Comparison Overview

National Institute of Standards and Technology (NIST)

VS

PPD

National Institute of Standards and Technology (NIST)

100 Bureau Drive, Gaithersburg, MD, US, 20899
Last Update: 2025-12-01
Between 700 and 749

We are the National Institute of Standards and Technology (NIST), a non-regulatory federal agency within the U.S. Department of Commerce. For more than a century, NIST has helped to keep U.S. technology at the leading edge. Our measurements support the smallest of technologies to the largest and most complex of human-made creations. NIST's mission is to promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and improve our quality of life. See what innovative work we’re doing to support it: https://www.nist.gov/

NAICS: 5417
NAICS Definition: Scientific Research and Development Services
Employees: 4,906
Subsidiaries: 9
12-month incidents
2
Known data breaches
1
Attack type number
2

PPD

168 3rd Ave, Waltham, 02451, US
Last Update: 2025-11-28
Between 750 and 799

The PPD™ clinical research business of Thermo Fisher Scientific, the world leader in serving science, enables customers to accelerate innovation and drug development through patient-centered strategies and data analytics. Our services, which span multiple therapeutic areas, include early development, all phases of clinical development, peri- and post-approval, patient recruitment, investigator sites and comprehensive laboratory services. As a global industry leader, we offer custom solutions to pharma, biotech, medical device, and government organizations, leveraging cutting-edge technology and therapeutic expertise to help customers deliver life-changing therapies.

NAICS: 5417
NAICS Definition: Scientific Research and Development Services
Employees: 22,755
Subsidiaries: 18
12-month incidents
0
Known data breaches
1
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/nist.jpeg
National Institute of Standards and Technology (NIST)
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/ppd.jpeg
PPD
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
National Institute of Standards and Technology (NIST)
100%
Compliance Rate
0/4 Standards Verified
PPD
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Research Services Industry Average (This Year)

National Institute of Standards and Technology (NIST) has 284.62% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs Research Services Industry Average (This Year)

No incidents recorded for PPD in 2025.

Incident History — National Institute of Standards and Technology (NIST) (X = Date, Y = Severity)

National Institute of Standards and Technology (NIST) cyber incidents detection timeline including parent company and subsidiaries

Incident History — PPD (X = Date, Y = Severity)

PPD cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/nist.jpeg
National Institute of Standards and Technology (NIST)
Incidents

Date Detected: 2/2025
Type:Breach
Motivation: Deprioritizing AI safety in favor of AI opportunity
Blog: Blog

Date Detected: 2/2025
Type:Cyber Attack
Motivation: Reduction in workforce and rescinding of executive order
Blog: Blog
https://images.rankiteo.com/companyimages/ppd.jpeg
PPD
Incidents

Date Detected: 7/2017
Type:Breach
Attack Vector: Email Compromise
Blog: Blog

FAQ

PPD company demonstrates a stronger AI Cybersecurity Score compared to National Institute of Standards and Technology (NIST) company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

National Institute of Standards and Technology (NIST) company has faced a higher number of disclosed cyber incidents historically compared to PPD company.

In the current year, National Institute of Standards and Technology (NIST) company has reported more cyber incidents than PPD company.

Neither PPD company nor National Institute of Standards and Technology (NIST) company has reported experiencing a ransomware attack publicly.

Both PPD company and National Institute of Standards and Technology (NIST) company have disclosed experiencing at least one data breach.

National Institute of Standards and Technology (NIST) company has reported targeted cyberattacks, while PPD company has not reported such incidents publicly.

Neither National Institute of Standards and Technology (NIST) company nor PPD company has reported experiencing or disclosing vulnerabilities publicly.

Neither National Institute of Standards and Technology (NIST) nor PPD holds any compliance certifications.

Neither company holds any compliance certifications.

PPD company has more subsidiaries worldwide compared to National Institute of Standards and Technology (NIST) company.

PPD company employs more people globally than National Institute of Standards and Technology (NIST) company, reflecting its scale as a Research Services.

Neither National Institute of Standards and Technology (NIST) nor PPD holds SOC 2 Type 1 certification.

Neither National Institute of Standards and Technology (NIST) nor PPD holds SOC 2 Type 2 certification.

Neither National Institute of Standards and Technology (NIST) nor PPD holds ISO 27001 certification.

Neither National Institute of Standards and Technology (NIST) nor PPD holds PCI DSS certification.

Neither National Institute of Standards and Technology (NIST) nor PPD holds HIPAA certification.

Neither National Institute of Standards and Technology (NIST) nor PPD holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipulation of the argument First Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 3.3
Severity: LOW
AV:N/AC:L/Au:M/C:N/I:P/A:N
cvss3
Base: 2.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 4.8
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the default configuration of this MCP server at the affected version (as of commit 2f3a5512 in September of 2025).

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in Qualitor 8.20/8.24. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing manipulation of the argument passageiros results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X