence sharing. These are complemented by thematic advisory services covering ransomware, phishing, and DDoS, tabletop exercise materials for incident management training, and email subscription products (weekly newsletters and flash alerts for critical threats). MISP-SE exercises are also offered to build operational capability in the Swedish cybersecurity community.
Differentiator
Problem solved
Functional benefit
Brands
- ANTS (Automatiska notifieringar om tekniska sårbarheter): Free service for Swedish organizations to monitor internet-facing assets for vulnerabilities
- Proaktiv skanning (Proactive Scanning)
- MISP-SE
Products and services
- ANTS (Automatisk Nätverksbaserad Teknisk Sårbarhetsövervakning) Automated notification service that alerts Swedish organizations when technical vulnerabilities are detected in their internet-facing assets, identifying publicly exposed services, services usable for DDoS amplification, potentially vulnerable services, and suspected compromised devices. Notifications are sent daily via email in CSV format.
- Proaktiv skanning (Proactive Scanning) A collection of free scanning services including a summary of known attack surface data and on-demand technical scanning including login attempts with common credentials and vulnerability verification, available to NIS entities upon request and completion of ANTS enrollment prerequisites.
- MISP-SE A national, free instance of the open-source Malware Information Sharing Platform (MISP) that enables Swedish organizations to collect, store, analyze, and share cyber threat indicators including IP addresses, domains, and malware signatures. Supports API-based MISP-to-MISP synchronization and web interface access with SAML 2.0/OpenID Connect federation. Includes threat intelligence correlation aligned with NIST CSF 2.0 phases.
- Ransomware guidance and support Advice and guidance for organizations on preventing and managing ransomware attacks, including technical mitigation steps, communication planning, and recovery procedures.
- Phishing (nätfiske) guidance Advisory resources for preventing and responding to phishing attacks, including recommendations for multi-factor authentication, password policies, and user awareness training.
- DDoS guidance Guidance on preventing and handling distributed denial-of-service attacks, including mitigation techniques and recommendations for maintaining service availability.
- Tabletop exercises for incident management Simple, short tabletop exercise materials for handling ransomware, DDoS, and phishing incidents, designed for small and medium-sized municipalities, companies, and organizations.
- CERT-SE email subscriptions (Blixtmeddelande, Veckobrev, MISP-SE nyhetsbrev) Free email subscription services including Blixtmeddelande for critical threat alerts requiring immediate action, Veckobrev with weekly cybersecurity news delivered every Friday, and MISP-SE monthly newsletter. Also available as an RSS feed.
- MISP-SE cybersecurity exercises Technical cybersecurity exercises focused on MISP and incident handling, designed to strengthen the operational capability of Swedish organizations for cyber threat information sharing.
- IT incident response coordination Core incident handling service providing 24/7/365 support to organizations affected by IT security incidents, following the Förebygga, Identifiera, Begränsa, Återställa, Erfarenheter process aligned with SANS and NIST incident response frameworks.
Quantifiable outcome
- 1–3 blixtmeddelande (critical threat alerts) sent per year, reaching thousands of Swedish organizations immediately
- +3 more outcomes
Companies that use CERT-SE
Customer profileSegments4 records
Ideal customer profiles3 records
CERT-SE technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
CERT-SE partnerships and signals
Strategic signalPartnerships
16 partnerships are on record, tiered core and minor.
- FRA (Försvarets radioanstalt — National Defence Radio Establishment)coreCERT-SE is fully embedded within FRA, Sweden's National Defence Radio Establishment. The organization operates under Ordinance (2025:237) with instructions for FRA, and is fully financed by FRA. CERT-SE's address and operations are at FRA's facilities (Terminalvägen 14, Solna). FRA handles all administrative functions including HR, finance, and legal compliance. CERT-SE is the operational cybersecurity arm of FRA's National Cyber Security Centre.
- NCSC-SE (Nationellt Cybersäkerhetscenter — National Cyber Security Centre)coreAs of 1 July 2026, CERT-SE becomes fully integrated into the National Cyber Security Centre (NCSC) at FRA. NCSC-SE serves as the overarching coordination body for all cybersecurity activities in Sweden. CERT-SE is the operational CSIRT within NCSC-SE. The two entities share leadership, staff, and facilities. NCSC publishes cybersecurity guidance (Cybersäkerhet i Sverige reports), manages the cybersecurity law (NIS2) implementation, and coordinates national cyber exercises.
- FIRST (Forum of Incident Response and Security Teams)coreFIRST is a premier global organization of CSIRTs. As a full member, CERT-SE participates in international incident response coordination, accesses the FIRST member directory, and engages in global best practice development. FIRST membership provides access to shared tooling, standards, and training resources for the global CERT community.
- Trusted IntroducercoreTrusted Introducer is a certification and directory service for European CERTs. CERT-SE is certified by Trusted Introducer, which validates the organization's legitimacy, operational capability, and adherence to standards. The certification is listed at https://www.trusted-introducer.org/directory/teams/cert-se.html.
- TF-CSIRTcoreTF-CSIRT is a European task force working to improve CERT collaboration and maturity across Europe. Membership enables CERT-SE to engage in cross-border CERT development initiatives, share methodologies, and participate in joint working groups.
- EU CSIRTs NetworkcoreThe EU CSIRTs Network is the formal cooperative body of national CSIRTs within EU member states, established to support cross-border incident response cooperation. CERT-SE serves as Sweden's representative in this network.
- European Government CERTs Group (EGC)coreThe EGC is a group of European government CERTs that cooperate on threat intelligence sharing, incident coordination, and best practices. CERT-SE participates as Sweden's government CERT.
- International Watch and Warning Network (IWWN)minorIWWN is an international network focused on watch and warning for cybersecurity events. CERT-SE participates in IWWN to exchange threat intelligence with counterpart organizations internationally.
- Swedish CERT-forum (certforum.se)coreThe Swedish CERT-forum is a national coordination body for all CERT activities in Sweden. CERT-SE participates regularly, sharing information and coordinating with Swedish sector-specific and organizational CERTs.
- FIDI (Forum för informationsdelning)coreFIDI forums are sector-specific information-sharing groups for telecom (ITID-FIDI), IT operations (ITOP-FIDI), SCADA/industrial control systems (SCADA-FIDI), and healthcare (SOS-FIDI). CERT-SE participates in these forums to coordinate threat intelligence and incident response across critical sectors.
- GovSec (Government Security Forum)coreGovSec is a forum for Swedish government authorities to share cybersecurity information and coordinate incident response. CERT-SE participates regularly in GovSec meetings to coordinate with government agencies.
- Bilateral national CERT counterparts (international)minorCERT-SE maintains bilateral relationships with equivalent national CERT functions in other countries, developing cooperation and information exchange for cross-border incident response. As Sweden's point of contact for equivalent services in other countries, CERT-SE exchanges information with counterparts in the EU, Nordic region, and globally.
- Polismyndigheten (Swedish Police Authority)coreFrom 1 October 2022, FRA (on behalf of the government) forwards notifications and completed forms reported to FRA that contain descriptions of incidents with a likely criminal basis to the Police Authority (Polismyndigheten) for potential criminal investigation. This includes incident reports filed through CERT-SE's channels that involve suspected cyber crime.
- MCF / Myndigheten för civilt försvar (Swedish Civil Contingencies Agency)corePrior to 1 July 2026, CERT-SE's cyber operations were conducted under MCF (Myndigheten för civilt försvar). On 1 July 2026, the cyber operations transferred from MCF to NCSC at FRA. MCF and NCSC will maintain close cooperation going forward, as cybersecurity is a central part of civil defense. CERT-SE continues to reference MCF's regulations (MSBFS 2020:6, MSBFS 2020:7, MSBFS 2020:8) as the applicable framework for Swedish authorities.
- MISP community (Malware Information Sharing Platform)coreMISP-SE is built on the open-source MISP platform developed by CIRCL (Computer Incident Response Center Luxembourg). CERT-SE participates in the MISP community, using the platform's standard data model for sharing threat indicators (IoCs) including IP addresses, domains, and malware signatures. The platform supports integration with SIEM, SOAR, and other security tools via API.
- NIS entities receiving proactive scanningminorSwedish NIS entities (essential service operators under NIS2) are eligible to request proactive scanning from CERT-SE. As of January 2026, this is a formal right under NIS2 Article 23. Prerequisites include ANTS enrollment and resolution of notifications. Organizations receiving scanning include energy, transport, banking, healthcare, and other critical sectors.
Scale indicators4 records
Recent moves7 records
Expansion highlights5 records
CERT-SE competitors and assessment
Company assessmentDirect peers
- BSI (Bundesamt für Sicherheit in der Informationstechnik): Germany's federal cybersecurity agency. Comparable role as the German national CSIRT, providing vulnerability advisories, incident coordination, and free services to government authorities and critical-infrastructure entities under federal mandate.
- NCSC-UK (National Cyber Security Centre): United Kingdom's national CSIRT/Cybersecurity authority. Direct comparable in mission, statutory role, free incident-response services, vulnerability-disclosure coordination (NCSC Alerts similar to CERT-SE blixtmeddelande), and integration with signals-intelligence parent (GCHQ).
- CIRCL (Computer Incident Response Center Luxembourg): Luxembourg's national CIRCL and the original developer of the open-source MISP platform that underpins CERT-SE's MISP-SE. Direct peer in national-CSIRT mission and unique commonality in MISP platform stewardship.
- NorCERT (Norwegian CERT, part of NSM): Norway's national CERT within the Norwegian Security and Service Organisation (NSM). Nordic regional peer offering similar incident coordination, vulnerability handling, and early-warning services to Norwegian critical sectors.
- ANSSI (Agence nationale de la sécurité des systèmes d'information): France's national cybersecurity agency under the SGDSN. Direct national-CSIRT peer delivering ANTS-equivalent vulnerability bulletins, government incident coordination, and free-of-charge services to French critical-infrastructure operators.
- NCSC-NL (Nationaal Cyber Security Centrum): Netherlands' national CSIRT. Comparable in operating under a government mandate to support Dutch vital infrastructure, issuing vulnerability alerts, and coordinating national incident response — including free-of-charge services to constituency.
- CFCS (Center for Cybersikkerhed, Denmark): Denmark's national cybersecurity authority under the Ministry of Defence. Nordic regional peer providing free incident handling, vulnerability alerts, and threat-intel coordination to Danish public authorities and critical-infrastructure providers.
- CISA (Cybersecurity & Infrastructure Security Agency): United States' national cybersecurity agency within DHS. Comparable in scaling free vulnerability scanning, proactive threat-hunting advisories, and CERT coordination across federal, state, and critical-infrastructure constituencies.
- CERT.at: Austria's national CSIRT, operating as a non-profit under nic.at. Comparable core services (incident coordination, vulnerability warnings, MISP-based threat-intel exchange) and constituency model serving government and critical-infrastructure operators.
Broad incumbents
- ENISA (European Union Agency for Cybersecurity): EU-wide cybersecurity agency coordinating CSIRTs Network and pan-European exercises. As a horizontal coordinator of which CERT-SE is a member, ENISA is a broader incumbent covering regulatory frameworks (NIS2), pan-EU training, and cross-border coordination analogous to CERT-SE's role at the Swedish national level.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights5 records
Customer concentration
CERT-SE social profiles
Digital presenceCERT-SE financial estimates
Financial estimateRevenue estimate
Valuation estimate
CERT-SE leadership team
Management profileNumber of profiles
CERT-SE funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CERT-SE M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CERT-SE
What does CERT-SE do?
CERT-SE is Sweden's national CSIRT providing free-of-charge incident coordination, vulnerability monitoring, and threat intelligence sharing services to Swedish government authorities, NIS entities, and critical infrastructure operators. Its core operational offerings include ANTS (automated daily vulnerability notifications), Proactive Scanning (attack surface assessment for NIS entities), and MISP-SE (a national threat intelligence sharing platform), complemented by 24/7 incident response coordination, ransomware/phishing/DDoS advisory services, tabletop exercises, and subscription-based critical threat alerts and weekly newsletters.
Is CERT-SE a public or private company?
CERT-SE is a private company. It is classified as state government owned and is currently operating.
When was CERT-SE founded?
CERT-SE was founded in -1. It employs 1 to 10 people.
Where is CERT-SE based?
CERT-SE is headquartered in Solna, Sweden, in the Europe region.
How does CERT-SE make money?
One revenue line is on record: public Services — No Revenue Generation.
Who are CERT-SE's main competitors?
Direct peers on record are BSI (Bundesamt für Sicherheit in der Informationstechnik), NCSC-UK (National Cyber Security Centre), CIRCL (Computer Incident Response Center Luxembourg), NorCERT (Norwegian CERT, part of NSM), ANSSI (Agence nationale de la sécurité des systèmes d'information), NCSC-NL (Nationaal Cyber Security Centrum), CFCS (Center for Cybersikkerhed, Denmark), CISA (Cybersecurity & Infrastructure Security Agency) and CERT.at. ENISA (European Union Agency for Cybersecurity) is listed as a broad incumbent.
Does CERT-SE have an API?
No public API is recorded for CERT-SE.
What industry is CERT-SE in?
CERT-SE's product category is National Cybersecurity / CSIRT Services. Its primary akta.pro industry code is BPAEADAI, Security Incident Response (IR) & Digital Forensics Services, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5616 and its SIC code is 7381.