How do you choose a provider for EVO or TSCM examination?
You do not judge a provider of electronic security surveys (EVO), TSCM sweeps or technical counter-espionage examination on the outcome alone. An examination that finds nothing and a superficial sweep can, after all, produce the same end result: a report without findings.
Look above all at the working method. Which threat profile is established beforehand? What falls within the scope? Which methodology is applied? Which examination lines are followed? How is equipment that does not transmit dealt with? What happens to your measurement data? And, just as importantly: does the report also state what was not established?
On this page we set out what you can assess a provider on, and we hold GreyOps to the same yardstick.
Why the outcome alone says little about quality
A sweep has an awkward inherent characteristic: when nothing is found, that outcome does not tell you whether the search was thorough. That makes statements such as “the room is clean” of little value. A sound conclusion states not only what was found but also what was examined for, with which methods, under which conditions and where the limits of the examination lay. Quality therefore has to be visible earlier in the process. What you can assess is:
- what is recorded in writing beforehand;
- how the examination scope is arrived at;
- which technical examination lines are carried out;
- how reproducible and traceable the methodology is;
- how measurement data and client information are handled;
- and how explicitly the provider states its own limitations.
Those are characteristics that let you compare providers against one another.
1. Who has an interest in the outcome?
Independence starts with a simple question: does the examiner also earn from the measures that follow from their own findings?
Ask, for example:
- does the provider sell shielding, detection equipment, secure rooms or security (advisory) services itself?
- does additional work depend on what is found during the examination?
- does the provider receive commission or other benefits from suppliers?
- is there a commercial relationship with the suppliers of your existing audiovisual, building management or security installations?
- can the party advise that no additional investment is needed without losing revenue by doing so?
That a provider also supplies products does not automatically mean the examination is unsound. What matters is that you, as the client, recognise and weigh it.
A useful international reference for that principle is ISO/IEC 17020. That standard covers competence, impartiality and consistent operation by inspection bodies, and distinguishes among other things independent third parties. A TSCM provider does not have to fall under this standard to use its principles as a yardstick.
How GreyOps handles this
GreyOps does not sell detection equipment, shielding products or other hardware. If a measure follows from an examination, we describe what that measure has to achieve and how the result can be established. Who supplies it remains your choice. Our revenue model therefore does not change on the basis of what we find.
2. What is recorded before measurement begins?
A technical examination does not start with an instrument such as a spectrum analyser, but with the question of what you actually want to be examined against.
Before the work begins, it should therefore be clear:
- which threat profile is applied;
- which information or other protected interests are central;
- which actors realistically may have an interest;
- which capabilities and access they may have;
- which rooms, objects, installations and adjacent zones are examined;
- which examination lines are carried out;
- which criteria are used in the assessment;
- what explicitly falls outside the scope;
- and what happens if the agreed examination conditions turn out not to be achievable during the work.
Without those choices, assumptions still exist — only nobody has written them down. That is an important difference. A competitor, a malicious insider, organised crime and a state actor do not have the same capabilities. An examination carried out identically for every client is therefore not automatically less thorough, but it is less targeted.
How GreyOps handles this
We record the threat profile and the examination scope in advance. The technical methodology follows from that. Our knowledge development is explicitly aimed at high-end and state-level attack capabilities too. That does not mean every client needs an examination at that level. It means we can distinguish when a lighter profile suffices and when it does not. You therefore pay for the examination that fits your threat profile, not by default for the heaviest conceivable scenario.
3. What does the examination cover technically?
Do not only ask which equipment a provider owns. Ask above all which attack vectors are examined with it.
Depending on the threat profile and the scope, a technical examination can consist of, for example:
- examination of the radio-frequency spectrum;
- physical inspection of the room, furniture and equipment;
- examination of telephone, network, power and other conductive connections;
- examination of fixed infrastructure and peripherals;
- non-linear junction detection for electronic components that do not transmit themselves;
- acoustic and structure-borne examination;
- optical examination;
- examination for unwanted or compromising electromagnetic emanation.
The most important check question
How do you search for a device that transmits nothing during the measurement?
A recorder that only stores locally, a switched-off electronic device or a facility activated only at a specific moment will produce no radio signal during a passive RF measurement. An examination consisting solely of looking at the radio-frequency spectrum therefore answers only part of the question. That does not mean spectrum analysis is unimportant — on the contrary — but that the methods chosen have to cohere with the threat profile.
Ask in addition
- how much examination time is foreseen per room, and on what basis?
- is adjacent infrastructure included as well?
- how is a distinction made between explainable and unknown signals?
- is representative use of the room taken into account where that is meaningful?
- which instruments are deployed and how is their measurement performance verified?
- how are the known limitations of each method reflected in the conclusion?
The list of brand names in a quotation matters far less than the answers to these questions.
4. How is your own information protected during the examination?
A sweep generates sensitive information of its own. Measurement data, photographs, floor plans, cabling routes, anomalies, equipment inventories and draft findings can together give a highly detailed picture of your organisation’s technical set-up.
Ask a provider therefore:
- where the raw measurement data are stored;
- which systems process the data;
- whether cloud or SaaS services are used for that;
- whether AI, transcription or other external processing services are deployed;
- which equipment has a network connection during the examination itself;
- who has access to the data;
- how data are encrypted;
- which retention period applies;
- and how destruction takes place.
A non-disclosure agreement is useful, but may not adequately close these operational vulnerabilities.
How GreyOps handles this
Our measurement and analysis systems operate without an internet connection during assignments. The substantive work is also carried out within a segregated environment. For assignment data we use no public cloud storage, online transcription services or generative AI. Measurement data and draft documents are held on encrypted media, in hardware and in software. Retention period and destruction date can be agreed per assignment in advance.
We also take no mobile phone into the room under examination. For documentation we use equipment dedicated to that purpose: air-gapped, without a network connection. The practical contact arrangement during the examination is agreed with you beforehand. These are not symbolic measures for appearance’s sake but deliberate operational choices. An examination of uncontrolled technical channels should not itself introduce further uncontrolled channels.
5. What does a sweep say about the period afterwards?
A sweep is always tied to a moment of examination and a described situation. Active RF presence can be moment-dependent. A device that is not active during the examination can become active at another time. Other characteristics are more structural. Consider:
- the routing of cabling;
- the layout of a room;
- the integrity of shielding;
- acoustic transmission;
- sight lines;
- the configuration of fixed infrastructure;
- and the control of physical access.
A good report distinguishes between the two.
Is periodic repetition the answer?
Not automatically. A standard quarterly or annual interval says little when it is unclear which risk it manages. A new examination is above all logical when the baseline situation changes, for example:
- after building or installation work;
- after changes to cabling or equipment;
- after uncontrolled access;
- after a concrete incident;
- when the threat picture has changed materially;
- ahead of a particularly sensitive event;
- or when sensitive conversations take place in the room routinely and periodic examination is part of risk management.
Repeat examination also becomes more valuable when an earlier examination produced a documented reference situation. It is then possible to establish what has changed since the previous measurement. Ultimately, structural security between two sweeps lies not in measuring more often but in access control, change management and discipline about what enters and leaves a room.
6. What will the report contain?
Before awarding the assignment, ask for a description of what the reporting looks like.
A usable technical report states at least:
- the threat profile applied;
- the scope of the examination;
- the rooms, installations and usage situations examined;
- the examination methods applied;
- relevant instrumentation and measurement conditions;
- the findings;
- what could be explained;
- which limitations applied during the examination;
- what was explicitly not examined;
- and what residual risk remains.
That last point is not a weakness of a report. It is a mark of quality. A report that does not state its own limits is hard to verify.
Board and technical readers
A technical examination usually has two kinds of reader. A director wants to know:
- what is going on?
- how serious is it?
- what needs to happen?
- and what uncertainty remains?
A technical specialist, auditor or other third party wants to be able to trace:
- what exactly was examined;
- how the examination was carried out;
- and what the conclusion is based on.
Good reporting serves both without abstracting away the technical substantiation. Ask therefore whether you may see an anonymised sample report or the reporting structure.
7. Who actually comes into your premises?
A technical examination gives an external party exceptional access. The examiners may see rooms, technical infrastructure, documents, security measures and usage patterns that are precisely what should stay out of third-party view.
Ask therefore:
- who carries out the examination in person;
- whether that is the same person who is substantively responsible for the report;
- whether subcontractors or hired staff are deployed;
- which screening is relevant and in place;
- which confidentiality and data security arrangements apply;
- and how your organisation’s identity and the existence of the assignment are protected.
ABRO and personnel screening
Where an examination takes place in an ABRO context, the required screening depends on the assignment, the role and the applicable protection level. The ABRO distinguishes among others between a VOG and a VGB; for a required VGB the framework stipulates that it must not be more than five years old. So do not only ask whether an examiner is “screened”. Ask which screening, for which role and in which context.
How GreyOps handles this
At GreyOps the substantive chain is deliberately short. Whoever carries out the examination analyses the findings and is responsible for the report. Measurements are not outsourced to operators who must later hand the examination situation over to someone who was not present.
That limits how many large sites we can examine simultaneously. The advantage is direct substantive responsibility: whoever signs a conclusion observed the conditions themselves and can explain the choices made.
We also publish no client names or logos and do not confirm to third parties whether an organisation is a client. A specific manner of presence on site, and how an examination is announced internally, can form part of the operational arrangements.
8. What happens if something is found?
This question should be answered before the examination. Removing a technical device immediately is not sensible in every situation. It can destroy context, traces or information that later prove relevant to an internal investigation, a criminal complaint, a civil dispute or an inquiry by a competent authority.
Discuss in advance therefore:
- who is informed when something is found;
- through which communication channel that happens;
- who decides whether the device is removed or left in place;
- how position, condition and time are recorded;
- who is given access to the find;
- and when a third party or competent authority is brought in.
Know the legal boundary
A technical sweep of a room is not the same as an investigation into a person. When an assignment shifts towards deliberately gathering and analysing facts about particular individuals, other statutory rules can apply, including those for private investigation agencies. Ask a provider how that boundary is maintained and when specialist or legally authorised third parties are brought in. Being technically able to demodulate or intercept communications does not automatically mean doing so is legally permitted. A professional provider should be able to explain which content it does and does not record, and on what basis.
9. What claims and certifications really say
In a market where quality is hard to read from the end result, brand names, logos, certificates and quality marks easily carry a lot of weight.
“ABRO-certified”
That formulation is incorrect. The ABRO stipulates that an ABRO declaration is not a certification. The declaration is issued in the context of a Special Assignment when the applicable ABRO requirements have been met. The ABRO also stipulates that a contractor may not publicly make known that it holds an ABRO declaration. A website advertising “ABRO certification” or publicly advertising possession of an ABRO declaration therefore warrants further questions.
So what does an ABRO declaration say?
An ABRO declaration concerns the contractor meeting the security requirements relevant to the Special Assignment. According to the ABRO, the NBIV examination does not concern the quality or security of the product or service the supplier delivers during the assignment.
And other certifications?
Always ask:
- Who issued the recognition?
- What exactly does it cover: the organisation, the management system, the examination method, the equipment or the individual examiner?
- Is the claim independently verifiable?
A certificate can be valuable. It just has to answer the question you are using it for.
10. Where GreyOps aims to make the technical difference
We do not limit technical counter-espionage examination to looking for active transmitters. Depending on the threat profile we consider several possible transfer and compromise paths: radio-frequency, conducted, physical, acoustic, optical and electromagnetic. Equipment that does not actively transmit during a measurement belongs in the examination model too. That approach follows from one principle: security should be assessed against what a relevant adversary can actually do, not against what is convenient to measure.
Our technical knowledge development is therefore also aimed at the higher capability segment. Publicly known examples of state technical surveillance show that devices do not always transmit continuously, do not always need a conventional power supply and are sometimes designed precisely to fall outside the most obvious detection path.
That does not mean every client has a state-level threat profile. It means we know the technical upper bound and can deliberately dimension the examination scope below it.
Read more in threat profiles and our collection of publicly known cases.
11. From finding to measure
A report is not a usable end product if nothing is done with it. We therefore translate technical findings into measures that fit the threat profile and what your organisation can sustain operationally. A simple measure is preferred where it achieves the same security objective as a complex one. Sometimes that means removing equipment or configuring it differently. Sometimes it is a matter of access or change management. Only where the risk gives cause can technical shielding or a specialist modification be appropriate. Where possible we also describe what result a measure has to achieve and how you can verify that result later.
12. Security awareness and technical security go hand in hand
Not every technical risk calls for more technology. Many vulnerabilities arise because equipment is added, installers are given access, a room is used differently from how it was designed, or staff do not recognise why an apparently harmless change is relevant. That is why, alongside examination, we also provide awareness sessions for boards, security teams and the custodians of sensitive rooms. The point is not another list of rules but understanding the mechanism behind them: how can information leave a room, which changes make that more likely, and which anomalies deserve attention?
Awareness does not replace a technical or procedural security measure. It does help to recognise changes during the period when no examiner is standing in the room.
What we do not promise
No “clean declaration”
We do not declare a room absolutely free of eavesdropping or observation devices. An examination records what was established within an agreed scope, at a given moment and with the chosen examination methods. Suggesting absolute certainty where it cannot be technically substantiated does not make a conclusion stronger but weaker.
No standard subscription because “more often is better”
We do not advise a fixed repeat frequency unrelated to the threat picture. A new examination has to answer a relevant question. If the room, the access, the technical set-up or the threat changes, re-examination can be worthwhile. If nothing has changed and periodic examination has not been substantiated as a measure, measuring more often is not self-evidently better.
No hardware sales following our own finding
We sell no shielding or detection equipment and have no supplier interest in the measure that follows from the examination.
No examination because it sounds exciting
Where an extensive sweep is not proportionate for your situation, we say so. Sometimes better access control, change management or adjusting existing equipment is the more sensible investment.
Red flags when comparing providers
Be extra critical when a provider:
- suggests certainty about the outcome before the examination;
- declares a room “clean” afterwards without further qualification;
- records no threat profile or scope in advance;
- will not state what falls outside the scope;
- speaks only about frequency ranges and equipment brands;
- has no convincing answer on devices that do not transmit;
- will not discuss the substantive examination method beforehand;
- has no clear policy for measurement data and client information;
- carries out the measurement with people other than those expected;
- delivers a report without limitations or residual risk;
- earns commercially from both the diagnosis and the prescribed solution without stating that interest;
- speaks of “ABRO certification”;
- or publicly advertises possession of an ABRO declaration.
No single point on its own proves that a provider does poor work. Several points together are reason to keep asking.
Ask GreyOps these questions too
This page is not meant as a questionnaire for assessing competitors only. Feel free to put these questions to us. Ask about the examination scope, the limitations of our methods, our data environment, the instrumentation, the reporting structure, what we do not examine and why we do or do not propose a particular examination line in your situation. Some of those answers may lead you to need less examination than you initially thought. We regard that as part of independent advice.
One final check question
If you ask a provider only one question, let it be this: “Which conclusion can you substantiate after your examination — and which one emphatically not?”
The answer to that often says more about the quality of a technical examination than the list of equipment it is carried out with.
Sources
- Ministry of Justice and Security. Algemene Beveiligingseisen voor Rijksoverheidsopdrachten 2026 (ABRO). The Hague, 2026. For the ABRO declaration and the NBIV examination, requirement 2.1.2 on the VGB and requirement 3.3.31 on the electronic security survey.
- ISO/IEC. ISO/IEC 17020:2012, Conformity assessment: Requirements for the operation of various types of bodies performing inspection. Geneva, 2012.
- Wet particuliere beveiligingsorganisaties en recherchebureaus (Dutch Private Security Organisations and Investigation Agencies Act). Article 1 (definitions) and article 2 (licensing requirement). Accessed 18 August 2026.
Frequently asked questions
- What is the difference between an EVO and a TSCM sweep?
-
TSCM stands for technical surveillance counter-measures and is used internationally for technical examination of covert surveillance and eavesdropping risks. The ABRO 2026 uses the specific term Elektronisch Veiligheidsonderzoek (EVO) for an investigation into the potential presence of unwanted equipment in a compartment. A TSCM sweep and an EVO can share technical elements but are not simply the same formal service. In an ABRO process, the applicable requirements and the coordination with the NBIV are decisive.
- When does the ABRO require an EVO?
-
Requirement 3.3.31 of the ABRO 2026 applies to TBB 2 and TBB 1. It ties the EVO and the sound attenuation measurement to a compartment being taken into use and to the addition or modification of resources, in coordination with the NBIV. At lower TBB levels a technical examination does not follow from this specific requirement, but it can of course follow from your own threat picture or risk management.
- Is “ABRO-certified” a recognised qualification?
-
No. The ABRO 2026 explicitly states that the ABRO declaration is not a certification. Nor may a contractor publicly make known that it holds an ABRO declaration.
- How do I know whether a sweep was good if nothing was found?
-
Not by looking at the nil finding. You assess quality on the basis of the threat profile, the scope recorded in advance, the examination lines carried out, the time spent, the criteria used and the transparency of the report about limitations and residual risk.
- Can I ask for client references?
-
You can, but with confidential assignments a provider may have good reasons not to name clients. An anonymised sample report, a reporting structure or insight into the methodology often says more about the actual working method.
- What does a TSCM sweep or technical security examination cost?
-
That depends above all on the scope: the number and type of rooms, the threat profile, the examination lines, the accessibility of infrastructure, the time available and the reporting required. Compare quotations therefore not only on total price but on what is actually examined within that price.
- What happens if something is found?
-
This should be agreed beforehand. Depending on the situation, immediate removal may be undesirable — for instance where traces or context need to be preserved. Record in advance who is informed, who decides on next steps and when specialist or authorised third parties are involved.
Read more about our EVO/TSCM sweeps.