Our expertise

You want to be able to verify our expertise.

Here you can trace what our consulting and testing are based on: formal recognitions, the qualifications of our experts and published work on methods, standards and security issues.

Two secuvera experts examining a navigation instrument together
Verified expertise: BSI-certified and DAkkS-accredited.

Certifications and recognitions

The BSI certification applies to clearly defined services: consulting, audit and technical security testing. The recognition and accreditation of our evaluation facility refer to the respective scope and do not replace the certification decision of the responsible body. Our own information security management is certified as well.

BSI-certified IT security service provider

Institutional evidence

IS consulting and IS audit: independently verified

secuvera is certified by the BSI (Federal Office for Information Security) as an IT security service provider for IS consulting and IS audit (IS-Revision). This evidence covers our consulting and audit services; certification decisions are made by the responsible certification bodies.

View certification for IS consulting and IS audit
BSI-certified IT security service provider

Institutional evidence

BSI-certified for IS penetration testing

The Federal Office for Information Security lists secuvera as a certified IT security service provider for IS penetration testing. The certification applies to this service area.

Pentest certification in the BSI register
BSI-recognised IT security evaluation facility

Institutional evidence

BSI-recognised evaluation facility since 1992

Our evaluation facility has been recognised by the BSI since 20 November 1992. The current entry covers Common Criteria and ITSEC. We evaluate products and prepare the evaluation reports; the certification decision lies with the certification body.

View the evaluation facility's recognition at the BSI

Institutional evidence

Accredited for product testing in the EUCC scheme

DAkkS accreditation D-PL-21736-01-00 to DIN EN ISO/IEC 17025:2018 covers testing of information and communication technology products in the EUCC scheme. The exact technical scope is described in the annex to the certificate.

View secuvera and its scope at DAkkS
BSI-recognised IT security evaluation facility

Institutional evidence

Recognised for BSZ evaluations

Since December 2022, secuvera has been recognised by the BSI as an evaluation facility for the Accelerated Security Certification (BSZ). We carry out the technical security assessment and report to the BSI; the BSI decides on certification.

View BSZ recognition in the BSI register
BSI-recognised IT security evaluation facility

Institutional evidence

BSI-recognised NESAS evaluation facility

The BSI lists secuvera as a recognised BSI NESAS evaluation facility. We assess mobile network equipment in the respective evaluation procedure. An audit of a specific campus network and product certification are different tasks.

View NESAS evaluation facility at the BSI
BSI-recognised IT security evaluation facility

Institutional evidence

Recognised evaluation facility for BSI TR-03161

secuvera is recognised by the BSI for evaluations under TR-03161. The recognition refers to applications in the healthcare sector. Our evaluation report is a contribution to the certification procedure at the BSI.

View TR-03161 evaluation facility in the BSI register
BSI-recognised IT security evaluation facility

Institutional evidence

Recognised evaluation facility for BSI TR-03174

secuvera is recognised by the BSI as an evaluation facility for TR-03174 – requirements for applications in the financial sector. The recognition is valid from 15 August 2025 to 31 August 2028. We carry out the evaluation; the BSI decides on certification.

View TR-03174 requirements at the BSI
PIAQ – ISO/IEC 27001, information security

Company certification

Our own ISMS is certified

We do more than advise on ISO/IEC 27001. Our own information security management system is also certified to ISO/IEC 27001:2022. It covers our testing and consulting services and the associated support processes.

Read the publication on our certified ISMS

Qualified experts

Several of our colleagues hold subject-specific certifications and qualifications. Here you will find the qualifications represented in our team.

Personal qualification

BSI-certified IS penetration testers

Several of our colleagues are personally certified by the BSI as IS penetration testers. This personal qualification complements secuvera's certification as an IT security service provider.

View BSI qualification for IS penetration testers
BSI-certified IT-Grundschutz Consultant

Personal qualification

BSI-certified IT-Grundschutz Consultants

Several of our cybersecurity consultants are certified by the BSI as IT-Grundschutz Consultants. This personal qualification complements secuvera's BSI certification for IS consulting.

View personal qualifications in the BSI register

Personal qualification

ISO/IEC 27001 Lead Auditor

Several of our colleagues hold the ISO/IEC 27001 Lead Auditor qualification. Our consulting therefore also takes into account the evidence and questions raised in an audit.

ISO/IEC 27001 Lead Auditor qualification profile at PECB

Personal qualification

BSI-certified audit team leaders

Several of our colleagues are certified by the BSI as audit team leaders for ISO 27001 audits on the basis of IT-Grundschutz. The qualification concerns conducting the audits; the certification decision remains with the BSI.

View audit team leaders in the BSI register

Personal qualification

BCM Practitioner (TÜV) and crisis communication

Several of our colleagues have passed the BCM Practitioner (TÜV) examination for BCMS in accordance with BSI Standard 200-4. The team also includes a graduate of the “Crisis Communication Manager” training programme of the Deutsche Presseakademie.

BCM Practitioner examination profile at TÜV NORD (in German)

Personal qualification

Additional audit procedure competence for Section 8a BSIG

Several of our colleagues hold the additional audit procedure competence for Section 8a BSIG. It concerns the audit procedure; the sector expertise required for an engagement and the applicable audit framework must be considered separately.

View training profile for KRITIS audit procedure competence (in German)

Practical qualification

Red Team Operator (CRTO)

Several of our colleagues hold the Red Team Operator (CRTO) qualification. The team also includes the Offensive Security Certified Professional (OSCP) qualification. Both demonstrate practical skills in carrying out technical attacks.

Red Team Operator qualification at Zero-Point Security
eWPT – Web Application Penetration Tester

Practical qualification

Web Application Penetration Tester (eWPT)

The team includes the Web Application Penetration Tester (eWPT) qualification. It complements our web testing practice and our work with OWASP methods.

eWPT qualification profile at INE Security
eMAPT – Mobile Application Penetration Tester

Practical qualification

Mobile Application Penetration Tester (eMAPT)

The team includes the Mobile Application Penetration Tester (eMAPT) qualification. It covers practical security testing of mobile applications and complements our testing practice under BSI TR-03161 and BSI TR-03174.

eMAPT qualification profile at INE Security

Practical qualification

Offensive Security Certified Professional (OSCP)

Several of our colleagues hold the Offensive Security Certified Professional (OSCP) qualification. It demonstrates practical skills in carrying out penetration tests.

OSCP+ exam at OffSec (Exam Guide)

Personal qualification

ISO/IEC 42001 Provisional Implementer

The qualifications of our cybersecurity consultants include ISO/IEC 42001 Provisional Implementer. Its focus is the implementation of an AI management system.

ISO/IEC 42001 qualification profile at PECB

Personal qualification

OWASP SAMM Fundamentals

The qualifications in our team include the successfully completed OWASP SAMM Fundamentals course. It complements our work on assessing and improving secure development processes.

View the Software Assurance Maturity Model at OWASP SAMM

Practical qualification

Certified Professional Penetration Tester (eCPPT)

The team includes the Certified Professional Penetration Tester (eCPPT) qualification. The practical exam covers the technical execution of a penetration test and the documentation of the results.

eCPPT qualification profile at INE Security

Personal qualification

Cyber Security Practitioner (CSP)

Several of our colleagues hold the Cyber Security Practitioner (CSP) qualification from ISACA Germany. It concerns carrying out Cyber Security Checks (BSI/ISACA guideline).

CSP qualification profile at ISACA Germany

Personal qualification

Certified Information Systems Security Professional (CISSP)

The team includes the Certified Information Systems Security Professional (CISSP) qualification. It covers information security, risk management and security architecture.

CISSP qualification profile at ISC2

Personal qualification

Criteria knowledge up to CC:2022

Our experts have attended BSI workshops on Common Criteria CC:2022 and passed the final tests. The content covers Protection Profiles, Security Targets and an introduction to evaluation.

View BSI workshops on Common Criteria

Standards and methodology

Our experts help develop testing methods and contribute practical results to professional exchange. The original sources name their specific contributions.

TeleTrusT – IT Security made in Germany

Standards & methodology

Co-authored the penetration testing guide

secuvera co-authored the TeleTrusT guide on penetration testing. It covers the planning, execution and delimitation of technical tests – including web applications, Active Directory, Entra ID and mobile apps with a backend API.

View the TeleTrusT penetration testing guide (in German)

Standards & methodology

Co-developed testing methods for IEC 62443

secuvera played a leading role in the TeleTrusT test scheme for IEC 62443-4-2. The work translates requirements of the standard into comparable tests of technical security properties.

Read TeleTrusT on the authorship of the test scheme

Standards & methodology

Specifying requirements for industrial firewalls

A member of our team led the moderation of the TeleTrusT project for the Industrial Firewall Profile. The profile specifies technical security requirements for industrial firewalls with router functionality.

Read the TeleTrusT publication on the Industrial Firewall Profile

Standards & methodology

Co-developed the Cyber Security Check

Experts from our team are part of the author team of the Cyber Security Check V2 guideline. This contribution concerns precisely the methodology used in the check to assess organisational and technical security measures.

View authors and Cyber Security Check V2 guideline (PDF, in German)
OWASP Corporate Member

Standards & methodology

OWASP: membership and volunteer work

secuvera supports the work of OWASP as OWASP Corporate Member and Silver Sponsor. Employees volunteer in a personal capacity: Tobias Glemser leads the OWASP German Chapter, and colleagues contribute to the working group developing an introductory course for new chapter leads.

View the working group and chapter leadership at OWASP

Personal qualification

CyberRisikoCheck based on DIN SPEC 27076

The further training in our team includes the BSI course on using the software for the CyberRisikoCheck based on DIN SPEC 27076.

Learn about the CyberRisikoCheck at the BSI

Publications and research

Articles by our experts appear in iX and heise, among others. Here you will find a selection with a direct link to our consulting and testing practice. Research projects and technical publications make our work traceable beyond individual engagements.

Specialist publication

Testing large cloud environments (automatically)

Our article in the iX special issue on security tools describes how large cloud environments can be tested. It combines the selection of testing tools with the expert assessment of the cloud configuration.

Read the article on cloud testing at iX (in German)

Specialist publication

Detecting security flaws early with SAST tools

Our article in the iX special issue on security tools explains how static code analysis can uncover security flaws early. It reflects the methodical approach to SAST from our testing practice.

Read the SAST article at iX (in German)

Specialist publication

Examining attack surfaces with BBOT

Our article in the iX special issue on security tools presents how BBOT records publicly visible attack surfaces. It shows a methodical approach to researching and assessing exposed systems.

Read the BBOT article at iX (in German)

Specialist publication

Responding to emergencies in a targeted way – prepared with BCM

Cybersecurity consultants from our team have written about business continuity management in the iX emergency guide. The article covers preparing for outages and integrating existing structures.

Read the BCM article in the iX emergency guide (in German)

Specialist publication

Putting the OWASP Top Ten 2025 into context

Our article in iX puts the OWASP Top Ten 2025 into context. It explains the changes and the difference between risks and directly testable vulnerabilities – relevant for selecting and interpreting application tests.

Read the OWASP Top Ten article at heise (in German)

Research

5G security assessment in the OPNESAS project

In the OPNESAS research project, a BSI NESAS certification was carried out for the 5G core of a private campus network. secuvera performed the security assessment of the core network components; the BSI made the certification decision.

View the results of the OPNESAS evaluation

Research

Published vulnerabilities and security analyses

Our published security advisories document technical vulnerabilities, affected products and how they were handled with the respective manufacturers. They provide insight into the research and analysis behind technical security tests.

View published security advisories

Associations, committees and universities

OWASP Corporate Member and Silver Sponsor

We value being present at OWASP as a Corporate Member and support the organisation as a Silver Sponsor. Our employees have been active in the community for many years. With our membership, we support long-term work on open, practical application security.

Bitkom member

As a member of Bitkom, we are actively involved in the association's work. We contribute the perspective of an independent IT security service provider and take part in the exchange on the requirements for secure digitalisation.

CISO Alliance

secuvera is a supporting member of the CISO Alliance. We are involved in the association's work and in exchange with those responsible for information security. The focus is on the questions CISOs face in their daily work.

Alliance for Cyber Security

As a partner of the Alliance for Cyber Security (Allianz für Cyber-Sicherheit), we support exchange between companies, public authorities and security professionals. We share knowledge from our work and help make experience usable for others.

IT Security made in Germany

secuvera holds the “IT Security made in Germany” trust mark of TeleTrusT – IT Security Association Germany. We are very active in the association's work and contribute our experience from consulting and testing to professional exchange.

DIN member

We are a member of DIN and are involved in its standardisation committees. Our experts contribute to security standards and evaluation methods. In this way, experience from specific testing and consulting projects feeds into the further development of standards.

Cooperation with universities

We cooperate with various regional and national universities. In doing so, we combine questions from IT security practice with teaching and academic work. Students gain insight into real tasks and can try out their own ideas in projects.

  • We regularly offer internship semesters and supervise bachelor's and master's theses.
  • We hold colloquia and give guest lectures.
  • We carry out semester projects together with students.
Back to “About us”

You don't need to have all the answers yet.