CryptoEng UG (haftungsbeschränkt)

Germany · owned by Independent (Germany) · celabs.eu · 7 vendors

CE Labs (trading name of CryptoEng UG) is a high-assurance security engineering company specialising in applied cryptography, protocol design, and formal verification. Founded as a spin-off from Cryspen, the company partners with organisations building software where security failures are unacceptable, offering services from threat modelling and protocol analysis to machine-checked correctness proofs. It also maintains open-source cryptographic libraries including post-quantum and classical primitive implementations.

Resilience scores

Disruption prediction

CryptoEng UG (haftungsbeschränkt) has an estimated 17% probability of disruption in the next 6 months.

2 of CryptoEng UG (haftungsbeschränkt)'s 7 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-09-15 · revision 3

7 direct vendors, 96 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

CryptoEng UG exhibits high migration readiness due to its modern and flexible internal tech stack. The primary use of Rust, along with advanced tools like F* and Lean, and the development of open-source, portable libraries (libcrux, libcrux-iot, hpke-rs, OpenMLS) indicates an architecture that is not tied to legacy systems and is highly adaptable to cloud-native environments. The use of Hugo for their website also points to a static, easily migratable web presence. The most significant challenge to migration readiness is the financial uncertainty, with 'None' reported for growth history and a lack of revenue concentration data, which could impact the ability to fund a substantial migration effort. While GDPR compliant, the pending NIS2 assessment introduces a new regulatory consideration that could add complexity to migration planning. Data residency requirements (Greece and other EU countries) will necessitate careful selection of cloud providers and regions to ensure compliance. The 'Vendor Lock-in Risk' is unknown, and the contradictory vendor data ('Total Vendors: 0' vs. geographic diversity) makes it difficult to precisely assess vendor dependencies, though the open-source nature of many of their products suggests potentially lower lock-in.

Compliance

9 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

As a cybersecurity service provider in Germany, CryptoEng UG could be classified as an 'Important Entity' under the NIS2 Directive. Applicability depends on whether it meets the size threshold of 50+ employees or over €10 million in annual turnover.

Non-compliance for an entity deemed 'Essential' or 'Important' can result in substantial fines and regulatory scrutiny. As a cybersecurity provider, a security incident could have a significant impact, making compliance a high-risk area.

GDPR (source) — Partially Compliant

CryptoEng UG is established in Germany, an EU member state. Therefore, it is subject to the General Data Protection Regulation for any processing of personal data, including that of employees, customers, and website visitors.

As a German company, non-compliance with GDPR can lead to significant fines (up to 4% of global turnover). The company processes personal data through its website, making compliance crucial. The risk is high due to the potential financial and reputational damage.

ISAE 3000 (source) — Assessment Required

ISAE 3000 is a standard for conducting assurance engagements. It is not a regulation that a company must comply with directly, but rather a framework that an auditor would use to provide an assurance report on a company's controls.

ISAE 3000 is a standard for assurance engagements on non-financial information. The risk of not having such a report is low unless specifically required by a client for a particular assurance engagement.

Financials

Financial Resilience Score: 4/10

CryptoEng UG is a micro-capitalised German Unternehmergesellschaft with only €500 in registered share capital, providing a minimal balance sheet cushion for absorbing losses or unexpected liabilities. The company operates in a technically attractive niche (post-quantum cryptography, formal verification) with strong regulatory tailwinds in Europe from NIS2, eIDAS 2, and BSI TR requirements. As a spin-off from Cryspen, it benefits from methodological continuity, established tooling (F*, Lean, libcrux), and likely inherited customer relationships. The founder Franziskus Kiefer brings notable credentials from Mozilla and Cryspen in TLS, MLS, and formal verification. However, the company faces significant structural risks. With only ~4 identifiable engineers and a single managing director, key-person concentration is high. The UG legal form carries signalling risk in enterprise procurement, and no public financial figures are available since the company likely uses the § 326 Abs. 2 HGB deposit option available to micro-entities. Customer concentration is likely material though unmeasured. The low fixed-cost structure of a small team provides some operational flexibility, but the minimal equity base and lack of financial transparency limit the resilience score.

Key strengths: Deep technical expertise in cryptography and formal verification, Spin-off from established parent Cryspen with methodology continuity, Post-quantum cryptography regulatory tailwind in EU (NIS2, eIDAS 2, BSI TR), Low fixed-cost structure with small team, Founder credentials from Mozilla/Cryspen

Risk factors: Micro-capitalisation with only €500 registered share capital, UG suffix signalling risk in enterprise procurement, Key-person concentration with single managing director and ~4 engineers, Likely high customer concentration (unmeasured), Limited financial transparency due to micro-entity deposit option, ~30% effective corporate tax burden in Berlin

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report