Your situation

IT security consulting for product manufacturers

Your customers ask for independent evidence of your product's IT security, but the right evaluation procedure is not yet clear? We support you from classifying the requirements to preparing the chosen evidence.

Free of charge and without obligation.

  • BSI-recognised Common Criteria evaluation facility
  • BSI-recognised BSZ evaluation facility
  • Coordinator of the TeleTrusT IEC 62443-4-2 evaluation scheme
An open brass compass lying in a hand in front of a world map and sticky notes
Security consulting for product manufacturers: the right course to the required evidence.

Your situation

Your customer requires a security evaluation of your product – but which one?

Manufacturers of IT products are frequently asked by their customers for a security evaluation. Which evaluation is actually meant often remains open: the entire product, central or individual security properties, the development, the support process or even the entire company?

The answer determines the approach, effort, cost and significance. A certification according to Common Criteria, an Accelerated Security Certification (BSZ), an approval for classified information, a product attestation or a penetration test provide different evidence. If the Cyber Resilience Act is the issue, the path usually leads through CRA consulting; for secure development there are IEC 62443 and BSI TR-03185, for individual security tests the cybersecurity tests for digital products. Certain product types have their own procedures: the IT Security Label, TR-03161 for healthcare applications and TR-03174 for financial applications, 5G certification under NESAS and the security assessment for gaming machines.

We help you find and prepare the right evaluation. secuvera has been active in IT security since 1988; our evaluation facility was recognised by the BSI in 1992 and is the longest-serving evaluation facility in Germany. Our white paper “Security evaluations for product manufacturers” (in German) gives an overview of all options.

Paths to evidence

Which evidence fits your product?

As a rule, customers are interested in an independent evaluation of the security features. We offer manufacturers these options – as an evaluation facility or in preparation.

Support in the development process

  • Training on fundamental IT security mechanisms
  • Documentation of existing security measures
  • Assessment of mechanisms for effectiveness and with formal methods
  • Assessment of algorithms for conformity and known vulnerabilities
  • Awareness-raising for development departments

Services & results

From an unclear evaluation request to the right evidence

You find the security evidence that fits your product: Common Criteria, Accelerated Security Certification (BSZ), approval for classified information (VS approval), product attestation or penetration test. In a free workshop you see the options side by side in terms of approach, effort, cost, significance and benefit, and you prepare the chosen evidence with an evaluation facility recognised by the BSI since 1992.

Product Security evaluates products; our security consulting looks at the organisation. We first clarify what statement your customer needs and then prepare the right procedure with you – from the free workshop to attestation or certification.

Free workshop: comparing the paths to evidence

In a free technical workshop we compare the possible forms of evidence for your product – for example BSI certificates according to Common Criteria, TÜV NORD certificates according to IEC 62443, penetration tests, the Accelerated Security Certification (BSZ) of the BSI or attestations according to standards. We recommend reading our white paper beforehand.

  • Approach
  • Effort
  • Cost
  • Significance
  • Benefit

A well-founded choice of evaluation procedure

A clearly delimited evaluation object and a well-founded choice of the evidence procedure.

Kickstarter workshop once the goal is set

Once the certification goal is set – for example, your customers require a Common Criteria certification – we spend one to two days together. We analyse all available information, explain the relationships and dependencies of the certification and start working on project results straight away. The aim is to considerably shorten the preparation time until the certification starts.

Supporting the development process

Our consulting services for your development process help you successfully complete a planned product certification:

  • Training on fundamental IT security mechanisms
  • Support in documenting existing security measures
  • Assessment of mechanisms for effectiveness
  • Assessment of mechanisms with formal methods
  • Assessment of algorithms for conformity
  • Assessment of algorithms for known vulnerabilities in design and implementation
  • Awareness-raising for development departments

Product attestation as efficient evidence

A Common Criteria certification means high financial and staffing effort, especially for medium-sized manufacturers. With the product attestation we assess a product on the basis of established methods – in two or four phases, depending on the evaluation depth:

  • Workshop to define the product properties to be evaluated (with increased evaluation depth)
  • Threat analysis following the Common Criteria approach with a defined attacker type (with increased evaluation depth)
  • Vulnerability analysis with penetration tests and further test methods, e.g. selective source code analysis
  • Handover of attestation and evaluation report

Attestation and evaluation report

A short-form attestation and a detailed evaluation report covering all project steps and notes for future product improvements – which also serves as groundwork for a later certification.

Coordinating evaluation and certification

Together we clarify which independent evaluation fits the product, the customer requirement and the intended use, and prepare the chosen procedure. In certifications, an independent body such as the BSI oversees the procedure; the evaluation is carried out by the evaluation facility. We separate the roles of consulting and evaluation according to the rules of the respective procedure.

Our expertise

secuvera has had expertise in IT security since 1988. Our evaluation facility was recognised by the BSI in 1992 as an evaluation facility for “trusted systems”, works according to ISO/IEC 17025 and is recognised for evaluations according to Common Criteria and ITSEC. Our consultants are trained by the BSI as Common Criteria/ITSEC evaluators and bring in-depth technical expertise.

This work has produced numerous evaluations, including many of the genugate and genuscreen products by genua and the evaluation in preparation for the approval of SiMKo3 (secure mobile communication) for Deutsche Telekom smartphones and tablets. Today we offer the BSI certifications according to TR-03163: Common Criteria, BSZ and NESAS CCS-GI.

The head of our evaluation facility, Sebastian Fritsch, passes on this knowledge, among other things in the heise Events training course “Rechtskonform: IT-Produkte prüfen und zertifizieren” (in German) on evaluation methods, certification procedures such as CC, BSZ and IEC 62443 and the ETSI EN 303 645 assessment standard.

Getting started

Looking at your customer's specific demand for evidence

Bring your customer requirements

Your customer's specific requirement, a product description , information on the intended operational environment and existing security documentation are helpful. Clarifying evidence requirements early helps to plan the necessary contributions during development. Even a still unspecific request for security evidence can be classified in the preliminary meeting.

Clarify the evaluation object and responsibilities

We distinguish between the product, individual security functions, the development process and company-wide requirements. We then discuss documents, roles and the right next step.

Classify your product evidence
Dividers fixing a position on the world map
Understanding customer requirements and choosing the right evidence.

Separating consulting, evaluation and decision

Consulting, independent evaluation and the certification decision are separated according to the chosen procedure and agreed with clear responsibilities.

Questions about security consulting for product manufacturers

What should you do if the customer only asks for a “security evaluation”?

First it has to be clarified what statement the customer needs. A technical test of individual security functions, the assessment of a development process and a formal product certification are not interchangeable. We classify the requirement based on the product and the operational environment.

Which evidence procedures are suitable for our IT product?

Depending on the requirement, Common Criteria, BSZ, a product approval, an attestation or a penetration test may be relevant. The choice depends on what is to be demonstrated and which procedure the customer or the responsible authority accepts.

Can consulting be combined with an independent product evaluation?

Whether and how support and evaluation can be agreed depends on the independence rules of the chosen procedure. The roles are defined in advance. A later certification decision is a separate step in addition.

What is the difference between a product attestation and a certificate?

An attestation is the statement of an evaluation facility without an independent certification body and is usually less effort than a certification. We are convinced that a certificate should only be issued by an accredited body independent of the evaluation – for Common Criteria, for example, by the BSI. This is why we issue an attestation with a detailed evaluation report.

What does a product attestation cost?

The cost depends mainly on the number and complexity of the security functions to be attested. For a specific proposal, we define the scope in our free workshop.

How can we support you with security evidence for your products?