CIS - Certification & Information Security Services
CIS is a Vienna-headquartered, state-accredited certification body that audits and certifies management systems across ISO/IEC standards (27001, 42001 AI, 22301, 20000, 27701), EN 50600, TISAX, and Austrian NISG 2026 (NIS-2), serving essential entities, automotive, energy, and data center operators via direct sales and subsidiaries in five Central and Eastern European countries.
- Company typePrivate
- Founded2018
- HeadquartersVienna, Austria
- Headcount11–50
- GTM typeB2B
- OfferingServices
What CIS - Certification & Information Security Services does
CIS - Certification & Information Security Services GmbH is a Vienna-headquartered, state-accredited certification body specializing in management system certifications across information security, data protection, AI, business continuity, IT service management, cloud, energy, and data center domains. Its core portfolio centers on ISO/IEC standards (27001, 27017, 27018, 27019, 27701, 20000, 22301, 42001), EN 50600 data center standards, TISAX for the automotive sector, and Austrian NISG 2026 (NIS-2) compliance examinations. CIS also delivers person certifications and accredited training programs (Information Security Manager/Auditor, AI Manager/Auditor, Business Continuity Manager/Auditor) through its own programs and via the co-founded Cyber Leaders Academy with KPMG Austria and FH St. Pölten.
The company generates revenue through a hybrid model: multi-year, recurring system certification projects (3-year certificate validity with annual surveillance audits) supplemented by professional services in training, person certification, and pre-audit advisory (Stage Reviews, integrated/combined audits). Pricing is custom and quote-based, determined by certification scope, organization size, sites, and applicable standards. CIS issues 65% of all ISO 27001 certificates in Austria, was the first Austrian body accredited for EN 50600 data center audits and to issue an ISO 42001 AI management certificate, and has been a qualified NIS testing body since February 2020.
Distribution combines direct enterprise field sales with five majority-owned subsidiaries (Austria, Czech Republic, Switzerland, Poland, Hungary, with Slovakia referenced in some materials) and a partner network spanning over 30 countries. Marketing is anchored by the annual CIS Compliance Summit in Vienna (280+ attendees, CISO of the Year award), LinkedIn presence, bi-monthly newsletter, and proprietary thought leadership including the annual ISO 27001 Statusreport. CIS is a wholly-owned subsidiary of Quality Austria Holding GmbH, with sister companies supporting integrated management system audits across quality, environmental, and occupational safety standards.
CIS - Certification & Information Security Services firmographics
Firmographics- Name
- CIS - Certification & Information Security Services
- Legal name
- CIS - Certification & Information Security Services GmbH
- Website
- https://cis-cert.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CIS is a Vienna-headquartered, state-accredited certification body that audits and certifies management systems across ISO/IEC standards (27001, 42001 AI, 22301, 20000, 27701), EN 50600, TISAX, and Austrian NISG 2026 (NIS-2), serving essential entities, automotive, energy, and data center operators via direct sales and subsidiaries in five Central and Eastern European countries.
- Ownership category
- akta.pro rank
CIS - Certification & Information Security Services industry classification
Industry- Product category
- Information Security Certification Services
- NAICS
- Professional and Management Development Training (611430), Educational Services (611)
- SIC
- Services-Educational Services (8200)
- akta.pro primary industry
- Sales, Marketing & Digital Marketing Certifications (EDAAANAF)
Keywords
Where CIS - Certification & Information Security Services is headquartered
LocationHeadquarters
- HQ city
- Vienna
- HQ country
- Austria
- HQ region
- Europe
Offices5 records
Markets served
CIS - Certification & Information Security Services business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D
Revenue model
- System Certification Services: CIS generates primary revenue through system certifications for management systems including ISO 27001, NIS-2, TISAX, ISO 42001, ISO 22301, ISO 20000, and related standards. Revenue is project-based, with multi-year certification cycles (certificates valid for 3 years with annual surveillance audits).
- Training and Person Certification: CIS offers training programs and professional certifications including Information Security Manager, Information Security Auditor, AI Manager, AI Auditor, Business Continuity Manager, Business Continuity Auditor, Data Protection Manager, and specialized seminars. Training includes in-house and public formats with certification exams.
- NIS-2/NISG Compliance Services: As a qualified testing body for NIS examinations in Austria since 2018, CIS provides NISG 2026 compliance assessments and combined audits with ISO 27001 certifications for essential and important entities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom Quote-Based Pricing |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels5 records
CIS - Certification & Information Security Services product offering
Product offeringCore offering
CIS is the leading Austrian certification body for information security and management systems, delivering accredited third-party audits and certifications against standards including ISO 27001, ISO 27017/27018, ISO 27019, ISO 20000-1, ISO 9001, NIS-2, TISAX, AQAP, and ISO 42001 (AI management systems). The company also runs structured training programs and events through its Quality Austria Training affiliate, serving 80+ certifications and 350+ training engagements annually across regulated and high-trust industries such as automotive, energy, and AI-driven enterprises.
Product overview
CIS - Certification & Information Security Services operates as an accredited certification body offering a portfolio of system certifications and professional training programs. The core offering centers on ISO/IEC standards for information security (ISO 27001), AI management (ISO 42001), business continuity (ISO 22301), IT service management (ISO 20000), and data protection (ISO 27701/ISO 27018). The company serves as the leading NIS-2 examination body in Austria, with specialized offerings for the automotive industry (TISAX), energy sector (ISO 27019/EnWG), and data centers (EN 50600). The training division provides state-accredited professional certification programs, including Information Security Manager/Auditor, AI Manager/Auditor, and Business Continuity Manager/Auditor courses. Services include Stage Reviews for pre-assessment and Combined Audits for organizations with integrated management systems.
Differentiator
Problem solved
Functional benefit
Brands
- CIS Compliance Summit: Annual security compliance conference organized by CIS bringing together security experts, CISOs, and IT decision-makers. Features award ceremony for CISO of the Year.
- CISO of the Year
- Cyber Leaders Academy
Products and services
- ISO 27001 Certification
Quantifiable outcome
- 93% of surveyed companies with ISO 27001 certification report that benefits outweigh costs, with 61% stating benefits significantly outweigh costs
- +3 more outcomes
Companies that use CIS - Certification & Information Security Services
Customer profileNamed customers1 record
Segments5 records
Ideal customer profiles5 records
CIS - Certification & Information Security Services technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
CIS - Certification & Information Security Services partnerships and signals
Strategic signalPartnerships
16 partnerships are on record, tiered core, major and minor.
- Quality Austria Holding GmbHcoreCIS is a 100% subsidiary of Quality Austria Holding GmbH. This parent company relationship provides synergies through the Quality Austria group, including access to integrated management system certifications, training via Quality Austria Academy, consulting via Quality Austria Consulting, and certification services via Quality Austria Certification.
- Quality Austria Certification GmbHcoreSister company within Quality Austria Holding that provides certification services for quality (ISO 9001), environment (ISO 14001), and occupational safety (ISO 45001). Offers integrated audits and management systems with synergies for CIS clients.
- Quality Austria Academy GmbHmajorSister company providing training and education services that complement CIS's professional certification programs in information security and related fields.
- SIQ Ljubljana (Slovenian Institute for Quality and Metrology)minorPartner organization in Slovenia (Ljubljana) providing CIS services in the Slovenian market through local representation.
- Quality Austria Adriatic d.o.o.minorPartner in Croatia (Zagreb) delivering CIS services in the Croatian market under Quality Austria Adriatic brand.
- Quality Austria Center d.o.o.minorPartner in Serbia (Belgrade) providing CIS certification services in the Serbian market.
- Quality Italia S.r.l.minorPartner organization in Rome, Italy extending CIS service reach to the Italian market.
- Quality Austria Certification Gulf, W.L.L.minorPartner in Qatar (Doha) providing CIS services in the Gulf region under Quality Austria Gulf branding.
- Quality Austria Central AsiaminorPartner in India (New Delhi) extending CIS services to the Central Asian market.
- TCIC Global Certification LTD.minorPartner in Canada (Surrey, B.C.) providing global certification services and extending CIS reach to North American markets.
- LSQA UruguayminorCorporate office partner in Montevideo, Uruguay extending CIS services to South American markets.
- KPMG AustriamajorCIS co-founded the Cyber Leaders Academy with KPMG Austria and University of Applied Sciences St. Pölten. The academy provides tailored training for executives on cybersecurity challenges, new legal requirements, and innovative technologies.
- University of Applied Sciences St. PöltenmajorAcademic partner in the Cyber Leaders Academy, providing research-based cybersecurity training for executives alongside KPMG and CIS.
- Austrian Data Center Association (ADCA)minorCIS is a member of ADCA, a nonprofit association representing Austrian data center operators. Membership provides access to latest industry information and allows CIS to contribute expertise to sustainability and security initiatives.
- OVE (Österreichische Verband für Elektrotechnik)minorCIS participates in Austrian technical standards committee for data centers, contributing to EN 50600 standard development alongside OVE.
- ENX AssociationcoreENX Association operates the TISAX platform for the automotive industry. CIS is an approved TISAX assessment provider registered on the ENX platform. Note: CIS states it has no business relationship with ENX beyond this approved provider status.
Scale indicators7 records
Recent moves7 records
Expansion highlights7 records
CIS - Certification & Information Security Services competitors and assessment
Company assessmentBroad incumbents
- TÜV Rheinland Certifyo: TÜV Rheinland operates a global certification body issuing ISO 27001, ISO 20000, ISO 22301 and TISAX assessments for the automotive industry. It is a broad incumbent peer directly competing with CIS in information security certification, including in the German-speaking market.
- TÜV SÜD Management Service: TÜV SÜD is one of the world's largest accredited certification bodies, issuing ISO 27001, ISO 9001, ISO 14001, ISO 45001 and sector-specific certifications globally. It competes with CIS across ISO 27001 and integrated management systems but operates as a broad portfolio incumbent rather than CIS's specialized information-security focus.
- DNV (Det Norske Veritas): DNV is a global assurance provider offering ISO 27001, ISO 22301, ISO 20000 and cybersecurity certification, with strong presence in energy, maritime and industrial sectors. It is a broad incumbent peer to CIS, particularly competing in ISO 27019 energy-sector certifications and integrated management systems.
- Bureau Veritas Certification: Bureau Veritas is a global testing, inspection and certification (TIC) company offering ISO 27001, ISO 9001, ISO 14001 and sector-specific certifications across 140+ countries. It is a broad incumbent competing with CIS in information security management system certification for enterprise clients.
- BSI Group (British Standards Institution): BSI Group is the UK's national standards body and a major global certification body offering ISO 27001, ISO 42001, ISO 9001 and information security assurance services. It competes directly with CIS in ISO 27001 system certification and increasingly in ISO 42001 AI management, with broader geographic reach.
- DEKRA Certification: DEKRA is a German-based global TIC firm offering ISO 27001, ISO 9001, ISO 14001 and cybersecurity certifications, with strong German-speaking market presence. It is a broad incumbent directly competing with CIS for DACH-region enterprise certification engagements.
Regional players
- certimeter AG (TIC entity): certimeter is an Italian/DACH-region certification body offering information security and data protection certifications. It is a regional peer to CIS in the DACH and Italian markets, with overlapping ISO 27001, ISO 27701 and GDPR-related certification offerings.
Emerging players
- Cyber Trust Austria (Kuratorium sicheres Österreich): Cyber Trust Austria operates the Cyber Trust Austria Gold Label program — an entry-level cybersecurity certification that CIS already offers through partnership. It represents an emerging competitor in the Austrian cybersecurity certification space, particularly for SMBs entering the certification journey.
Direct peers
- Quality Austria Certification GmbH: Quality Austria Certification is CIS's sister company within Quality Austria Holding, offering ISO 9001, ISO 14001, ISO 45001 and integrated audits. While under common ownership, it is the closest direct peer in business model (accredited certification body) and competes for similar customer relationships in the Austrian and CEE market.
- TISAX Assessment Providers (ENX Association approved providers): Other approved TISAX assessment providers (e.g., KPMG, TÜV, DEKRA) compete with CIS directly for automotive industry information security assessments. They offer overlapping TISAX assessment services based on the VDA-ISA catalog, serving the same automotive OEM and supplier customer base.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
CIS - Certification & Information Security Services social profiles
Digital presenceCIS - Certification & Information Security Services compliance and trust
Trust signalCompliance22 records
CIS - Certification & Information Security Services financial estimates
Financial estimateRevenue estimate
Valuation estimate
CIS - Certification & Information Security Services leadership team
Management profileNumber of profiles
Profiles4 records
CIS - Certification & Information Security Services subsidiaries and ownership
Company hierarchySubsidiaries4 records
CIS - Certification & Information Security Services funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CIS - Certification & Information Security Services M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CIS - Certification & Information Security Services
What does CIS - Certification & Information Security Services do?
CIS is the leading Austrian certification body for information security and management systems, delivering accredited third-party audits and certifications against standards including ISO 27001, ISO 27017/27018, ISO 27019, ISO 20000-1, ISO 9001, NIS-2, TISAX, AQAP, and ISO 42001 (AI management systems). The company also runs structured training programs and events through its Quality Austria Training affiliate, serving 80+ certifications and 350+ training engagements annually across regulated and high-trust industries such as automotive, energy, and AI-driven enterprises.
Is CIS - Certification & Information Security Services a public or private company?
CIS - Certification & Information Security Services is a private company. It is classified as corporate owned and is currently operating.
When was CIS - Certification & Information Security Services founded?
CIS - Certification & Information Security Services was founded in 2018. It employs 11 to 50 people.
Where is CIS - Certification & Information Security Services based?
CIS - Certification & Information Security Services is headquartered in Vienna, Austria, in the Europe region.
How does CIS - Certification & Information Security Services make money?
Three revenue lines are on record. System Certification Services are the primary driver. The others are training and Person Certification and NIS-2/NISG Compliance Services.
Who are CIS - Certification & Information Security Services's main competitors?
Broad incumbents on record are TÜV Rheinland Certifyo, TÜV SÜD Management Service, DNV (Det Norske Veritas), Bureau Veritas Certification, BSI Group (British Standards Institution) and DEKRA Certification. certimeter AG (TIC entity) is listed as a regional player. Cyber Trust Austria (Kuratorium sicheres Österreich) is listed as an emerging player. Direct peers are Quality Austria Certification GmbH and TISAX Assessment Providers (ENX Association approved providers).
Does CIS - Certification & Information Security Services have an API?
No public API is recorded for CIS - Certification & Information Security Services.
What industry is CIS - Certification & Information Security Services in?
CIS - Certification & Information Security Services's product category is Information Security Certification Services. Its primary akta.pro industry code is EDAAANAF, Sales, Marketing & Digital Marketing Certifications. Its NAICS code is 611430 and its SIC code is 8200.