Independent · Evidence-led · EU

We vet systems, suppliers and people.

CYBERVETTER is an independent European cybersecurity assurance firm. We assess what others build, sell and claim — and we hand over evidence you can check yourself.

01

The three questions we are hired to answer

  • Is this actually secure?

    Systems, cloud estates, suppliers, acquisition targets, AI models. Independent technical assurance from people with no stake in the answer.

    Vetting
  • Can we prove it to a regulator?

    NIS2, DORA, ISO 27001, GDPR, the Cyber Resilience Act. Compliance built as a working management system, not a binder.

    Governance, Risk & Compliance
  • What do we do right now?

    Incident response, forensics, crisis leadership. Certified investigators who have run real incidents.

    Incident Response & Digital Forensics
02

What we do

Six practices and thirty-three services, from architecture vetting to forensic investigation, so a single question does not have to be split across several firms.

03

The regulatory clock

These are your deadlines. Each obligation below already applies to client organisations, or applies from the date shown.

Cyber Resilience Act · Deadline imminent

Vulnerability reporting obligations begin for manufacturers

Cyber Resilience Act guidance

NIS2 · Deadline

Enforceable across the European Union

Romania: GEO 155/2024, Law 124/2025, DNSC Orders 1 and 2/2025.

NIS2 guidance

DORA · Deadline

Applicable to financial entities and their critical ICT providers

DORA guidance

AI Act · Deadline

Article 50 transparency obligations apply

AI Act guidance

Cyber Resilience Act · Deadline

Full application, conformity assessment and CE marking

04

What you can check

Every finding comes with the evidence behind it

A penetration test finding arrives with reproduction steps, so you can run it yourself. An architecture review cites the specific configuration it is describing. A supplier assessment shows what we saw and where. A risk rating explains the reasoning, so you can disagree with it. Assurance work is only worth what its evidence is worth, and we hand the evidence over.

05

Independence

We sell nothing but judgement

How independence is maintained
  • We do not resell security products.
  • We do not manage client infrastructure.
  • We take no vendor commission and hold no reseller agreement.
06

Credentials

Certified practitioners on every engagement

Certifications held

  • CISSP
  • CISA
  • CISM
  • CRISC
  • CGEIT
  • TOGAF 9
  • ISO/IEC 27001 Lead Auditor
  • CEH
  • CHFI
  • CSSLP
  • CompTIA CASP+
  • PRINCE2
  • SAFe
  • PM2
  • ISTQB
  • ITIL

Consultant profiles map to the twelve role profiles of the ENISA European Cybersecurity Skills Framework.

Our consultants
07

Latest from Insights

Article slot 01

[PLACEHOLDER: article title]

[PLACEHOLDER: standfirst, author name with credentials, and publication date — added when the article is published.]

Article slot 02

[PLACEHOLDER: article title]

[PLACEHOLDER: standfirst, author name with credentials, and publication date — added when the article is published.]

Article slot 03

[PLACEHOLDER: article title]

[PLACEHOLDER: standfirst, author name with credentials, and publication date — added when the article is published.]

All insights

Tell us what you need assessed

Describe the system, supplier or obligation in question and we will tell you how we would approach it.

Contact us

Responding to an incident now? Incident contact.