Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

SGS vs Bureau Veritas

SGS

SGS is the world's largest testing, inspection, and certification company. Its cybersecurity arm, SGS Brightsight, runs accredited security-evaluation laboratories (including a facility in Graz, Austria) that assess digital products against CRA requirements and RED cybersecurity standards. SGS develops tailored CRA service packages and operates a Notified Body that can issue EU type certificates for RED Article 3(3) using EN 18031.

Pros
  • Massive global scale (~99,500 employees; ~2,500 labs/offices in 115 countries)
  • Brightsight is a top-tier security-evaluation lab with deep Common Criteria and high-assurance expertise
  • Notified Body able to issue EU type certificates for RED cybersecurity (EN 18031)
  • Accreditations including ISO/IEC 17025, plus IEC 62443 and EN 18031 capability
Things to check
  • Large enterprise TIC firm — formal certification-led engagements, less suited to small or early-stage manufacturers
  • No public pricing
  • Evaluation/certification focus rather than ongoing in-house remediation engineering

Pricing: Custom (contact sales)

Bureau Veritas

Bureau Veritas is an 1828-founded testing, inspection, and certification group. Its Bureau Veritas Cybersecurity division (built around the acquired specialist Secura) maps CRA requirements to existing standards and delivers end-to-end compliance, from gap assessment to penetration testing and conformity advisory. Its consumer-products and certification arms run accredited RED cybersecurity testing and CE-marking support across labs in Germany, France, China, and Taiwan.

Pros
  • Combines a 300+ specialist cybersecurity team (ex-Secura) with large TIC certification infrastructure
  • Accredited for RED certification with multi-region radio and cybersecurity testing labs
  • Recognized certification routes: IECEE for IEC 62443, Common Criteria under NSCIB/EU CC
  • 50+ end-to-end cybersecurity, compliance, and training services
Things to check
  • Large global TIC group — engagements skew enterprise and formal
  • No public pricing
  • Offering split across multiple Bureau Veritas entities, which can complicate scoping

Pricing: Custom (contact sales)