sgs brightsight
- Company typePrivate
- Founded1984
- HeadquartersDelft, Netherlands
- Headcount—
- GTM typeB2B
- OfferingServices
sgs brightsight firmographics
Firmographics- Name
- sgs brightsight
- Legal name
- SGS Société Générale de Surveillance SA
- Website
- https://sgsbrightsight.com
- Company type
- Private
- Founded year
- 1984
- Operating status
- Operating
- Ownership category
- akta.pro rank
sgs brightsight industry classification
Industry- Product category
- Cybersecurity Evaluation and Certification Services
- NAICS
- Other Computer Related Services (541519)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Security Operations Center (SOC) as a Service (BPAEADAB)
Keywords
Where sgs brightsight is headquartered
LocationHeadquarters
- HQ city
- Delft
- HQ country
- Netherlands
- HQ region
- Europe
Offices7 records
Markets served
sgs brightsight business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others
Revenue model
- Security Evaluations: Security evaluation services including Common Criteria, EUCC, SESIP, PSA Certified, EMVCo, PCI PTS, FIPS 140-3, and other security certifications for IT products, smartcards, IoT devices, payment terminals, and hardware security modules.
- Certification Body Services: As a Certification Body (CB), Brightsight issues certifications under various schemes including EUCC, PSA Certified, SESIP, and other cybersecurity certification programs.
- Professional Advisory and Training: Customized training courses and advisory services including CRA workshops, Common Criteria training, and pre-evaluation consulting to help clients prepare for security certifications.
- CRA Compliance Services: Cyber Resilience Act (CRA) framework workshops, product-specific gap assessments, and CRA-ready certifications to help manufacturers achieve compliance with EU regulations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Security evaluation and certification services are provided on a custom quote basis depending on product type, evaluation scope, certification scheme requirements, and project complexity. |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
sgs brightsight product offering
Product offeringCore offering
SGS Brightsight is an independent IT Security Evaluation Facility (ITSEF) and Certification Body that performs security evaluations and issues certifications for IT products including smartcards, IoT devices, payment terminals, semiconductors, and hardware security modules. The company operates accredited laboratories across Europe and Asia and evaluates products against international standards such as Common Criteria, EUCC, SESIP, PSA Certified, EMVCo, PCI PTS, FIPS 140-3, and GSMA NESAS. It also delivers professional advisory, training, and regulatory compliance services including support for the EU Cyber Resilience Act and Radio Equipment Directive.
Product overview
Brightsight is a global cybersecurity evaluation laboratory and certification body (ITSEF and Certification Body) providing comprehensive security testing and certification services. The company operates a multi-site laboratory network across Europe (Delft, Barcelona, Madrid, Graz, Meyreuil) and Asia (Beijing, Singapore). Its core offerings include Security Evaluations (Common Criteria, EUCC, SESIP, PSA Certified, PCI PTS, EMVCo, FIPS 140-3, GSMA NESAS, MDSCert, EN 303 645, IEC 62443), combined with a Certification Body for issuing certificates under multiple international schemes. Professional Advisory services provide training, gap assessments, and regulatory compliance guidance. The company supports compliance with EU regulations including the Cyber Resilience Act (CRA) and Radio Equipment Directive (RED), offering the SGS Cybersecurity Mark as a product certification identifier. Brightsight is accredited by over 50 international schemes and is recognized as the leading Common Criteria laboratory worldwide.
Differentiator
Problem solved
Functional benefit
Brands
- Brightsight CB: Brightsight Certification Body — a dedicated certification body website (brightsightcb.com) offering CB services separate from ITSEF evaluation services.
Products and services
- Security Evaluations Comprehensive IT security evaluation and testing services performed by accredited laboratories to assess product security against international standards and certification schemes. Targeted at enterprises manufacturing IT products across multiple sectors.
- Common Criteria Evaluations Security evaluations against the ISO/IEC 15408 Common Criteria standard covering EAL1 through EAL7 for smartcards, secure elements, hardware devices, and general IT products. For semiconductor, payment, and high-assurance product manufacturers.
- EUCC Evaluations European cybersecurity certification based on Common Criteria enabling EU-wide recognition of IT security certificates under the EU Cybersecurity Act. For manufacturers requiring EU market access for IT products.
- PSA Certified Evaluations Globally recognized IoT security certification scheme operated by GlobalPlatform helping manufacturers demonstrate security of connected products through independently validated assurance levels. For IoT device manufacturers.
- SESIP Evaluations Methodology for evaluating security of IoT platforms providing a standardized approach for assessing connected device security. For IoT platform manufacturers requiring repeatable security assurance.
- PCI PTS Evaluations
- EMVCo Security Evaluations
- FIPS 140-3 Evaluations
- GSMA NESAS and MDSCert
- SGS Cybersecurity Mark Product certification mark demonstrating compliance with recognized cybersecurity standards including ETSI EN 303 645, NIST IR 8259A, RED Article 3.3, and IEC 62443. For consumer product manufacturers seeking cybersecurity certification.
- ISA/IEC 62443 Evaluation Services
- CRA Notified Body Services
- RED Cybersecurity Evaluations
- EN 303 645 IoT Security Testing
- OCP S.A.F.E. Security Reviews Security appraisals for Open Compute Project data center and AI infrastructure components conducted as an approved OCP Security Review Provider. For data center and AI infrastructure manufacturers and hyperscalers.
- Brightsight Certification Body Services Independent certification body services for issuing certificates under various schemes including EUCC, PSA Certified, SESIP, and other international certification programs. For product manufacturers requiring certifications.
- Professional Advisory
- eIDAS HSM Certification Common Criteria EAL4+ certification for Hardware Security Modules according to eIDAS Protection Profile EN 419 221-5 for qualified trust service providers. For HSM manufacturers serving EU trust service providers.
- BSI BSZ Accelerated Security Certification
Quantifiable outcome
- Achieved first-place ranking with 71 Common Criteria evaluations in 2025
- +4 more outcomes
Companies that use sgs brightsight
Customer profileNamed customers12 records
Segments8 records
Ideal customer profiles6 records
sgs brightsight technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
sgs brightsight partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered flagship and core.
- SGS GroupflagshipBrightsight was acquired by SGS Group (Société Générale de Surveillance) in 2021, becoming part of the world's leading testing, inspection and certification company. This provides Brightsight access to SGS's global network, Notified Body services for EU certifications, and expanded distribution capabilities.
- Arm (PSA Certified)coreBrightsight was a lead partner in setting up Platform Security Architecture (PSA) Certified, an IoT security evaluation scheme initiated by Arm. Brightsight continues as founding member of PSA Certified and offers PSA Certified evaluations.
- GlobalPlatformcoreBrightsight operates as Certification Body and evaluation laboratory under GlobalPlatform's PSA Certified and SESIP schemes. GlobalPlatform is the organization governing PSA Certified.
- TrustCBcoreTrustCB is the Certification Body for SESIP certification. Brightsight works with TrustCB as co-founder of the SESIP methodology and evaluation partner.
- Open Compute Project (OCP)coreBrightsight achieved OCP Security Appraisal Framework and Enablement (S.A.F.E.) Security Review Provider (SRP) approval to conduct security evaluations for hardware and software solutions within the OCP ecosystem.
- EurosmartflagshipBrightsight elected as Board member of Eurosmart, the association advocating for high level of security in digital interactions. Fabrice Heiser represents Testing and Inspections Companies (TIC) on the Board.
- SGS FimkocoreSGS Fimko serves as SGS's EC accredited Notified Body for RED certifications. Brightsight leverages this partnership to deliver complete RED certification services with EU Type Certificates.
- ENISA / European CommissioncoreBrightsight participates in EU cybersecurity certification framework development under the EU Cybersecurity Act (CSA), contributing to EUCC scheme development and acting as licensed EUCC ITSEF and Certification Body.
Scale indicators7 records
Recent moves8 records
Expansion highlights6 records
sgs brightsight competitors and assessment
Company assessmentDirect peers
- TÜV Rheinland: Global testing, inspection, and certification company with active Common Criteria evaluation laboratory services (TÜV Rheinland Nederland). Direct competitor to Brightsight in CC evaluations, EMVCo, and IoT security certifications, serving similar enterprise semiconductor and payment customers.
- TÜV SÜD: Major TIC company operating Common Criteria, EMVCo, and IoT security evaluation services. Competes directly with Brightsight for semiconductor and IoT device certifications and operates multiple accredited ITSEF facilities across Europe and Asia.
- atsec information security: Specialized cybersecurity evaluation laboratory focused on Common Criteria, FIPS 140-3, and PCI assessments. Direct competitor to Brightsight with US and European presence, particularly competing for high-assurance CC evaluations and cryptographic module certifications.
- Serma Safety & Security: European cybersecurity evaluation laboratory (Serma Safety & Security) operating Common Criteria, EMVCo, and PCI evaluations. Direct peer to Brightsight, particularly competing in French and broader European markets for security certifications.
Broad incumbents
- UL Solutions: Global safety and security certification incumbent offering cybersecurity evaluation and testing services alongside a much broader portfolio (electrical safety, sustainability, etc.). Competes with Brightsight in CC and IoT security certifications but as part of a multi-vertical TIC portfolio.
- Bureau Veritas: Global TIC conglomerate (similar to SGS) with cybersecurity testing and certification capabilities. Competes with Brightsight/SGS in broader TIC tenders and increasingly in cybersecurity evaluation services as it expands its digital trust portfolio.
- Applus+ Laboratories: Global TIC group offering cybersecurity testing and certification among its broader testing services. Competes with Brightsight in select IoT and payment security evaluations as part of its diversified TIC portfolio.
- Intertek: Global TIC incumbent providing cybersecurity and IoT security testing and certification services alongside its broader quality assurance portfolio. Overlaps with Brightsight in consumer IoT and connected device certification work.
Emerging players
- TrustCB: Independent certification body operating SESIP and PSA Certified schemes, co-founded with Brightsight. An ecosystem peer rather than direct competitor—handles CB activities Brightsight may have historically performed, while Brightsight serves as evaluation laboratory partner.
- Riscure: Specialized cybersecurity testing lab offering CC, EMVCo, and IoT security evaluation services. Smaller-scale competitor focused on smartcard, payment, and embedded security, with overlapping but more limited scheme coverage than Brightsight.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
sgs brightsight social profiles
Digital presencesgs brightsight compliance and trust
Trust signalCompliance22 records
sgs brightsight financial estimates
Financial estimateRevenue estimate
Valuation estimate
sgs brightsight leadership team
Management profileNumber of profiles
Profiles5 records
sgs brightsight funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
sgs brightsight M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about sgs brightsight
What does sgs brightsight do?
SGS Brightsight is an independent IT Security Evaluation Facility (ITSEF) and Certification Body that performs security evaluations and issues certifications for IT products including smartcards, IoT devices, payment terminals, semiconductors, and hardware security modules. The company operates accredited laboratories across Europe and Asia and evaluates products against international standards such as Common Criteria, EUCC, SESIP, PSA Certified, EMVCo, PCI PTS, FIPS 140-3, and GSMA NESAS. It also delivers professional advisory, training, and regulatory compliance services including support for the EU Cyber Resilience Act and Radio Equipment Directive.
Is sgs brightsight a public or private company?
sgs brightsight is a private company. It is classified as corporate owned and is currently operating.
When was sgs brightsight founded?
sgs brightsight was founded in 1984.
Where is sgs brightsight based?
sgs brightsight is headquartered in Delft, Netherlands, in the Europe region.
How does sgs brightsight make money?
Four revenue lines are on record. Security Evaluations are the primary driver. The others are certification Body Services, professional Advisory and Training and CRA Compliance Services.
Who are sgs brightsight's main competitors?
Direct peers on record are TÜV Rheinland, TÜV SÜD, atsec information security and Serma Safety & Security. Broad incumbents are UL Solutions, Bureau Veritas, Applus+ Laboratories and Intertek. Emerging players are TrustCB and Riscure.
Does sgs brightsight have an API?
No public API is recorded for sgs brightsight.
What industry is sgs brightsight in?
sgs brightsight's product category is Cybersecurity Evaluation and Certification Services. Its primary akta.pro industry code is BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 541519 and its SIC code is 8700.