Developer docs
API playgroundTry for free, no card

Search company profiles

CERT-SE

Full company profile

uuid004477r

Namestring
CERT-SE
Legal namestring
CERT-SE
Websiteurl
cert.se
Company typeenum
Private
Founded yearstring
-
Descriptiontext

CERT-SE is Sweden's national CSIRT (Computer Security Incident Response Team), operating as a government agency within the National Cyber Security Centre (Nationellt cybersäkerhetscenter, NCSC) at the Swedish Defence Radio Establishment (Försvarets radioanstalt, FRA). Its mandate, codified under Ordinance (2025:237), covers incident coordination, vulnerability management, and threat intelligence sharing for Swedish government authorities, regional and municipal entities, critical infrastructure operators, and the broader Swedish constituency. On July 1, 2026, CERT-SE's operations transferred from the Swedish Civil Contingencies Agency (MCF) to NCSC at FRA, consolidating national cyber operations.

The core product portfolio comprises three free services: ANTS (Automatisk sårbarhetsnotifiering), which delivers daily CSV-formatted email notifications identifying exposed services, DDoS-amplification vectors, vulnerable services, and suspected compromised devices; Proactive Scanning, which provides a summary of known attack surface plus on-demand intrusive scanning (including credential testing and vulnerability verification) for NIS entities; and MISP-SE, a national instance of the open-source Malware Information Sharing Platform enabling Swedish organizations to share IoCs via API or SAML 2.0/OpenID Connect federation. Supporting capabilities include a 24/7 incident hotline, an RFC-2350-compliant incident handling process aligned with SANS/NIST frameworks, "Blixtmeddelande" critical threat flash alerts (1–3 per year), a weekly "Veckobrev" newsletter, and cybersecurity tabletop exercises. The organization is a full member of FIRST, Trusted Introducer, TF-CSIRT, the EU CSIRTs Network, EGC, and IWWN.

CERT-SE operates under a non-commercial model: all services are free of charge to the Swedish constituency, with funding flowing through FRA appropriations. There is no pricing, no commercial sales motion, and no revenue generation; the distribution model is direct-to-constituency through the cert.se website, email subscriptions, phone hotline, sector-specific forums (FIDI, GovSec), and a Cyberportalen incident reporting portal. The effective date of Sweden's NIS2 cybersecurity law (January 2026) expanded the mandatory reporting constituency and formalized rights to free proactive scanning under Article 23, broadening CERT-SE's mandate.

Short descriptiontext

CERT-SE is Sweden's national CSIRT, operating as a government agency within NCSC at FRA, providing free incident coordination, vulnerability monitoring (ANTS), proactive scanning, and the national MISP-SE threat intelligence sharing platform to Swedish government, critical infrastructure, and private sector organizations.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersSolna, Sweden
HQ citystring
Solna
HQ countrystring
Sweden
HQ regionstring
Europe
Markets served

Serves global market

Offices2 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
national CSIRT services, incident response coordination, threat intelligence sharing, vulnerability monitoring services, cybersecurity advisory
Industry3 codes
1Security Incident Response (IR) & Digital Forensics Services
CodeBPAEADAIPrimaryYes
2Vulnerability Management & Penetration Testing Services
CodeBPAEADADPrimaryNo
3Border Security & Homeland Security
CodeBPAIAHAIPrimaryNo
NAICS code3 codes
  • Investigation and Security Services5616
  • Security Systems Services (except Locksmiths)561621
  • National Security928110
SIC code1 code
  • Services-Detective, Guard & Armored Car Services7381
Product category
National Cybersecurity / CSIRT Services
Social media profiles1 record
GTM motion2 records

Each record includes

Type, Description, Source

Revenue model1 record
1Public Services — No Revenue Generation
TypeSubscription Recurring
Description

CERT-SE is a government agency (part of FRA — Försvarets radioanstalt, the National Defence Radio Establishment) providing all services free of charge to Swedish organizations. The organization is fully financed by FRA. There is no commercial revenue model; services are funded through government appropriations.

cert.se
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels6 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Technology or R&D, Operations, Infrastructure
Pricing details4 tiers
1ANTS — Free for all Swedish organizations
ModelFreemiumBilling cadenceMonthly
Notes

ANTS is a free service available to all Swedish organizations (public and private sector) monitoring internet-facing attack surfaces. No charge for notification delivery.

cert.se
2MISP-SE — Free national threat intelligence sharing platform
ModelFreemiumBilling cadenceMonthly
Notes

MISP-SE is provided at no cost to Swedish entities. Connection via own MISP instance (API sync) or web interface is free. Requires acceptance of Allmänna villkor MISP-SE.

cert.se
3Proaktiv skanning — Free proactive scanning services
ModelFreemiumBilling cadenceAnnual
Notes

Both 'Sammanställning av känd angreppsyta' and 'Skanning från CERT-SE på begäran' are free services for Swedish organizations. Prerequisites include ANTS enrollment and resolution of notifications.

cert.se
4Blixtmeddelande, Veckobrev, MISP-SE nyhetsbrev — Free email subscriptions
ModelFreemiumBilling cadenceMonthly
Notes

All email subscription services are free. Subscriptions include: blixtmeddelande (1–3/year for critical threats), veckobrev (weekly on Fridays), and MISP-SE monthly newsletter. RSS feed also available free of charge.

cert.se
GTM typeB2B
B2B
Offering typeServices
Services
Brand1 of 3 records shown
1ANTS (Automatiska notifieringar om tekniska sårbarheter)
Description

Free service for Swedish organizations to monitor internet-facing assets for vulnerabilities

cert.se
+2 more records
Core offering1 text field

CERT-SE is Sweden's national CSIRT providing free-of-charge incident coordination, vulnerability monitoring, and threat intelligence sharing services to Swedish government authorities, NIS entities, and critical infrastructure operators. Its core operational offerings include ANTS (automated daily vulnerability notifications), Proactive Scanning (attack surface assessment for NIS entities), and MISP-SE (a national threat intelligence sharing platform), complemented by 24/7 incident response coordination, ransomware/phishing/DDoS advisory services, tabletop exercises, and subscription-based critical threat alerts and weekly newsletters.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • 1–3 blixtmeddelande (critical threat alerts) sent per year, reaching thousands of Swedish organizations immediately
+3 more records
Product overview1 text field

CERT-SE (Computer Emergency Response Team – Sverige) is Sweden's national CSIRT, operating within the National Cyber Security Centre (NCSC) at the Swedish Defence Radio Establishment (FRA). CERT-SE's portfolio consists of a coordinated set of free services aimed at helping Swedish organizations prevent and manage IT security incidents. The core offerings include: ANTS (Automatisk Nätverksbaserad Teknisk Sårbarhetsövervakning), an automated notification service for internet-facing vulnerabilities; Proaktiv skanning, proactive scanning of internet attack surfaces; and MISP-SE, a national MISP instance for structured threat intelligence sharing. These are complemented by thematic advisory services covering ransomware, phishing, and DDoS, tabletop exercise materials for incident management training, and email subscription products (weekly newsletters and flash alerts for critical threats). MISP-SE exercises are also offered to build operational capability in the Swedish cybersecurity community.

Product and service10 records
1ANTS (Automatisk Nätverksbaserad Teknisk Sårbarhetsövervakning)
CategoryCore service - vulnerability monitoring
Description

Automated notification service that alerts Swedish organizations when technical vulnerabilities are detected in their internet-facing assets, identifying publicly exposed services, services usable for DDoS amplification, potentially vulnerable services, and suspected compromised devices. Notifications are sent daily via email in CSV format.

2Proaktiv skanning (Proactive Scanning)
CategoryCore service - vulnerability assessment
Description

A collection of free scanning services including a summary of known attack surface data and on-demand technical scanning including login attempts with common credentials and vulnerability verification, available to NIS entities upon request and completion of ANTS enrollment prerequisites.

3MISP-SE
CategoryCore service - threat intelligence platform
Description

A national, free instance of the open-source Malware Information Sharing Platform (MISP) that enables Swedish organizations to collect, store, analyze, and share cyber threat indicators including IP addresses, domains, and malware signatures. Supports API-based MISP-to-MISP synchronization and web interface access with SAML 2.0/OpenID Connect federation. Includes threat intelligence correlation aligned with NIST CSF 2.0 phases.

4Ransomware guidance and support
CategoryAdvisory service
Description

Advice and guidance for organizations on preventing and managing ransomware attacks, including technical mitigation steps, communication planning, and recovery procedures.

5Phishing (nätfiske) guidance
CategoryAdvisory service
Description

Advisory resources for preventing and responding to phishing attacks, including recommendations for multi-factor authentication, password policies, and user awareness training.

6DDoS guidance
CategoryAdvisory service
Description

Guidance on preventing and handling distributed denial-of-service attacks, including mitigation techniques and recommendations for maintaining service availability.

7Tabletop exercises for incident management
CategoryAdvisory service - training material
Description

Simple, short tabletop exercise materials for handling ransomware, DDoS, and phishing incidents, designed for small and medium-sized municipalities, companies, and organizations.

8CERT-SE email subscriptions (Blixtmeddelande, Veckobrev, MISP-SE nyhetsbrev)
CategoryCommunication service
Description

Free email subscription services including Blixtmeddelande for critical threat alerts requiring immediate action, Veckobrev with weekly cybersecurity news delivered every Friday, and MISP-SE monthly newsletter. Also available as an RSS feed.

9MISP-SE cybersecurity exercises
CategoryAdvisory service - training
Description

Technical cybersecurity exercises focused on MISP and incident handling, designed to strengthen the operational capability of Swedish organizations for cyber threat information sharing.

10IT incident response coordination
CategoryCore service - incident coordination
Description

Core incident handling service providing 24/7/365 support to organizations affected by IT security incidents, following the Förebygga, Identifiera, Begränsa, Återställa, Erfarenheter process aligned with SANS and NIST incident response frameworks.

Scale indicator4 records

Each record includes

Type, Value, Description, Source

Partnership16 partners
Strategic tierCoreTypeOthers
Description

CERT-SE is fully embedded within FRA, Sweden's National Defence Radio Establishment. The organization operates under Ordinance (2025:237) with instructions for FRA, and is fully financed by FRA. CERT-SE's address and operations are at FRA's facilities (Terminalvägen 14, Solna). FRA handles all administrative functions including HR, finance, and legal compliance. CERT-SE is the operational cybersecurity arm of FRA's National Cyber Security Centre.

Strategic tierCoreTypeOthers
Description

As of 1 July 2026, CERT-SE becomes fully integrated into the National Cyber Security Centre (NCSC) at FRA. NCSC-SE serves as the overarching coordination body for all cybersecurity activities in Sweden. CERT-SE is the operational CSIRT within NCSC-SE. The two entities share leadership, staff, and facilities. NCSC publishes cybersecurity guidance (Cybersäkerhet i Sverige reports), manages the cybersecurity law (NIS2) implementation, and coordinates national cyber exercises.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

FIRST is a premier global organization of CSIRTs. As a full member, CERT-SE participates in international incident response coordination, accesses the FIRST member directory, and engages in global best practice development. FIRST membership provides access to shared tooling, standards, and training resources for the global CERT community.

4Trusted Introducer
Strategic tierCoreTypeStrategic or Co-development Partner
Description

Trusted Introducer is a certification and directory service for European CERTs. CERT-SE is certified by Trusted Introducer, which validates the organization's legitimacy, operational capability, and adherence to standards. The certification is listed at https://www.trusted-introducer.org/directory/teams/cert-se.html.

cert.se
Strategic tierCoreTypeStrategic or Co-development Partner
Description

TF-CSIRT is a European task force working to improve CERT collaboration and maturity across Europe. Membership enables CERT-SE to engage in cross-border CERT development initiatives, share methodologies, and participate in joint working groups.

6EU CSIRTs Network
Strategic tierCoreTypeStrategic or Co-development Partner
Description

The EU CSIRTs Network is the formal cooperative body of national CSIRTs within EU member states, established to support cross-border incident response cooperation. CERT-SE serves as Sweden's representative in this network.

cert.se
7European Government CERTs Group (EGC)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

The EGC is a group of European government CERTs that cooperate on threat intelligence sharing, incident coordination, and best practices. CERT-SE participates as Sweden's government CERT.

cert.se
8International Watch and Warning Network (IWWN)
Strategic tierMinorTypeStrategic or Co-development Partner
Description

IWWN is an international network focused on watch and warning for cybersecurity events. CERT-SE participates in IWWN to exchange threat intelligence with counterpart organizations internationally.

cert.se
9Swedish CERT-forum (certforum.se)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

The Swedish CERT-forum is a national coordination body for all CERT activities in Sweden. CERT-SE participates regularly, sharing information and coordinating with Swedish sector-specific and organizational CERTs.

cert.se
Strategic tierCoreTypeStrategic or Co-development Partner
Description

FIDI forums are sector-specific information-sharing groups for telecom (ITID-FIDI), IT operations (ITOP-FIDI), SCADA/industrial control systems (SCADA-FIDI), and healthcare (SOS-FIDI). CERT-SE participates in these forums to coordinate threat intelligence and incident response across critical sectors.

11GovSec (Government Security Forum)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

GovSec is a forum for Swedish government authorities to share cybersecurity information and coordinate incident response. CERT-SE participates regularly in GovSec meetings to coordinate with government agencies.

cert.se
12Bilateral national CERT counterparts (international)
Strategic tierMinorTypeStrategic or Co-development Partner
Description

CERT-SE maintains bilateral relationships with equivalent national CERT functions in other countries, developing cooperation and information exchange for cross-border incident response. As Sweden's point of contact for equivalent services in other countries, CERT-SE exchanges information with counterparts in the EU, Nordic region, and globally.

cert.se
13Polismyndigheten (Swedish Police Authority)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

From 1 October 2022, FRA (on behalf of the government) forwards notifications and completed forms reported to FRA that contain descriptions of incidents with a likely criminal basis to the Police Authority (Polismyndigheten) for potential criminal investigation. This includes incident reports filed through CERT-SE's channels that involve suspected cyber crime.

cert.se
14MCF / Myndigheten för civilt försvar (Swedish Civil Contingencies Agency)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

Prior to 1 July 2026, CERT-SE's cyber operations were conducted under MCF (Myndigheten för civilt försvar). On 1 July 2026, the cyber operations transferred from MCF to NCSC at FRA. MCF and NCSC will maintain close cooperation going forward, as cybersecurity is a central part of civil defense. CERT-SE continues to reference MCF's regulations (MSBFS 2020:6, MSBFS 2020:7, MSBFS 2020:8) as the applicable framework for Swedish authorities.

cert.se
Strategic tierCoreTypeTechnology or Integration
Description

MISP-SE is built on the open-source MISP platform developed by CIRCL (Computer Incident Response Center Luxembourg). CERT-SE participates in the MISP community, using the platform's standard data model for sharing threat indicators (IoCs) including IP addresses, domains, and malware signatures. The platform supports integration with SIEM, SOAR, and other security tools via API.

Strategic tierMinorTypeOthers
Description

Swedish NIS entities (essential service operators under NIS2) are eligible to request proactive scanning from CERT-SE. As of January 2026, this is a formal right under NIS2 Article 23. Prerequisites include ANTS enrollment and resolution of notifications. Organizations receiving scanning include energy, transport, banking, healthcare, and other critical sectors.

Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Peers10 records
1BSI (Bundesamt für Sicherheit in der Informationstechnik)
TypeDirect peer
Description

Germany's federal cybersecurity agency. Comparable role as the German national CSIRT, providing vulnerability advisories, incident coordination, and free services to government authorities and critical-infrastructure entities under federal mandate.

TypeDirect peer
Description

United Kingdom's national CSIRT/Cybersecurity authority. Direct comparable in mission, statutory role, free incident-response services, vulnerability-disclosure coordination (NCSC Alerts similar to CERT-SE blixtmeddelande), and integration with signals-intelligence parent (GCHQ).

TypeBroad incumbent
Description

EU-wide cybersecurity agency coordinating CSIRTs Network and pan-European exercises. As a horizontal coordinator of which CERT-SE is a member, ENISA is a broader incumbent covering regulatory frameworks (NIS2), pan-EU training, and cross-border coordination analogous to CERT-SE's role at the Swedish national level.

4CIRCL (Computer Incident Response Center Luxembourg)
TypeDirect peer
Description

Luxembourg's national CIRCL and the original developer of the open-source MISP platform that underpins CERT-SE's MISP-SE. Direct peer in national-CSIRT mission and unique commonality in MISP platform stewardship.

5NorCERT (Norwegian CERT, part of NSM)
TypeDirect peer
Description

Norway's national CERT within the Norwegian Security and Service Organisation (NSM). Nordic regional peer offering similar incident coordination, vulnerability handling, and early-warning services to Norwegian critical sectors.

TypeDirect peer
Description

France's national cybersecurity agency under the SGDSN. Direct national-CSIRT peer delivering ANTS-equivalent vulnerability bulletins, government incident coordination, and free-of-charge services to French critical-infrastructure operators.

TypeDirect peer
Description

Netherlands' national CSIRT. Comparable in operating under a government mandate to support Dutch vital infrastructure, issuing vulnerability alerts, and coordinating national incident response — including free-of-charge services to constituency.

TypeDirect peer
Description

Denmark's national cybersecurity authority under the Ministry of Defence. Nordic regional peer providing free incident handling, vulnerability alerts, and threat-intel coordination to Danish public authorities and critical-infrastructure providers.

TypeDirect peer
Description

United States' national cybersecurity agency within DHS. Comparable in scaling free vulnerability scanning, proactive threat-hunting advisories, and CERT coordination across federal, state, and critical-infrastructure constituencies.

TypeDirect peer
Description

Austria's national CSIRT, operating as a non-profit under nic.at. Comparable core services (incident coordination, vulnerability warnings, MISP-based threat-intel exchange) and constituency model serving government and critical-infrastructure operators.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat4 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights5 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature6 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

CERT-SE

National Cybersecurity / CSIRT Servicescert.se

CERT-SE is Sweden's national CSIRT, operating as a government agency within NCSC at FRA, providing free incident coordination, vulnerability monitoring (ANTS), proactive scanning, and the national MISP-SE threat intelligence sharing platform to Swedish government, critical infrastructure, and private sector organizations.

What CERT-SE does

CERT-SE is Sweden's national CSIRT (Computer Security Incident Response Team), operating as a government agency within the National Cyber Security Centre (Nationellt cybersäkerhetscenter, NCSC) at the Swedish Defence Radio Establishment (Försvarets radioanstalt, FRA). Its mandate, codified under Ordinance (2025:237), covers incident coordination, vulnerability management, and threat intelligence sharing for Swedish government authorities, regional and municipal entities, critical infrastructure operators, and the broader Swedish constituency. On July 1, 2026, CERT-SE's operations transferred from the Swedish Civil Contingencies Agency (MCF) to NCSC at FRA, consolidating national cyber operations.

The core product portfolio comprises three free services: ANTS (Automatisk sårbarhetsnotifiering), which delivers daily CSV-formatted email notifications identifying exposed services, DDoS-amplification vectors, vulnerable services, and suspected compromised devices; Proactive Scanning, which provides a summary of known attack surface plus on-demand intrusive scanning (including credential testing and vulnerability verification) for NIS entities; and MISP-SE, a national instance of the open-source Malware Information Sharing Platform enabling Swedish organizations to share IoCs via API or SAML 2.0/OpenID Connect federation. Supporting capabilities include a 24/7 incident hotline, an RFC-2350-compliant incident handling process aligned with SANS/NIST frameworks, "Blixtmeddelande" critical threat flash alerts (1–3 per year), a weekly "Veckobrev" newsletter, and cybersecurity tabletop exercises. The organization is a full member of FIRST, Trusted Introducer, TF-CSIRT, the EU CSIRTs Network, EGC, and IWWN.

CERT-SE operates under a non-commercial model: all services are free of charge to the Swedish constituency, with funding flowing through FRA appropriations. There is no pricing, no commercial sales motion, and no revenue generation; the distribution model is direct-to-constituency through the cert.se website, email subscriptions, phone hotline, sector-specific forums (FIDI, GovSec), and a Cyberportalen incident reporting portal. The effective date of Sweden's NIS2 cybersecurity law (January 2026) expanded the mandatory reporting constituency and formalized rights to free proactive scanning under Article 23, broadening CERT-SE's mandate.

CERT-SE firmographics

Firmographics
Name
CERT-SE
Legal name
CERT-SE
Website
https://cert.se
Company type
Private
Operating status
Operating
Headcount range
1–10 employees
Short description
CERT-SE is Sweden's national CSIRT, operating as a government agency within NCSC at FRA, providing free incident coordination, vulnerability monitoring (ANTS), proactive scanning, and the national MISP-SE threat intelligence sharing platform to Swedish government, critical infrastructure, and private sector organizations.
Ownership category
akta.pro rank

CERT-SE industry classification

Industry
Product category
National Cybersecurity / CSIRT Services
NAICS
Investigation and Security Services (5616), Security Systems Services (except Locksmiths) (561621), National Security (928110)
SIC
Services-Detective, Guard & Armored Car Services (7381)
akta.pro primary industry
Security Incident Response (IR) & Digital Forensics Services (BPAEADAI)
akta.pro secondary industries
Vulnerability Management & Penetration Testing Services (BPAEADAD), Border Security & Homeland Security (BPAIAHAI)

Keywords

  • National CSIRT services
  • Incident response coordination
  • Threat intelligence sharing
  • Vulnerability monitoring services
  • Cybersecurity advisory

Where CERT-SE is headquartered

Location

Headquarters

HQ city
Solna
HQ country
Sweden
HQ region
Europe

Offices2 records

Markets served

CERT-SE business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Technology or R&D, Operations, Infrastructure

Revenue model

  1. Public Services — No Revenue Generation: CERT-SE is a government agency (part of FRA — Försvarets radioanstalt, the National Defence Radio Establishment) providing all services free of charge to Swedish organizations. The organization is fully financed by FRA. There is no commercial revenue model; services are funded through government appropriations.

Pricing tiers

ModelBillingPrice
FreemiumMonthlyANTS — Free for all Swedish organizations
FreemiumMonthlyMISP-SE — Free national threat intelligence sharing platform
FreemiumAnnualProaktiv skanning — Free proactive scanning services
FreemiumMonthlyBlixtmeddelande, Veckobrev, MISP-SE nyhetsbrev — Free email subscriptions

Go-to-market motion2 records

Distribution channels6 records

Marketing channels7 records

CERT-SE product offering

Product offering

Core offering

CERT-SE is Sweden's national CSIRT providing free-of-charge incident coordination, vulnerability monitoring, and threat intelligence sharing services to Swedish government authorities, NIS entities, and critical infrastructure operators. Its core operational offerings include ANTS (automated daily vulnerability notifications), Proactive Scanning (attack surface assessment for NIS entities), and MISP-SE (a national threat intelligence sharing platform), complemented by 24/7 incident response coordination, ransomware/phishing/DDoS advisory services, tabletop exercises, and subscription-based critical threat alerts and weekly newsletters.

Product overview

CERT-SE (Computer Emergency Response Team – Sverige) is Sweden's national CSIRT, operating within the National Cyber Security Centre (NCSC) at the Swedish Defence Radio Establishment (FRA). CERT-SE's portfolio consists of a coordinated set of free services aimed at helping Swedish organizations prevent and manage IT security incidents. The core offerings include: ANTS (Automatisk Nätverksbaserad Teknisk Sårbarhetsövervakning), an automated notification service for internet-facing vulnerabilities; Proaktiv skanning, proactive scanning of internet attack surfaces; and MISP-SE, a national MISP instance for structured threat intelligence sharing. These are complemented by thematic advisory services covering ransomware, phishing, and DDoS, tabletop exercise materials for incident management training, and email subscription products (weekly newsletters and flash alerts for critical threats). MISP-SE exercises are also offered to build operational capability in the Swedish cybersecurity community.

Differentiator

Problem solved

Functional benefit

Brands

  • ANTS (Automatiska notifieringar om tekniska sårbarheter): Free service for Swedish organizations to monitor internet-facing assets for vulnerabilities
  • Proaktiv skanning (Proactive Scanning)
  • MISP-SE

Products and services

  • ANTS (Automatisk Nätverksbaserad Teknisk Sårbarhetsövervakning) Automated notification service that alerts Swedish organizations when technical vulnerabilities are detected in their internet-facing assets, identifying publicly exposed services, services usable for DDoS amplification, potentially vulnerable services, and suspected compromised devices. Notifications are sent daily via email in CSV format.
  • Proaktiv skanning (Proactive Scanning) A collection of free scanning services including a summary of known attack surface data and on-demand technical scanning including login attempts with common credentials and vulnerability verification, available to NIS entities upon request and completion of ANTS enrollment prerequisites.
  • MISP-SE A national, free instance of the open-source Malware Information Sharing Platform (MISP) that enables Swedish organizations to collect, store, analyze, and share cyber threat indicators including IP addresses, domains, and malware signatures. Supports API-based MISP-to-MISP synchronization and web interface access with SAML 2.0/OpenID Connect federation. Includes threat intelligence correlation aligned with NIST CSF 2.0 phases.
  • Ransomware guidance and support Advice and guidance for organizations on preventing and managing ransomware attacks, including technical mitigation steps, communication planning, and recovery procedures.
  • Phishing (nätfiske) guidance Advisory resources for preventing and responding to phishing attacks, including recommendations for multi-factor authentication, password policies, and user awareness training.
  • DDoS guidance Guidance on preventing and handling distributed denial-of-service attacks, including mitigation techniques and recommendations for maintaining service availability.
  • Tabletop exercises for incident management Simple, short tabletop exercise materials for handling ransomware, DDoS, and phishing incidents, designed for small and medium-sized municipalities, companies, and organizations.
  • CERT-SE email subscriptions (Blixtmeddelande, Veckobrev, MISP-SE nyhetsbrev) Free email subscription services including Blixtmeddelande for critical threat alerts requiring immediate action, Veckobrev with weekly cybersecurity news delivered every Friday, and MISP-SE monthly newsletter. Also available as an RSS feed.
  • MISP-SE cybersecurity exercises Technical cybersecurity exercises focused on MISP and incident handling, designed to strengthen the operational capability of Swedish organizations for cyber threat information sharing.
  • IT incident response coordination Core incident handling service providing 24/7/365 support to organizations affected by IT security incidents, following the Förebygga, Identifiera, Begränsa, Återställa, Erfarenheter process aligned with SANS and NIST incident response frameworks.

Quantifiable outcome

  • 1–3 blixtmeddelande (critical threat alerts) sent per year, reaching thousands of Swedish organizations immediately
  • +3 more outcomes

Companies that use CERT-SE

Customer profile

Segments4 records

Ideal customer profiles3 records

CERT-SE technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature6 records

CERT-SE partnerships and signals

Strategic signal

Partnerships

16 partnerships are on record, tiered core and minor.

  • FRA (Försvarets radioanstalt — National Defence Radio Establishment)coreOthersCERT-SE is fully embedded within FRA, Sweden's National Defence Radio Establishment. The organization operates under Ordinance (2025:237) with instructions for FRA, and is fully financed by FRA. CERT-SE's address and operations are at FRA's facilities (Terminalvägen 14, Solna). FRA handles all administrative functions including HR, finance, and legal compliance. CERT-SE is the operational cybersecurity arm of FRA's National Cyber Security Centre.
  • NCSC-SE (Nationellt Cybersäkerhetscenter — National Cyber Security Centre)coreOthersAs of 1 July 2026, CERT-SE becomes fully integrated into the National Cyber Security Centre (NCSC) at FRA. NCSC-SE serves as the overarching coordination body for all cybersecurity activities in Sweden. CERT-SE is the operational CSIRT within NCSC-SE. The two entities share leadership, staff, and facilities. NCSC publishes cybersecurity guidance (Cybersäkerhet i Sverige reports), manages the cybersecurity law (NIS2) implementation, and coordinates national cyber exercises.
  • FIRST (Forum of Incident Response and Security Teams)coreStrategic or Co-development PartnerFIRST is a premier global organization of CSIRTs. As a full member, CERT-SE participates in international incident response coordination, accesses the FIRST member directory, and engages in global best practice development. FIRST membership provides access to shared tooling, standards, and training resources for the global CERT community.
  • Trusted IntroducercoreStrategic or Co-development PartnerTrusted Introducer is a certification and directory service for European CERTs. CERT-SE is certified by Trusted Introducer, which validates the organization's legitimacy, operational capability, and adherence to standards. The certification is listed at https://www.trusted-introducer.org/directory/teams/cert-se.html.
  • TF-CSIRTcoreStrategic or Co-development PartnerTF-CSIRT is a European task force working to improve CERT collaboration and maturity across Europe. Membership enables CERT-SE to engage in cross-border CERT development initiatives, share methodologies, and participate in joint working groups.
  • EU CSIRTs NetworkcoreStrategic or Co-development PartnerThe EU CSIRTs Network is the formal cooperative body of national CSIRTs within EU member states, established to support cross-border incident response cooperation. CERT-SE serves as Sweden's representative in this network.
  • European Government CERTs Group (EGC)coreStrategic or Co-development PartnerThe EGC is a group of European government CERTs that cooperate on threat intelligence sharing, incident coordination, and best practices. CERT-SE participates as Sweden's government CERT.
  • International Watch and Warning Network (IWWN)minorStrategic or Co-development PartnerIWWN is an international network focused on watch and warning for cybersecurity events. CERT-SE participates in IWWN to exchange threat intelligence with counterpart organizations internationally.
  • Swedish CERT-forum (certforum.se)coreStrategic or Co-development PartnerThe Swedish CERT-forum is a national coordination body for all CERT activities in Sweden. CERT-SE participates regularly, sharing information and coordinating with Swedish sector-specific and organizational CERTs.
  • FIDI (Forum för informationsdelning)coreStrategic or Co-development PartnerFIDI forums are sector-specific information-sharing groups for telecom (ITID-FIDI), IT operations (ITOP-FIDI), SCADA/industrial control systems (SCADA-FIDI), and healthcare (SOS-FIDI). CERT-SE participates in these forums to coordinate threat intelligence and incident response across critical sectors.
  • GovSec (Government Security Forum)coreStrategic or Co-development PartnerGovSec is a forum for Swedish government authorities to share cybersecurity information and coordinate incident response. CERT-SE participates regularly in GovSec meetings to coordinate with government agencies.
  • Bilateral national CERT counterparts (international)minorStrategic or Co-development PartnerCERT-SE maintains bilateral relationships with equivalent national CERT functions in other countries, developing cooperation and information exchange for cross-border incident response. As Sweden's point of contact for equivalent services in other countries, CERT-SE exchanges information with counterparts in the EU, Nordic region, and globally.
  • Polismyndigheten (Swedish Police Authority)coreStrategic or Co-development PartnerFrom 1 October 2022, FRA (on behalf of the government) forwards notifications and completed forms reported to FRA that contain descriptions of incidents with a likely criminal basis to the Police Authority (Polismyndigheten) for potential criminal investigation. This includes incident reports filed through CERT-SE's channels that involve suspected cyber crime.
  • MCF / Myndigheten för civilt försvar (Swedish Civil Contingencies Agency)coreStrategic or Co-development PartnerPrior to 1 July 2026, CERT-SE's cyber operations were conducted under MCF (Myndigheten för civilt försvar). On 1 July 2026, the cyber operations transferred from MCF to NCSC at FRA. MCF and NCSC will maintain close cooperation going forward, as cybersecurity is a central part of civil defense. CERT-SE continues to reference MCF's regulations (MSBFS 2020:6, MSBFS 2020:7, MSBFS 2020:8) as the applicable framework for Swedish authorities.
  • MISP community (Malware Information Sharing Platform)coreTechnology or IntegrationMISP-SE is built on the open-source MISP platform developed by CIRCL (Computer Incident Response Center Luxembourg). CERT-SE participates in the MISP community, using the platform's standard data model for sharing threat indicators (IoCs) including IP addresses, domains, and malware signatures. The platform supports integration with SIEM, SOAR, and other security tools via API.
  • NIS entities receiving proactive scanningminorOthersSwedish NIS entities (essential service operators under NIS2) are eligible to request proactive scanning from CERT-SE. As of January 2026, this is a formal right under NIS2 Article 23. Prerequisites include ANTS enrollment and resolution of notifications. Organizations receiving scanning include energy, transport, banking, healthcare, and other critical sectors.

Scale indicators4 records

Recent moves7 records

Expansion highlights5 records

CERT-SE competitors and assessment

Company assessment

Direct peers

  • BSI (Bundesamt für Sicherheit in der Informationstechnik): Germany's federal cybersecurity agency. Comparable role as the German national CSIRT, providing vulnerability advisories, incident coordination, and free services to government authorities and critical-infrastructure entities under federal mandate.
  • NCSC-UK (National Cyber Security Centre): United Kingdom's national CSIRT/Cybersecurity authority. Direct comparable in mission, statutory role, free incident-response services, vulnerability-disclosure coordination (NCSC Alerts similar to CERT-SE blixtmeddelande), and integration with signals-intelligence parent (GCHQ).
  • CIRCL (Computer Incident Response Center Luxembourg): Luxembourg's national CIRCL and the original developer of the open-source MISP platform that underpins CERT-SE's MISP-SE. Direct peer in national-CSIRT mission and unique commonality in MISP platform stewardship.
  • NorCERT (Norwegian CERT, part of NSM): Norway's national CERT within the Norwegian Security and Service Organisation (NSM). Nordic regional peer offering similar incident coordination, vulnerability handling, and early-warning services to Norwegian critical sectors.
  • ANSSI (Agence nationale de la sécurité des systèmes d'information): France's national cybersecurity agency under the SGDSN. Direct national-CSIRT peer delivering ANTS-equivalent vulnerability bulletins, government incident coordination, and free-of-charge services to French critical-infrastructure operators.
  • NCSC-NL (Nationaal Cyber Security Centrum): Netherlands' national CSIRT. Comparable in operating under a government mandate to support Dutch vital infrastructure, issuing vulnerability alerts, and coordinating national incident response — including free-of-charge services to constituency.
  • CFCS (Center for Cybersikkerhed, Denmark): Denmark's national cybersecurity authority under the Ministry of Defence. Nordic regional peer providing free incident handling, vulnerability alerts, and threat-intel coordination to Danish public authorities and critical-infrastructure providers.
  • CISA (Cybersecurity & Infrastructure Security Agency): United States' national cybersecurity agency within DHS. Comparable in scaling free vulnerability scanning, proactive threat-hunting advisories, and CERT coordination across federal, state, and critical-infrastructure constituencies.
  • CERT.at: Austria's national CSIRT, operating as a non-profit under nic.at. Comparable core services (incident coordination, vulnerability warnings, MISP-based threat-intel exchange) and constituency model serving government and critical-infrastructure operators.

Broad incumbents

  • ENISA (European Union Agency for Cybersecurity): EU-wide cybersecurity agency coordinating CSIRTs Network and pan-European exercises. As a horizontal coordinator of which CERT-SE is a member, ENISA is a broader incumbent covering regulatory frameworks (NIS2), pan-EU training, and cross-border coordination analogous to CERT-SE's role at the Swedish national level.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat4 records

Key risks5 records

Key highlights5 records

Customer concentration

CERT-SE social profiles

Digital presence

CERT-SE financial estimates

Financial estimate

Revenue estimate

Valuation estimate

CERT-SE leadership team

Management profile

Number of profiles

CERT-SE funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

CERT-SE M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about CERT-SE

What does CERT-SE do?

CERT-SE is Sweden's national CSIRT providing free-of-charge incident coordination, vulnerability monitoring, and threat intelligence sharing services to Swedish government authorities, NIS entities, and critical infrastructure operators. Its core operational offerings include ANTS (automated daily vulnerability notifications), Proactive Scanning (attack surface assessment for NIS entities), and MISP-SE (a national threat intelligence sharing platform), complemented by 24/7 incident response coordination, ransomware/phishing/DDoS advisory services, tabletop exercises, and subscription-based critical threat alerts and weekly newsletters.

Is CERT-SE a public or private company?

CERT-SE is a private company. It is classified as state government owned and is currently operating.

When was CERT-SE founded?

CERT-SE was founded in -1. It employs 1 to 10 people.

Where is CERT-SE based?

CERT-SE is headquartered in Solna, Sweden, in the Europe region.

How does CERT-SE make money?

One revenue line is on record: public Services — No Revenue Generation.

Who are CERT-SE's main competitors?

Direct peers on record are BSI (Bundesamt für Sicherheit in der Informationstechnik), NCSC-UK (National Cyber Security Centre), CIRCL (Computer Incident Response Center Luxembourg), NorCERT (Norwegian CERT, part of NSM), ANSSI (Agence nationale de la sécurité des systèmes d'information), NCSC-NL (Nationaal Cyber Security Centrum), CFCS (Center for Cybersikkerhed, Denmark), CISA (Cybersecurity & Infrastructure Security Agency) and CERT.at. ENISA (European Union Agency for Cybersecurity) is listed as a broad incumbent.

Does CERT-SE have an API?

No public API is recorded for CERT-SE.

What industry is CERT-SE in?

CERT-SE's product category is National Cybersecurity / CSIRT Services. Its primary akta.pro industry code is BPAEADAI, Security Incident Response (IR) & Digital Forensics Services, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5616 and its SIC code is 7381.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales