Fendix
Fendix is a Dutch compliance consultancy, headquartered in Elst, that helps Dutch organizations from startups to enterprises achieve and maintain certifications across information security (ISO 27001, NEN 7510, NIS2, NIS2 Supply Chain), privacy (AVG/GDPR, ISO 27018/27701), and AI regulation (AI Act, ISO 42001) through consulting, audits, and executive training.
- Company typePrivate
- Founded2020
- HeadquartersElst, Netherlands
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Fendix does
Fendix is a Netherlands-based compliance consulting firm that advises Dutch organizations on information security, privacy, and AI regulatory frameworks. Operating under the legal entity KAM Certificeringen B.V. from its headquarters in Elst, Gelderland, the firm delivers services across ISO 27001, NEN 7510, NIS2, NIS2 Supply Chain (SC10/SC20), the EU AI Act, ISO/IEC 42001, AVG/GDPR, ISO 27018, ISO 27701, BIO, and IBP FO. Its service catalog spans GAP analysis, end-to-end implementation support, internal audits, interim officer placement (Security Officer, CISO, Privacy Officer, Functionaris Gegevensbescherming), security awareness training, and paid executive training (NIS2 Executive Training at €449 per person for a half-day session). Authorized to perform NIS2 Supply Chain audits and a member of the NEN standards committee, Fendix also distributes complementary privacy hardware through Spy-Fy and offers a Purple Family Partner Portal for partner-led distribution.
The firm employs 24 people—predominantly information security and privacy consultants—which it positions as a 'new generation' team alongside three partners: founder Wouter Vreeburg, Operational Manager Mathijs Oppelaar, and Commercial Manager Kilian Houthuijzen. The commercial motion is sales-led and direct: free introductory calls, dedicated consultant engagement from GAP analysis through external audit, time-and-materials billing with annual Service Price Index (DPI) adjustments, and optional fixed-price agreements. Content marketing (downloadable ISO 27001 and NEN 7510 checklists, knowledge articles, SEO) and paid NIS2 training feed the top-of-funnel, while partnerships with certification body KIWA, awareness platform Guardey, tool provider Tidal Control, and NIS2 portal Together Digitally Safe form the supporting ecosystem. The firm claims to have helped 650+ organizations from startups to enterprises across healthcare, ICT, education, and enterprise/industrial sectors, and reports a 100% ISO audit pass rate to date.
Fendix operates exclusively in the domestic Netherlands market with no disclosed revenue, no external funding rounds, and no subsidiary or parent structure. Its growth orientation in 2026 reflects direct alignment with EU regulatory tailwinds—particularly NIS2 enforcement (Dutch Cyberbeveiligingswet live by mid-August) and incoming AI Act obligations—through new audit authorizations, GTM partnerships, and AI compliance service expansion. Revenue is generated entirely through professional services fees (consulting hours and training) plus a small line of partner-distributed hardware products.
Fendix firmographics
Firmographics- Name
- Fendix
- Legal name
- KAM Certificeringen B.V.
- Website
- https://fendix.nl
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Fendix is a Dutch compliance consultancy, headquartered in Elst, that helps Dutch organizations from startups to enterprises achieve and maintain certifications across information security (ISO 27001, NEN 7510, NIS2, NIS2 Supply Chain), privacy (AVG/GDPR, ISO 27018/27701), and AI regulation (AI Act, ISO 42001) through consulting, audits, and executive training.
- Ownership category
- akta.pro rank
Fendix industry classification
Industry- Product category
- Compliance Consulting Services
- NAICS
- Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Management Consulting Services (8742)
- akta.pro primary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
- akta.pro secondary industries
- Privacy Management (Consent, DSAR, RoPA) (HDADAFAH), Internal Audit & SOX/ICFR Advisory (BPAHAFAD), Information Security, Privacy & IT Governance (CISSP CPE, Privacy CE) (EDAAALAL)
Keywords
Where Fendix is headquartered
LocationHeadquarters
- HQ city
- Elst
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
Fendix business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D
Revenue model
- Compliance Consulting Services: Professional consulting services including GAP analysis, implementation support, internal audits, and security/privacy officer services. Billed on time-spent basis with hourly rates adjusted annually using Service Price Index (DPI).
- Training Services: NIS2 Executive training offered at €449 per person. Half-day (4 hour) in-company training sessions. Minimum 4, maximum 12 participants per session.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Unit Pricing | One time | NIS2 Executive Training |
| Other | Pay-as-you-go | Consulting Services |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels5 records
Fendix product offering
Product offeringCore offering
Fendix is a Next-Gen compliance consulting firm providing advisory, implementation, audit, and interim specialist services for information security (ISO 27001), healthcare security (NEN 7510), privacy (AVG/GDPR), and AI compliance (AI Act, ISO 42001) to organizations from startups to enterprises. The firm guides customers through the complete certification lifecycle — from GAP analysis and implementation through internal audits and post-certification maintenance — and supplies interim officers (CISO, Security Officer, Privacy Officer, FG/DPO) on a flexible basis. It also delivers paid executive training (NIS2 Executive Training) and authorized NIS2 Supply Chain (SC10/SC20) audit services.
Product overview
Fendix is a Next-Gen compliance consulting firm offering advisory and implementation services for information security, privacy, and AI compliance. The core offering consists of consulting services including GAP analysis, implementation support, internal audits, and interim specialist placement (Security Officer, CISO, Privacy Officer, Functionaris Gegevensbescherming). The company also provides training programs such as NIS2 Executive Training, and distributes privacy products through the Spy-Fy partnership. Fendix supports organizations through the complete certification lifecycle with services for ISO 27001, NEN 7510, NIS2, NIS2 Supply Chain, GDPR/AVG, ISO 27018, ISO 27701, and ISO 42001 standards. The Purple Family Partner Portal provides a platform for partner management and resource access. The company serves organizations from startups to enterprises across healthcare, education, ICT, and enterprise sectors.
Differentiator
Problem solved
Functional benefit
Products and services
- GAP-analyse
- Implementatie
- Interne audit
- Security Officer (interim)
- CISO (interim)
- Functionaris Gegevensbescherming (FG)
- Privacy Officer (interim)
- NIS2 Executive Training
- Security Awareness Training
- NIS2 Supply Chain Certificering
- Onderhoud & Verbetering (Maintenance & Improvement)
Quantifiable outcome
- Every customer has successfully passed ISO audit with 'vlag en wimpel' (flying colors)
- +3 more outcomes
Companies that use Fendix
Customer profileNamed customers11 records
Segments5 records
Ideal customer profiles5 records
Fendix technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Fendix partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and minor.
- Together Digitally Safe (Samen Digitaal Veilig)coreJoint collaboration to help organizations achieve NIS2 Supply Chain certification. Together Digitally Safe provides a smart portal for NIS2 obligations management and supply chain monitoring. Fendix offers 50% discount to customers on this platform using code 'TENNIS 2'. Addresses the NIS2 requirement for organizations to verify supplier cybersecurity.
- Spy-FyminorCollaboration to improve digital privacy and elevate protection standards. Spy-Fy offers privacy products including webcam covers, custom card holders with RFID blocking, Faraday bags, and USB data blockers. Fendix provides these products as practical tools contributing to stronger information security and privacy awareness.
- KIWAcoreProud partner of KIWA, a certification body. KIWA is a leading certification provider used for verifying compliance with various standards including ISO certifications.
- NENcoreMember of NEN (Netherlands Standardization Institute) standards committee. Active participation in shaping information security and privacy standards in the Netherlands.
- Purple FamilyminorPurple Family Partner Portal (portal.fendix.nl) allows Fendix to distribute third-party products and services. Separate privacy statement applies for data processed in the portal.
Scale indicators2 records
Recent moves6 records
Expansion highlights6 records
Fendix competitors and assessment
Company assessmentDirect peers
- Normec: Dutch compliance, certification and testing services group. Directly comparable to Fendix because both serve Dutch organizations across ISO, information security, and sector-specific compliance standards (including NEN frameworks) with consulting and audit-prep services.
- Secura: Dutch cybersecurity services firm offering consulting, testing, and certification support (including ISO 27001). Closely comparable to Fendix in size, Dutch market focus, and information-security advisory scope.
- Kiwa: Leading Dutch certification body and Fendix's named partner for ISO audits. Comparable as a Dutch-rooted standards and certification player, though Kiwa is also the external auditor that Fendix engagements ultimately feed into.
Broad incumbents
- EY Netherlands: Big 4 firm with a Dutch cybersecurity and privacy consulting practice. Comparable to Fendix on ISO 27001, NIS2, GDPR, and AI-related compliance engagements, typically serving enterprise and regulated-entity clients.
- Deloitte Netherlands: Big 4 advisory with a Risk & Advisory practice covering cyber, privacy, and regulatory compliance. Overlaps with Fendix on NIS2, ISO 27001, GDPR, and AI Act readiness work for Dutch enterprise and public-sector clients.
- Bureau Veritas: Global testing, inspection and certification company with a Dutch entity. Overlaps with Fendix on ISO 27001, NIS2, and information-security certification services, but operates with much wider geographic and vertical reach.
- DNV: Global assurance and certification firm (now including Nixu cybersecurity). Comparable to Fendix in ISO 27001 and NIS2 advisory/audit but at much larger scale and broader industry coverage; competes for Dutch enterprise compliance budgets.
- KPMG Netherlands: Big 4 advisory firm with a large Dutch cyber & risk practice. Competes with Fendix on ISO 27001, NIS2 readiness, and privacy compliance for mid-market and enterprise clients, but as part of a much broader portfolio.
- BSI Group: Global standards and certification body, originator of ISO 27001. Comparable to Fendix as an ISO 27001 and information-security advisory provider, but with international delivery capability and significantly larger market presence.
Others
- Tidal Control: Dutch compliance management software referenced in Fendix customer success stories. Adjacent rather than directly competitive — Tidal Control provides tooling that complements Fendix's consulting engagements.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Fendix social profiles
Digital presenceFendix compliance and trust
Trust signalCompliance11 records
Fendix financial estimates
Financial estimateRevenue estimate
Valuation estimate
Fendix leadership team
Management profileNumber of profiles
Profiles21 records
Fendix funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Fendix M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Fendix
What does Fendix do?
Fendix is a Next-Gen compliance consulting firm providing advisory, implementation, audit, and interim specialist services for information security (ISO 27001), healthcare security (NEN 7510), privacy (AVG/GDPR), and AI compliance (AI Act, ISO 42001) to organizations from startups to enterprises. The firm guides customers through the complete certification lifecycle — from GAP analysis and implementation through internal audits and post-certification maintenance — and supplies interim officers (CISO, Security Officer, Privacy Officer, FG/DPO) on a flexible basis. It also delivers paid executive training (NIS2 Executive Training) and authorized NIS2 Supply Chain (SC10/SC20) audit services.
Is Fendix a public or private company?
Fendix is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Fendix founded?
Fendix was founded in 2020. It employs 11 to 50 people.
Where is Fendix based?
Fendix is headquartered in Elst, Netherlands, in the Europe region.
How does Fendix make money?
Two revenue lines are on record. Compliance Consulting Services are the primary driver. The others are training Services.
Who are Fendix's main competitors?
Direct peers on record are Normec, Secura and Kiwa. Broad incumbents are EY Netherlands, Deloitte Netherlands, Bureau Veritas, DNV, KPMG Netherlands and BSI Group. Tidal Control is listed as an others.
Does Fendix have an API?
No public API is recorded for Fendix.
What industry is Fendix in?
Fendix's product category is Compliance Consulting Services. Its primary akta.pro industry code is BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX), with a secondary code of HDADAFAH, Privacy Management (Consent, DSAR, RoPA). Its NAICS code is 54169 and its SIC code is 8700.