Our rating methodology

Transparent, source-based and disclosed: how the category and overall scores of the 16 tested providers come about.

Rating categories & weighting

Each provider is rated in 6 categories on a scale from 0 to 100. The categories are weighted differently – criteria that are decisive for German B2B use (data protection above all) count the most.

GDPR & Data Security 25%

Legally compliant processing of personal data under EU law, together with technical and organisational safeguards. For German and European companies the decisive selection criterion, which is why this category carries the highest weighting.

Measured: Server location (Germany / EU), availability of a data processing agreement (AVV/DPA), recognised certifications (ISO 27001, SOC 2), as well as verifiable information on encryption, subprocessors and data sharing. Measured from the fields dataResidency.* (serverLocationGermany, serverLocationEU, avv, iso27001, soc2, euSubprocessors).

Scale: 90-100: server location DE/EU + AVV + ISO 27001 and/or SOC 2, transparent documentation. 70-89: EU hosting + AVV, at least one certification. 50-69: EU hosting + AVV, no certification. 25-49: hosting outside the EU or AVV only on request. 0-24: no AVV, non-EU hosting, non-transparent. Fields that are not substantiated (null) lower the score, since the burden of proof lies with the provider.

Enterprise Integration (SSO/SCIM/MDM/API) 20%

Ability to connect to existing corporate IT. Decisive for whether the tool fits into identity, device and CRM landscapes without becoming an isolated solution.

Measured: Single Sign-On (SAML, OIDC), automated user provisioning (SCIM), Managed App Configuration (app-side preconfiguration via MDM; plain distribution through Microsoft Intune or Jamf is generically possible for any store app and therefore not a provider-specific feature), a public REST API and the number/relevance of native CRM integrations. Measured from features.sso.*, features.mdm.*, features.api and features.crmIntegrations[].

Scale: 90-100: SAML+OIDC, SCIM, MDM (Intune & Jamf), open API, several CRM integrations. 70-89: SSO + SCIM or MDM + API available. 50-69: SSO OR API available, the rest patchy. 25-49: only isolated integrations. 0-24: no enterprise interfaces. Assessed by breadth and verifiability; unsubstantiated (null) fields count as not available.

Team & Admin Management 17%

Ability to manage cards for many employees centrally, consistently and on a role-based basis. Critical in practice for roll-outs from medium team size upwards.

Measured: Central admin console, bulk creation/management of users (bulk provisioning), central branding/template management, role and permission concept as well as central email signature management. Measured from features.teamAdminConsole, features.bulkProvisioning, features.customBranding and features.emailSignatureManagement.

Scale: 90-100: fully-fledged admin console, bulk provisioning, central branding and signature management, granular roles. 70-89: admin console + bulk + branding. 50-69: admin console available, bulk management limited. 25-49: only rudimentary team functions. 0-24: pure single-user product without admin.

Feature Scope 15%

Scope and maturity of the card-related core functions beyond pure enterprise connectivity. Determines the practical benefit in day-to-day sales and networking.

Measured: NFC cards, QR code, Apple/Google Wallet, lead capture, analytics/reporting as well as customisability (custom branding). Measured from features.nfcCard, features.qrCode, features.appleWallet, features.googleWallet, features.leadCapture, features.analytics, features.customBranding.

Scale: 90-100: all core channels (NFC, QR, Apple & Google Wallet) plus lead capture and analytics. 70-89: most core functions, minor gaps. 50-69: basic functions (QR + one wallet) available. 25-49: limited feature scope. 0-24: only a basic card without additional functions.

User Reviews 12%

Aggregated, externally verifiable customer satisfaction as a corrective to the editorial feature assessment. Deliberately weighted lower, since review volume and origin vary considerably from provider to provider.

Measured: Average ratings on independent B2B platforms (G2, Capterra, Trustpilot, Google, OMR). When several platform ratings are available, we first form the simple arithmetic mean of the available values on the 0-5 scale; missing platforms do not count as zero but are left out. This average is then normalised to 0-100 and adjusted for review volume (number) and recency. Measured from ratings.g2, ratings.capterra, ratings.trustpilot, ratings.google, ratings.omr.

Scale: 90-100: consistently high ratings (approx. 4.6-5.0/5) with a solid volume. 70-89: solid 4.0-4.5/5. 50-69: mixed (3.0-3.9/5) or thin data. 25-49: below average. 0-24: predominantly negative. If ratings are missing entirely, the category is factored in neutrally/marginally and the weights are normalised across the substantiated categories.

Support & Language 11%

Availability, response commitments and German-language support. Relevant for operation in German organisations and for rollout questions.

Measured: Support channels (email, chat, phone), availability of German-language support, documented SLA/response times as well as the scope of onboarding/help resources. Measured from support.channels[], support.germanSupport and support.sla.

Scale: 90-100: several channels including phone, German-language support, committed SLA. 70-89: German-language support across at least two channels. 50-69: multilingual support without dedicated German or without an SLA. 25-49: only email/ticket, no German. 0-24: barely documented support.

Calculating the overall score

Overall score = Σ (category score × weight) / Σ (weights). With full data: Overall = 0.25·GDPR + 0.20·Enterprise Integration + 0.17·Team/Admin + 0.15·Feature Scope + 0.11·Support & Language + 0.12·User Reviews. The weights add up to 100%. If data for a category is missing for a provider (e.g. no external user reviews), that category is removed from the calculation and the remaining weights are proportionally renormalised to 100%, so that providers with incomplete data that is honestly marked as 'unknown' are not penalised twice. The result is commercially rounded to a whole number.

Scale

0-100 points per category (0 = criterion not met / no public evidence, 100 = fully and verifiably met). The overall score is also reported on the 0-100 scale.