Comparison Overview

The National Institutes of Health

VS

Charles River Laboratories

The National Institutes of Health

9000 Rockville Pike, Bethesda, MD, US, 20892
Last Update: 2025-12-09
Between 750 and 799

NIH is the only agency of its kind. We impact the health of the country and the world through unique and innovative medical research. Did you know that NIH is the largest public funder of biomedical research in the world, investing more than $32 billion a year to enhance life, and reduce illness and disability? NIH funded research has led to breakthroughs and new treatments, helping people live longer, healthier lives, and building the research foundation that drives discovery. Whether you are graduating with a bachelor's degree, working on your doctoral degree, entering the workforce for the first time, or changing careers, NIH offers a place for you to start and plenty of room to grow your career. When you join us, you’re not just advancing your career — you’re driving the health of our country forward. Official LinkedIn Account of the NIH. Privacy policy: http://go.usa.gov/x9svN Comment policy: https://bit.ly/3G6xq94 Engagement ≠ endorsement

NAICS: 541714
NAICS Definition: Research and Development in Biotechnology (except Nanobiotechnology)
Employees: 29,850
Subsidiaries: 50
12-month incidents
0
Known data breaches
0
Attack type number
0

Charles River Laboratories

251 Ballardvale Street, Wilmington, Massachusetts, US, 01887
Last Update: 2025-12-13
Between 750 and 799

At Charles River, we are guided by our strong purpose—to create healthier lives—which centers around the patients who rely on the therapeutics we help to develop, the animals in our care, to our planet, and to the passionate and skilled people who are at the heart of our organization and make it all possible. #DrugDiscovery #Biotech #Biotechnology #Pharmaceuticals #CRL

NAICS: 541714
NAICS Definition: Research and Development in Biotechnology (except Nanobiotechnology)
Employees: 14,752
Subsidiaries: 2
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/national-institutes-of-health.jpeg
The National Institutes of Health
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/charles-river-laboratories.jpeg
Charles River Laboratories
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
The National Institutes of Health
100%
Compliance Rate
0/4 Standards Verified
Charles River Laboratories
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Biotechnology Research Industry Average (This Year)

No incidents recorded for The National Institutes of Health in 2025.

Incidents vs Biotechnology Research Industry Average (This Year)

No incidents recorded for Charles River Laboratories in 2025.

Incident History — The National Institutes of Health (X = Date, Y = Severity)

The National Institutes of Health cyber incidents detection timeline including parent company and subsidiaries

Incident History — Charles River Laboratories (X = Date, Y = Severity)

Charles River Laboratories cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/national-institutes-of-health.jpeg
The National Institutes of Health
Incidents

No Incident

https://images.rankiteo.com/companyimages/charles-river-laboratories.jpeg
Charles River Laboratories
Incidents

No Incident

FAQ

The National Institutes of Health company demonstrates a stronger AI Cybersecurity Score compared to Charles River Laboratories company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, Charles River Laboratories company has disclosed a higher number of cyber incidents compared to The National Institutes of Health company.

In the current year, Charles River Laboratories company and The National Institutes of Health company have not reported any cyber incidents.

Neither Charles River Laboratories company nor The National Institutes of Health company has reported experiencing a ransomware attack publicly.

Neither Charles River Laboratories company nor The National Institutes of Health company has reported experiencing a data breach publicly.

Neither Charles River Laboratories company nor The National Institutes of Health company has reported experiencing targeted cyberattacks publicly.

Neither The National Institutes of Health company nor Charles River Laboratories company has reported experiencing or disclosing vulnerabilities publicly.

Neither The National Institutes of Health nor Charles River Laboratories holds any compliance certifications.

Neither company holds any compliance certifications.

The National Institutes of Health company has more subsidiaries worldwide compared to Charles River Laboratories company.

The National Institutes of Health company employs more people globally than Charles River Laboratories company, reflecting its scale as a Biotechnology Research.

Neither The National Institutes of Health nor Charles River Laboratories holds SOC 2 Type 1 certification.

Neither The National Institutes of Health nor Charles River Laboratories holds SOC 2 Type 2 certification.

Neither The National Institutes of Health nor Charles River Laboratories holds ISO 27001 certification.

Neither The National Institutes of Health nor Charles River Laboratories holds PCI DSS certification.

Neither The National Institutes of Health nor Charles River Laboratories holds HIPAA certification.

Neither The National Institutes of Health nor Charles River Laboratories holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Risk Information
cvss3
Base: 8.1
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Risk Information
cvss3
Base: 2.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this issue. You should upgrade the affected component. The vendor confirms that this is "[f]ixed in version 4.10.2". Furthermore, that "[b]ackports for older versions in process and will be out as soon as their respective CI pipelines complete."

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Risk Information
cvss3
Base: 4.5
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Risk Information
cvss3
Base: 5.8
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N