Key findings
- • 288 domains across 6 sectors scanned: 0 of 288 reach CERTIFIED (75+ points).
- • Best sector average: financial sector (BaFin) at Ø 30.1 points, despite DORA obligations in effect since January 2025.
- • Highest single score: 55.1 points in the healthcare sector. Lowest: 1.6 points in the DAX.
- • Critical infrastructure: 87 % of domains score below 20 points.
- • Cluster E (Agentic Readiness) and Cluster F (AI Governance) are the structurally weakest layers across every sector.
Thesis Layer-0 infrastructure validation is the precondition every AI governance framework silently assumes. This benchmark shows: the assumption has no empirical basis.
On June 11, 2026, CERTavia scanned a total of 288 European enterprise domains across six sectors. The result is unambiguous and holds across every sector: not a single company reaches the CERTavia CERTIFIED threshold of 75 points. The average CES score across all 288 domains is 22.9 points.
Methodology
Each domain runs through the full CERTavia Evaluation Score (CES). The score aggregates 80+ parameters across six clusters:
- Cluster A: Digital infrastructure
- Cluster B: Machine readability
- Cluster C: Legal compliance
- Cluster D: Transparency & consent
- Cluster E: Agentic readiness
- Cluster F: AI governance
All scans were performed on June 11, 2026. The results are anonymized: company names are not disclosed in this public report. The paid sector data packages provide distribution metrics (median, quartiles, grade histogram) as well as your own domain benchmarked against its sector — no named list of the remaining domains.
Results at a glance
All six sectors sit well below the CERTIFIED threshold. BaFin-regulated financial institutions, the strongest sector, average 30.1 points. That corresponds to 40 % of the target mark.
| Sector | Domains | Ø CES | Max CES | Min CES | CERTIFIED |
|---|---|---|---|---|---|
| DAX 40 | 40 | 22.7 | 53.5 | 1.6 | 0 |
| Automotive & industry | 50 | 29.5 | 47.0 | 10.8 | 0 |
| Financial sector (BaFin) | 50 | 30.1 | 47.8 | 16.0 | 0 |
| Healthcare & pharma | 50 | 20.7 | 55.1 | 7.6 | 0 |
| Critical infrastructure | 49 | 13.6 | 38.6 | 7.6 | 0 |
| Federal government & EU | 49 | 20.2 | 37.5 | 8.6 | 0 |
| Total | 288 | 22.9 | 55.1 | 1.6 | 0 |
The CERTIFIED threshold is 75 points. The sector average of the strongest sector (BaFin, 30.1) doesn't even reach half of that mark. The scale runs from 0 to 100; no value in this benchmark exceeds 55.1.
Sector profile: six industries compared
The tiles below show average CES, range and score distribution per sector. All values are from the scan on June 11, 2026.
DAX 40
Automotive & industry
Financial sector (BaFin)
Healthcare & pharma
Critical infrastructure
Federal government & EU
Sector deep dive
Every sector has its own risk profile. The following sections show the top 5 per sector (anonymized) plus the structural core issue.
DAX 40: widest spread, highest tail risk
Top 5 (anonymized)
- #153.5
- #246.0
- #337.8
- #437.1
- #536.6
The DAX shows the widest range of any sector: between 1.6 and 53.5 lies a spread of 51.9 points. 50 % of DAX domains score below 19 points. Investor-side compliance pressure has not yet reached the technical infrastructure.
Automotive & industry: strongest sector, still far from CERTIFIED
Top 5 (anonymized)
- #147.0
- #246.6
- #346.1
- #443.3
- #542.9
Automotive is the only sector without a single domain below 10 points. The mid-field cluster (30–40 points) accounts for 40 % of all domains. The sector's top score exceeds the DAX's top score, suggesting a degree of prioritization of infrastructure compliance within German industrial culture.
Financial sector (BaFin): DORA-compliant? The CES says no.
Top 5 (anonymized)
- #147.8
- #247.2
- #342.5
- #442.3
- #540.8
The financial sector has the highest average of any sector (30.1). No institution scores below 16 points. The Digital Operational Resilience Act (DORA) has been binding for all BaFin-regulated institutions since January 2025. The sector average of 30.1 corresponds to 40 % of the CERTIFIED threshold. This shows: regulatory pressure produces baseline competence, but not top-tier performance.
Healthcare & pharma: highest peak, steepest drop
Top 5 (anonymized)
- #155.1
- #250.2
- #339.2
- #436.2
- #536.1
The highest single value of all 288 domains comes from the healthcare sector (55.1). At the same time, 56 % of sector domains score below 20 points, including several university hospitals and hospital chains. Highly regulated pharmaceutical companies and digital health infrastructure live in different compliance worlds.
Critical infrastructure: systemically important, infrastructurally underserved
Top 5 (anonymized)
- #138.6
- #233.7
- #327.2
- #426.7
- #523.7
87 % of critical-infrastructure domains score below 20 points. Energy, telecommunications and network infrastructure have structurally different requirements than financial-services providers. Cluster A (Digital Infrastructure) is particularly weak in this sector, because ISPs and energy providers expose different technical endpoints. NIS2 has applied since October 2024: the measured data shows no discernible infrastructure adaptation.
Federal government & EU: the regulators miss their own bar
Top 5 (anonymized)
- #137.5
- #235.8
- #332.4
- #432.3
- #532.2
The government bodies enforcing NIS2 and the EU AI Act on companies achieve an average of 20.2 points. Not a single federal ministry or regulatory institution reaches the CERTIFIED threshold. The highest score in the sector is 37.5. That corresponds to the mid-field of the financial sector and represents a structural credibility problem for the entirety of European digital regulation.
Cluster analysis: where are the weak points?
The CES distributes its 80+ parameters across six clusters. The following breakdown shows the average values across all 288 scanned domains.
Cluster E (Agentic Readiness, Ø ~9) and Cluster F (AI Governance, Ø ~6) form the infrastructural precondition for rule-compliant AI systems under the EU AI Act. The market treats this layer as a solved problem. The measured data shows the opposite.
Regulatory context
Three European regulatory frameworks are immediately relevant:
DORA (Digital Operational Resilience Act) has been binding for all BaFin-regulated institutions since January 2025. The average CES score of the 50 largest German banks and financial institutions is 30.1 points. The CERTIFIED threshold is 75 points.
NIS2 has applied since October 2024 to operators of essential and important entities, which includes every critical-infrastructure operator in this benchmark. The sector average is 13.6 points.
The EU AI Act classifies AI systems into high-risk categories whose operators must maintain demonstrable infrastructure governance. Cluster F measures exactly this governance layer. The cross-sector average is ~6 points. The proof obligation meets an infrastructure that is structurally unprepared for this proof.
Takeaways
The strongest single values are 55.1 (healthcare), 53.5 (DAX) and 47.8 (BaFin). These are upward outliers, not a sector pattern. They show that a CES above 50 is technically achievable. They also show that no company in this benchmark has found the path to 75.
Particularly telling is the government panel: federal ministries and EU institutions that enforce NIS2 and the AI Act on third parties achieve an average of 20.2 points. The regulators themselves are not CERTIFIED-ready.
Complete sector rankings: anonymized and as PDF
About this report
The CERTavia DACH Benchmark is published semi-annually. All scans are performed with the CERTavia Evaluation Score (CES), the deterministic validation protocol for digital infrastructure under the EU AI Act, NIS2 and DORA.
Companies that want to determine their own CES score can get started at certavia.org/en/how-it-works. The free scan delivers Clusters A–F and a comparison against the sector average in under 60 seconds.
Full sector data packages with all domains, rank positions and historical comparison values are available as a Pro product. Interested? View sector data.
CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of an EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, please contact an accredited conformity assessment body.