65,000+ global labs and counting

Is this your lab? Claim this profile to earn a Verified badge, receive testing leads, and manage your listing — free.

Claim this profile

SGS BRIGHTSIGHT BARCELONA, S.L. (Unipersonal)

SpainSant Cugat del Vallès, Spain· 10:10 PM Website
Accepts NDA

About

SGS Brightsight Barcelona, S.L. (Unipersonal) is a specialist IT security evaluation and certification laboratory operating under the global SGS group (SGS Société Générale de Surveillance SA), the world's leading testing, inspection, and certification company. Based in Barcelona, Spain, Brightsight functions simultaneously as an accredited IT Security Evaluation Facility (ITSEF) and an independent Certification Body (CB), providing end-to-end security assurance services that span the full product development lifecycle — from early-stage pre-evaluation and architecture review through to formal certification submission. The organisation serves manufacturers, developers, and product integrators across highly regulated technology sectors who require independent, impartial security attestation to access global markets.

Brightsight's core service offering centres on security evaluations conducted under internationally recognised frameworks. The laboratory is equipped and authorised to evaluate products against the EU Cybersecurity Certification Scheme on Common Criteria (EUCC), the definitive European successor to the SOGIS Mutual Recognition Agreement (MRA), as well as the globally accepted Common Criteria standard (ISO/IEC 15408). Additional schemes in scope include the NSCIB (Netherlands Scheme for Certification in the area of IT Security), the full suite of PCI Security Standards Council programmes — encompassing MPoC, SPoC, 3DS SDK, and CPoC — EMVCo security requirements for payment technology, the Radio Equipment Directive (RED), the EU Cyber Resilience Act (CRA), PSA Certified, SESIP (Security Evaluation Standard for IoT Platforms), and GSMA security guidelines. This breadth of scheme coverage enables Brightsight to serve clients seeking multi-framework compliance through a single evaluation partner.

The Internet of Things (IoT) sector represents a significant and growing area of Brightsight's work. As connected devices proliferate across consumer, industrial, automotive, and healthcare environments, the risk landscape around cyberattacks, data breaches, and system vulnerabilities has intensified. Brightsight offers IoT security evaluation and certification services that address these risks, and has recently been designated as a PSA Certified Certification Body — meaning it can now issue PSA Certified credentials directly in-house. This designation also enables combined PSA and SESIP certification services, streamlining the compliance pathway for IoT product developers. A landmark achievement in this domain was Brightsight's assessment leading to the world's first SESIP Assurance Level 3 certificate for a UWB (Ultra-Wideband) module: Samsung's U100 device, the first UWB product within the Car Connectivity Consortium's Digital Key programme to reach SESIP3 status.

Telecommunication and network infrastructure is another domain in which Brightsight holds market leadership. The laboratory provides tailored security evaluation services for routers, switches, servers, firewalls, and access control systems, supporting manufacturers seeking certification under Common Criteria, RED, CRA, and other applicable schemes. A dedicated SpaceTeam within Brightsight specialises in secure telecommunication, network security, and key management for space applications; this team holds clearances to work with EU classified information and other highly sensitive government domains, making Brightsight one of very few commercial evaluation facilities capable of handling space-sector security assessments.

In the payment technology sector, Brightsight brings deep expertise in contact and contactless payment solutions, encompassing mobile payment applications, payment terminals, and payment cards. Recognising that time-to-market is a competitive critical factor for payment product developers, the laboratory offers tailored, expedited evaluation pathways to minimise delays. For government identity programmes, Brightsight supports clients with eIDAS compliance (covering remote electronic signatures and electronic seals), electronic passports and signature products, and national identity scheme evaluations including BSPA and LINCE programmes. The integrated circuit practice covers security certification for smart cards, soft IP cores, systems-on-chip (SoC), and Industrial IoT (IIoT) devices evaluated against Common Criteria, EMVCo, and PSA Certified requirements.

Operating with structural impartiality is a defining characteristic of Brightsight's model. By combining the functions of a Certification Body and an ITSEF under a single organisation while maintaining independence between those roles, Brightsight ensures that certification decisions are transparent, unbiased, and fully defensible before national authorities and scheme owners. This dual-role model also reduces handoff friction for clients, who can progress from evaluation to certification without transferring documentation or context to a separate third-party CB. The laboratory's independence is further underpinned by its position within SGS, whose global quality infrastructure and governance frameworks provide additional assurance of procedural rigour.

Beyond formal evaluation and certification, Brightsight offers professional advisory services designed to empower product developers and manufacturers throughout the security development lifecycle. These include pre-evaluation consulting, design and architecture reviews, hands-on developer support, and structured training courses — all aimed at reducing rework and improving first-pass certification success rates. The organisation publishes the Brightsight Bulletin, a curated newsletter covering cybersecurity regulatory developments, scheme updates, and expert commentary, demonstrating a commitment to knowledge-sharing across its client communities in payment, IoT, medical, automotive, industrial, government, and telecommunications sectors. Brightsight also actively participates in industry forums such as the Open Compute Project (OCP), reflecting its engagement with emerging open-infrastructure security challenges under frameworks like OCP S.A.F.E. and the Cyber Resilience Act.

Industries served

Consumer ProductsMedical Devices

Test categories

Product safety