HomeFrameworksNational Cyber & Cloud SchemesCyberTrust

Framework  National Cyber & Cloud Schemes

CyberTrust

The Cyber Trust Austria label (now marketed across borders as Cyber Trust Europe) is a voluntary cybersecurity quality label for companies, developed by the Kompetenzzentrum Sicheres Österreich (KSÖ) with the credit agency KSV1870 and operated by Cyber Trust Services GmbH.

It is built on the KSV1870 Cyber Risk Rating scheme, a questionnaire-based rating of an organization's basic cyber hygiene that Austrian companies increasingly use to screen suppliers.

The label comes in tiers: Standard and Silver are based on a validated self-declaration against the rating questionnaire (Silver corresponds to a KSV1870 CyberRisk A rating and its 25 questions), Gold requires an on-site audit by a qualified auditor accredited under Austria's NIS Act (corresponding to an A+ rating), and a Platinum tier exists for the most demanding profile (verify the current tier definitions on the scheme site).

Labels are valid for one year.

The label is a supply chain trust signal rather than a regulatory requirement. In writing, an applicant needs an information security policy, an asset and system overview, evidence for the questionnaire items (patching, backups, access control, MFA, awareness training, incident handling, supplier management), and for Gold the documentation an auditor will sample against the requirements catalog.

AI-compiled
Share
Sponsored
CyberTrust
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with CyberTrust
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary. Any company, primarily Austrian and Central European SMEs and mid-sized firms, that wants to demonstrate baseline cyber hygiene to customers and insurers; some larger Austrian buyers ask suppliers for the label or the underlying KSV1870 rating.

What the assessor asks to see

Completed KSV1870 Cyber Risk Rating questionnaire (25 questions for A, extended set for A+); information security policy; asset overview; patch and update management records; backup and recovery evidence; access control and MFA configuration; awareness training records; incident response procedure; supplier and service provider management; for Gold, on-site audit sampling of these controls against the requirements catalog.

Assessors

Who assesses CyberTrust

For Standard and Silver, the scheme operator validates the self-declaration for completeness and plausibility. For Gold, a qualified auditor accredited under Section 18 of the Austrian NIS Act (NISG) performs an audit. Platinum follows the scheme's stated audit requirements.

Accredited by For Gold audits, auditor qualification rests on accreditation as a qualified body under the Austrian NIS Act (overseen by the Austrian NIS authority); the scheme operator issues the label.

Public register of assessors: https://www.cyber-trust-europe.eu/label-download/

No firm has claimed a CyberTrust assessor listing yet. Claim yours →

Consultants

Who helps with CyberTrust

Austrian IT security consultancies and managed service providers prepare companies for the questionnaire and Gold audit; the scheme publishes the requirements catalog so preparation is straightforward. Engagements are typically short, a few weeks.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a CyberTrust consultant listing yet. Claim yours →

Software

Tools for CyberTrust

Tools that name this framework in their own material.

No firm has claimed a CyberTrust tool listing yet. Claim yours →

Need a hand implementing it?

Find a Consultant for CyberTrust

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with CyberTrust

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.