Your situation

Cybersecurity tests for digital products

You need cybersecurity tests for your digital product – for the CRA, RED, IEC 62443 or your own quality assurance? We put together the right tests and document the technical results for your evidence.

Free of charge and without obligation.

  • BSI-recognised BSZ evaluation facility
  • Co-author of the IEC 62443-4-2 evaluation scheme
  • Contribution to the Industrial Firewall Profile
A navigation instrument being explained in a joint discussion
Cybersecurity tests for digital products, down to the smallest detail.

Your situation

Your product has to comply with the CRA, RED or IEC 62443, and you need reliable security tests?

You develop connected, software-based products, perhaps with radio modules, integrate control components into plants or operate systems whose security you have to demonstrate to third parties. The Cyber Resilience Act (CRA) requires manufacturers to systematically test all security requirements, analyse the attack surface and maintain a software bill of materials (SBOM). Since 1 August 2025, the cybersecurity requirements of Article 3(3)(d)–(f) of the Radio Equipment Directive (RED) 2014/53/EU have also applied to certain radio equipment.

Even without a regulatory reason, some vulnerabilities remain undetected in agile development despite all due care. An independent security test by an external testing laboratory can uncover them before the next release.

As a BSI-recognised evaluation facility and testing laboratory accredited by DAkkS (German national accreditation body) to ISO/IEC 17025, we test apps, software, connected devices and OT components – as a one-off test, as continuous support or while you build up your internal testing capabilities. You can find the regulatory classification under CRA consulting and IEC 62443. Which formal evidence fits your product, we clarify in our consulting for product manufacturers.

Services & results

Security tests by product and evidence requirement

Your digital product gets the cybersecurity tests your goal requires: Cyber Resilience Act, Radio Equipment Directive (RED), IEC 62443 or your own quality assurance. You receive the vulnerabilities found in product pentests and documented technical results for your evidence, from a BSI-recognised evaluation facility and testing laboratory accredited by DAkkS to ISO/IEC 17025.

You do not start from scratch: our modular test catalogues allow a structured start and the swift development of a test strategy. The tests cover classic IT protocols, industrial OT components and software applications, and also work remotely via secured access and documented procedures. Alongside independent testing, we offer methodical knowledge transfer for in-house security testing teams.

CRA: getting started and gap analysis

For the CRA, we work with a modular project approach. The standard packages:

  • CRA introductory workshop
  • Portfolio review by criticality
  • Gap analysis of requirement fulfilment
  • Optional: implementation support

Your test strategy

A test plan tailored to the product, its criticality and existing tests.

Security tests and product pentests according to CRA requirements

In addition to the standard packages, we test your products according to CRA requirements and identify vulnerabilities with product pentests – as part of your CRA compliance or as stand-alone security evidence.

Industrial components according to IEC 62443

For OT components, assets worth protecting and possible attack vectors are often not clearly identified. We therefore start with a threat analysis and define the security objectives with you. We then test along the four categories of security verification and validation (SVV):

  • Security requirements testing
  • Threat mitigation testing
  • Vulnerability testing
  • Penetration testing

Basis for product certification

These tests provide the basis for a product certification according to IEC 62443-4-2. Alternatively, we test the component with a standardised test package in our laboratory.

Products with radio modules according to RED

Manufacturers of connected devices with radio components must demonstrate that their products comply with the requirements of Article 3(3)(d)–(f) of the RED.

  • Test case specification: development of individual test strategies
  • Security tests: technical testing of radio modules, interfaces and communication paths for vulnerabilities and security flaws

Quality assurance and internal testing capabilities

Whether app, software or connected device: we test your digital product independently before it goes into the next release. If you already have a strong test team but no focus on cybersecurity yet, we support you in building internal security testing capabilities.

  • Design and wording of test cases
  • Definition of suitable test methods
  • Setting up realistic test environments
  • Optional: full integration into your existing team

Our expertise

Our evaluation facility is recognised by the BSI and accredited by DAkkS (German national accreditation body) to ISO/IEC 17025. As a BSZ evaluation facility of the BSI, we are particularly qualified for black-box product evaluations; our penetration testing team has been certified by the BSI as an IT security service provider since 2013.

We help shape the standards we test against: we drove the TeleTrusT evaluation scheme for IEC 62443-4-2 forward as coordinator, the head of our evaluation facility played a key role in driving the standardisation project IEC 62443-6-2 on evaluation methodology forward at the IEC as project leader, and our colleague Luise Werner contributed to a TeleTrusT profile proposal for an industrial firewall based on IEC 62443.

We have been evaluating IT products as a BSI-recognised evaluation facility since 1992.

Getting started

Looking at product architecture and existing test coverage

Present your product and testing needs

In the initial consultation we discuss the target market, product, operational environment and required evidence. Existing tests and certifications help to narrow down what is needed.

Agreeing modules and execution

We define which tests are needed, which test environment is suitable and how we work with your development team. Where useful, we start with a gap analysis.

Put together product tests
Several hands working with compass and dividers between sticky notes on a map
Test coverage that fits your product architecture.

A test report is not automatically a certification

The test scope and the applicable requirements are agreed for the specific product. Individual test results do not automatically replace a certification or a complete conformity assessment.

Questions about cybersecurity tests for digital products

Can existing internal product tests be reused?

Existing tests, development documents and certifications are taken into account in the planning. We look at which security properties have already been examined and where independent tests should complement them. This aligns the test strategy with the actual testing needs.

Which types of product can be tested for cybersecurity?

The service is aimed, among others, at manufacturers of software, apps, connected devices and industrial components as well as integrators and operators. Architecture, interfaces and operational environment determine the right combination of technical tests.

Can cybersecurity tests support the evidence for the CRA or RED?

Yes, the tests can provide technical results on the requirements agreed in each case. Which test basis applies is clarified for your specific product. However, individual test results do not automatically replace the complete conformity assessment procedure.

Can product tests also be carried out remotely?

Tests can be carried out remotely via suitable secured access and defined test methods. Whether this is sufficient for the product and the required test activities is decided based on the test environment.

How can the timing of the cooperation be organised?

We adapt to your processes, from start-up to large corporation, and offer our services within flexible time budgets – for a one-off test as well as for continuous support.

How can we support you with security tests for your product?