Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

SGS vs TUV SUD

SGS

SGS is the world's largest testing, inspection, and certification company. Its cybersecurity arm, SGS Brightsight, runs accredited security-evaluation laboratories (including a facility in Graz, Austria) that assess digital products against CRA requirements and RED cybersecurity standards. SGS develops tailored CRA service packages and operates a Notified Body that can issue EU type certificates for RED Article 3(3) using EN 18031.

Pros
  • Massive global scale (~99,500 employees; ~2,500 labs/offices in 115 countries)
  • Brightsight is a top-tier security-evaluation lab with deep Common Criteria and high-assurance expertise
  • Notified Body able to issue EU type certificates for RED cybersecurity (EN 18031)
  • Accreditations including ISO/IEC 17025, plus IEC 62443 and EN 18031 capability
Things to check
  • Large enterprise TIC firm — formal certification-led engagements, less suited to small or early-stage manufacturers
  • No public pricing
  • Evaluation/certification focus rather than ongoing in-house remediation engineering

Pricing: Custom (contact sales)

TUV SUD

TUV SUD is a global testing, inspection, and certification organization with a dedicated CRA practice in its product-testing and cybersecurity divisions. It helps manufacturers interpret CRA obligations, run gap assessments, set up vulnerability management and incident reporting, and obtain third-party assessment for higher-risk products. It also runs RED cybersecurity testing against the EN 18031 series.

Pros
  • Long-established, globally accredited certification body (25,000+ employees, 1,000+ locations)
  • Established Notified Body for RED cybersecurity under EN 18031 (a strong precedent for CRA conformity work)
  • Combines testing labs, certification, and structured training under one roof
  • Deep cross-sector regulatory experience across CE marking directives
Things to check
  • Large enterprise TIC firm — engagements tend to be formal and process-heavy
  • No public pricing
  • Certification/assessment-led rather than hands-on engineering remediation

Pricing: Custom (contact sales)