Comparison Overview

The National Institutes of Health

VS

bioMérieux

The National Institutes of Health

9000 Rockville Pike, Bethesda, 20892, US
Last Update: 2026-04-01
Between 750 and 799

NIH is the only agency of its kind. We impact the health of the country and the world through unique and innovative medical research. Did you know that NIH is the largest public funder of biomedical research in the world, investing more than $32 billion a year to enhance life, and reduce illness and disability? NIH funded research has led to breakthroughs and new treatments, helping people live longer, healthier lives, and building the research foundation that drives discovery. Whether you are graduating with a bachelor's degree, working on your doctoral degree, entering the workforce for the first time, or changing careers, NIH offers a place for you to start and plenty of room to grow your career. When you join us, you’re not just advancing your career — you’re driving the health of our country forward. Official LinkedIn Account of the NIH. Privacy policy: http://go.usa.gov/x9svN Comment policy: https://bit.ly/3G6xq94 Engagement ≠ endorsement

NAICS: 541714
NAICS Definition: Research and Development in Biotechnology (except Nanobiotechnology)
Employees: 29,981
Subsidiaries: 50
12-month incidents
0
Known data breaches
0
Attack type number
0

bioMérieux

100, Allée Louis Pasteur, Marcy-l'Étoile, 69280, FR
Last Update: 2026-04-01
Between 750 and 799

A family-owned company, bioMérieux has grown to become a world leader in the field of in vitro diagnostics. Our entrepreneurial adventure, begun over a century ago, is driven by an unrelenting commitment to improve public health worldwide. Since 1963, we've been paving the way in the field of in vitro diagnostics and have contributed greatly to improving public health and making the world a healthier place. The solutions that our teams imagine, develop and manufacture are key to enable healthcare professionals and industry players to make confident decisions to improve patient outcome and ensure consumer safety.

NAICS: 541714
NAICS Definition: Research and Development in Biotechnology (except Nanobiotechnology)
Employees: 12,827
Subsidiaries: 6
12-month incidents
0
Known data breaches
0
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/national-institutes-of-health.jpeg
The National Institutes of Health
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/biomerieux.jpeg
bioMérieux
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
The National Institutes of Health
100%
Compliance Rate
0/4 Standards Verified
bioMérieux
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Biotechnology Research Industry Average (This Year)

No incidents recorded for The National Institutes of Health in 2026.

Incidents vs Biotechnology Research Industry Average (This Year)

No incidents recorded for bioMérieux in 2026.

Incident History — The National Institutes of Health (X = Date, Y = Severity)

The National Institutes of Health cyber incidents detection timeline including parent company and subsidiaries

Incident History — bioMérieux (X = Date, Y = Severity)

bioMérieux cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/national-institutes-of-health.jpeg
The National Institutes of Health
Incidents

No Incident

https://images.rankiteo.com/companyimages/biomerieux.jpeg
bioMérieux
Incidents

Date Detected: 6/2023
Type:Vulnerability
Attack Vector: Unauthorized Access
Blog: Blog

FAQ

The National Institutes of Health company demonstrates a stronger AI Cybersecurity Score compared to bioMérieux company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

bioMérieux company has historically faced a number of disclosed cyber incidents, whereas The National Institutes of Health company has not reported any.

In the current year, bioMérieux company and The National Institutes of Health company have not reported any cyber incidents.

Neither bioMérieux company nor The National Institutes of Health company has reported experiencing a ransomware attack publicly.

Neither bioMérieux company nor The National Institutes of Health company has reported experiencing a data breach publicly.

Neither bioMérieux company nor The National Institutes of Health company has reported experiencing targeted cyberattacks publicly.

bioMérieux company has disclosed at least one vulnerability, while The National Institutes of Health company has not reported such incidents publicly.

Neither The National Institutes of Health nor bioMérieux holds any compliance certifications.

Neither company holds any compliance certifications.

The National Institutes of Health company has more subsidiaries worldwide compared to bioMérieux company.

The National Institutes of Health company employs more people globally than bioMérieux company, reflecting its scale as a Biotechnology Research.

Neither The National Institutes of Health nor bioMérieux holds SOC 2 Type 1 certification.

Neither The National Institutes of Health nor bioMérieux holds SOC 2 Type 2 certification.

Neither The National Institutes of Health nor bioMérieux holds ISO 27001 certification.

Neither The National Institutes of Health nor bioMérieux holds PCI DSS certification.

Neither The National Institutes of Health nor bioMérieux holds HIPAA certification.

Neither The National Institutes of Health nor bioMérieux holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X