Charter of Trust
Charter of Trust is a non-profit alliance of 19+ global companies that collaboratively develops cybersecurity principles, baseline requirements, frameworks, and policy recommendations across five working groups, serving member enterprises, regulators, and SMEs worldwide.
- Company typePrivate
- Founded2018
- HeadquartersMunich, Germany
- Headcount251–500
- GTM typeB2B
- OfferingServices
What Charter of Trust does
Charter of Trust is a non-profit alliance of global companies that advances cybersecurity and digital trust through collaborative development of principles, baseline requirements, frameworks, and policy recommendations. Founded in February 2018 at the Munich Security Conference by Siemens and eight founding partners (Airbus, Allianz, Daimler Group, IBM, MSC, NXP, SGS, Deutsche Telekom), the alliance has grown to 19+ partner companies and associated partners including Allianz, Atos, Bosch, Danfoss, Elastic, IBM, Infineon Technologies, Microsoft, Mitsubishi Heavy Industries, Palo Alto Networks, Siemens, TÜV SÜD, Zscaler, Munich Security Conference, Cloud Security Alliance, Shared Assessments, CEBRI, and academic institutions such as Hasso Plattner Institute and Graz University of Technology. Its work is organized into five working groups — Security by Default, Supply Chain Security, Emerging Technologies, Education, and External Engagement — plus a newly launched Cyber Deterrence Working Group (June 2026).
The alliance's core technology deliverables are not commercial products but policy artifacts and frameworks: 10 Cybersecurity Principles, Security by Default baseline requirements (Phase 1 covering products/functionalities/technologies and Phase 2 covering processes/operations/architectures), Secure Development Lifecycle guidelines, a Post-Quantum Cryptography framework and white paper, a Trustworthiness in AI Framework aligned with the EU AI Act, and a Human-to-Human Threat Intelligence Network using the Information Sharing Traffic Light Protocol (ISTLP) facilitated by the TruSTAR platform. It does not develop proprietary technology products and does not sell software or services.
The business model is member-funded and non-commercial: the alliance is operated by Siemens Aktiengesellschaft (headquartered in Munich, Germany) and funded through member contributions from partner and associated partner companies. All publications, guidelines, and reports are made freely available on charteroftrust.com. GTM is community-led, driven by onboarding new partners, expanding into new sectors and countries (members operate across 190 countries), and engaging with policymakers and regulators in the EU, US, UK, Singapore, Australia, Japan, India, Brazil, and other regions. Revenue from a commercial standpoint is not applicable.
Charter of Trust firmographics
Firmographics- Name
- Charter of Trust
- Legal name
- Charter of Trust (operated by Siemens Aktiengesellschaft)
- Website
- https://charteroftrust.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Charter of Trust is a non-profit alliance of 19+ global companies that collaboratively develops cybersecurity principles, baseline requirements, frameworks, and policy recommendations across five working groups, serving member enterprises, regulators, and SMEs worldwide.
- Ownership category
- akta.pro rank
Charter of Trust industry classification
Industry- Product category
- Cybersecurity Industry Alliance
- NAICS
- Computer Systems Design and Related Services (54151), Investigation and Security Services (5616)
- SIC
- Services-Membership Organizations (8600)
- akta.pro primary industry
- Security Architecture & Engineering Advisory (Zero Trust, IAM, Network) (BPAKADAF)
Keywords
Where Charter of Trust is headquartered
LocationHeadquarters
- HQ city
- Munich
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Charter of Trust business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Member Contributions / Membership Dues: Charter of Trust is a non-profit alliance funded by contributions from its partner and associated partner companies. There is no commercial revenue model as the organization exists to advance cybersecurity and digital trust objectives shared by its members.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels10 records
Charter of Trust product offering
Product offeringCore offering
Charter of Trust is a non-profit alliance of global companies that develops cybersecurity principles, baseline requirements, guidelines, frameworks, and policy recommendations for its members to implement. Its core deliverables include the Security by Default baseline requirements (Phase 1 and Phase 2), Secure Development Lifecycle guidelines, cybersecurity risk assessment guidelines, Post-Quantum Cryptography frameworks, AI trustworthiness frameworks, and a Human-to-Human Threat Intelligence Network. The alliance operates across five activity areas: Security by Default, Supply Chain Security, Emerging Technologies, Education, and External Engagement, and produces white papers, frameworks, and training programs for its partner ecosystem.
Product overview
The Charter of Trust is a non-profit alliance of global companies that are thought leaders and pioneer practitioners in cybersecurity and digital trust. The organization is structured around five key activity areas: Security By Default, Supply Chain Security, Emerging Technologies, Education, and External Engagement. These are operationalized through dedicated working groups that produce guidelines, baseline requirements, white papers, and reports. Key deliverables include the Secure Development Lifecycle Guidelines (Phases 1 and 2), Post-Quantum Cryptography white papers, the Cyber Deterrence Working Group's publications, and the Trustworthiness in AI Framework. The alliance also manages the Cyber Talent Academy for education and training initiatives.
Differentiator
Problem solved
Functional benefit
Products and services
- Security by Default Baseline Requirements
- Secure Development Lifecycle Guidelines
- Charter of Trust PQC Ambition
- Decrypting the Future: Global Timelines for Post-Quantum Cryptography White Paper
- Trustworthiness in AI Framework
- Cyber Deterrence White Paper
- Hybrid Threats Report
- Cyber Talent Academy
- Cyber Deterrence Working Group
Quantifiable outcome
- 60% of cyberattacks originate from supply chain vulnerabilities, and 60% of those incidents affect smaller companies — Charter of Trust's supply chain baseline requirements address this gap by requiring suppliers to meet cybersecurity standards.
- +2 more outcomes
Companies that use Charter of Trust
Customer profileNamed customers1 record
Segments3 records
Ideal customer profiles3 records
Charter of Trust technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
Charter of Trust partnerships and signals
Strategic signalPartnerships
19 partnerships are on record, tiered core, founding partner and associated.
- ZscalercoreZscaler joined Charter of Trust as a new partner in September 2025. Zscaler is a leading cloud enterprise security provider. Sam Curry, Zscaler CISO, emphasized the need for reducing inherent trust and default access, and the importance of industry coalition to stay ahead of evolving threats.
- Siemensfounding partnerSiemens is the founding company and primary operator of Charter of Trust. As the entity responsible for the Charter of Trust website and legal operations, Siemens plays a central role in coordinating the alliance, hosting its events, and driving the collaborative cybersecurity mission alongside other global partners.
- AllianzcoreAllianz is a core partner of Charter of Trust. Dr. Ralf Schneider, Senior Fellow and Head of Cybersecurity and NextGenIT Think Tank at Allianz SE, was elected Co-Chair of Charter of Trust in February 2025 alongside Dr. Sumit Chanda from Atos.
- AtoscoreAtos is a core partner and Co-Chair organization of Charter of Trust. Dr. Sumit Chanda, COO/CISO at Atos Group Security, was elected Co-Chair of the alliance in February 2025. Atos contributes to multiple working groups including the Global External Engagement Group.
- Bosch (Robert Bosch GmbH)coreBosch is a core partner of Charter of Trust, contributing expertise in cybersecurity, AI, and operational technology. Bosch's Dr. Christoph Peylo serves as AI Task Force Lead of the Charter of Trust.
- MicrosoftcoreMicrosoft is a core partner of Charter of Trust. Microsoft contributes to multiple initiatives including the CyberTrust Talks series, RSA Conference panels, and provides expertise on AI governance and regulatory alignment.
- Mitsubishi Heavy Industries (MHI)coreMitsubishi Heavy Industries is a core partner of Charter of Trust from Japan, contributing expertise in industrial cybersecurity, supply chain security, and operational technology.
- Palo Alto NetworkscorePalo Alto Networks is a core partner of Charter of Trust, providing cybersecurity expertise, threat intelligence capabilities, and contributions to the alliance's cybersecurity frameworks.
- TÜV SÜDcoreTÜV SÜD is a core partner of Charter of Trust. Sudhir Ethiraj, Global Head of Cybersecurity Office at TÜV SÜD, serves as Taskforce Lead for the Security by Default Working Group and moderator for multiple Charter of Trust events.
- Infineon TechnologiescoreInfineon Technologies is a core partner of Charter of Trust, contributing semiconductor and hardware security expertise. Detlef Houdeau from Infineon has participated in panels on regulatory landscape and supply chain security.
- ElasticcoreElastic is a core partner of Charter of Trust, providing expertise in cybersecurity analytics, search, and observability. Suzanne Button, Field CTO EMEA at Elastic, has participated in CyberTrust Talk panels.
- DanfosscoreDanfoss is a core partner of Charter of Trust and hosted Collaboration Week 2025 in Denmark, providing an inspiring venue for the alliance's three-day strategic summit.
- Munich Security Conference (MSC)coreMSC is a founding partner of Charter of Trust. The alliance was launched at the Munich Security Conference in February 2018. Benedikt Franke, Vice-Chairman & CEO of MSC, provides keynote addresses at Charter of Trust Board meetings.
- IBMcoreIBM is a founding partner of Charter of Trust, contributing expertise in cybersecurity, AI, cloud security, threat intelligence (X-Force), identity and access management, and post-quantum cryptography. IBM contributes to multiple working groups.
- Graz University of TechnologyassociatedGraz University of Technology is an Associated Partner of Charter of Trust, contributing academic research and expertise in cybersecurity from the educational and research community.
- Hasso Plattner Institute (HPI)associatedThe Hasso Plattner Institute for Digital Engineering GmbH is an Associated Partner contributing academic research and education expertise to the Charter of Trust's cybersecurity mission.
- CEBRI (Brazilian Center for International Relations)associatedCEBRI, the Brazilian Center for International Relations, is an Associated Partner of Charter of Trust, contributing perspectives on international cooperation, data governance, and public-private partnership to protect critical infrastructures in Latin America.
- Shared AssessmentsassociatedShared Assessments is an Associated Partner of Charter of Trust. As a newest Associated Partner, Shared Assessments organized the inaugural UK/EU Summit on 'Risk to Resilience' in London, bringing together professionals from different industries and regions.
- Cloud Security AllianceassociatedCloud Security Alliance (CSA) is an Associated Partner of Charter of Trust. Linda Strick, Director at CSA EMEA, has participated in Charter of Trust webinars and contributed expertise on cloud security and Secure Development Lifecycle.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
Charter of Trust competitors and assessment
Company assessmentBroad incumbents
- ENISA (European Union Agency for Cybersecurity): EU agency that supports member states and EU institutions on cybersecurity, producing widely adopted guidance and frameworks. Broader and government-led, but overlaps with Charter of Trust in producing baseline requirements, supply-chain guidance, and AI/PQC frameworks at EU level.
- (ISC)²: International non-profit member organisation for cybersecurity professionals, known for the CISSP certification and Common Body of Knowledge. Comparable in operating a large global cybersecurity community with education and certification deliverables, but much larger and more mature.
- ISACA: Global professional association for IT governance, risk, and cybersecurity practitioners offering frameworks (COBIT), certifications (CISA, CISM), and research. Comparable as an established multi-stakeholder cybersecurity community, though more certification- and governance-focused than Charter of Trust's standards mission.
- NIST (National Institute of Standards and Technology) — Cybersecurity Framework programme: U.S. government programme that produces the widely adopted Cybersecurity Framework and PQC standardisation (FIPS 203/204/205). Comparable as a global reference for cybersecurity baseline requirements, but government-led rather than industry-led.
Direct peers
- Global Cyber Alliance: Non-profit international organisation building cross-sector cybersecurity tools and initiatives to eliminate cyber risk. Directly comparable as a global, non-profit, multi-stakeholder alliance producing practical cybersecurity deliverables rather than products.
- FS-ISAC (Financial Services Information Sharing and Analysis Center): Member-driven, cross-border threat intelligence sharing community for the financial sector. Comparable to Charter of Trust's Human-to-Human Threat Intelligence Network in mission (collective defence through information sharing) though narrower in industry scope.
- Internet Security Alliance: Non-profit trade association that brings together businesses, governments, and academia to integrate cyber risk into business strategy. Comparable multi-stakeholder mission and policy-advocacy focus to Charter of Trust, particularly around regulatory frameworks.
- Cloud Security Alliance: Cloud-focused non-profit alliance producing cybersecurity best practices, frameworks, and certifications. Directly comparable to Charter of Trust as a vendor-neutral cybersecurity standards body; in fact, CSA is itself an Associated Partner of Charter of Trust, evidencing peer-level collaboration.
- FIRST (Forum of Incident Response and Security Teams): Global confederation of incident response and security teams that develops best-practice standards (CVSS, PSIRT, TLP). Directly comparable as a non-profit global community producing cybersecurity frameworks and coordinating practitioner information sharing.
- OASIS Open — cybersecurity technical committees: International non-profit standards body that develops open cybersecurity standards (e.g., STIX, TAXII, SAMM). Comparable to Charter of Trust in producing vendor-neutral, member-developed frameworks that become de facto industry standards.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Charter of Trust social profiles
Digital presenceCharter of Trust financial estimates
Financial estimateRevenue estimate
Valuation estimate
Charter of Trust leadership team
Management profileNumber of profiles
Profiles5 records
Charter of Trust funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Charter of Trust M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Charter of Trust
What does Charter of Trust do?
Charter of Trust is a non-profit alliance of global companies that develops cybersecurity principles, baseline requirements, guidelines, frameworks, and policy recommendations for its members to implement. Its core deliverables include the Security by Default baseline requirements (Phase 1 and Phase 2), Secure Development Lifecycle guidelines, cybersecurity risk assessment guidelines, Post-Quantum Cryptography frameworks, AI trustworthiness frameworks, and a Human-to-Human Threat Intelligence Network. The alliance operates across five activity areas: Security by Default, Supply Chain Security, Emerging Technologies, Education, and External Engagement, and produces white papers, frameworks, and training programs for its partner ecosystem.
Is Charter of Trust a public or private company?
Charter of Trust is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Charter of Trust founded?
Charter of Trust was founded in 2018. It employs 251 to 500 people.
Where is Charter of Trust based?
Charter of Trust is headquartered in Munich, Germany, in the Europe region.
How does Charter of Trust make money?
One revenue line is on record: member Contributions / Membership Dues.
Who are Charter of Trust's main competitors?
Broad incumbents on record are ENISA (European Union Agency for Cybersecurity), (ISC)², ISACA and NIST (National Institute of Standards and Technology) — Cybersecurity Framework programme. Direct peers are Global Cyber Alliance, FS-ISAC (Financial Services Information Sharing and Analysis Center), Internet Security Alliance, Cloud Security Alliance, FIRST (Forum of Incident Response and Security Teams) and OASIS Open — cybersecurity technical committees.
Does Charter of Trust have an API?
No public API is recorded for Charter of Trust.
What industry is Charter of Trust in?
Charter of Trust's product category is Cybersecurity Industry Alliance. Its primary akta.pro industry code is BPAKADAF, Security Architecture & Engineering Advisory (Zero Trust, IAM, Network). Its NAICS code is 54151 and its SIC code is 8600.