Product cybersecurity evaluation 

From cybersecurity testing to certification, we help manufacturers meet regulatory requirements and bring secure products to global markets.

250+ cybersecurity experts

We are a leading global supplier in cybersecurity evaluation, cryptography and pentesting for more than 30 cyber schemes across multiple industries and products.

A network of cybersecurity labs

Europe: Barcelona, Madrid, Granada
North America: Ottawa, Vancouver, Baltimore
Asia-Pacific: Shanghai, Seoul, Canberra

A partner for cyber compliance

Combining regional teams and accredited labs, we help vendors access global markets, maximizing reuse of evaluation activities to accelerate certification.

 

 

Cybersecurity certification & market access

Achieve trusted cybersecurity certification and seamless market access through high-assurance evaluation schemes recognized worldwide.

Cybersecurity certification

Common Criteria – Accredited laboratory for CC evaluations, by national schemes in USA, Canada, Spain, the Netherlands and Australia.

EUCC – Accredited lab for substantial and high assurance, and Certification Body for Substantial assurance level.

LINCE  for medium assurance

CICLON – for cloud‑native products

Cryptographic certification

FIPS 140‑3  – Accredited laboratories for cryptographic validation schemes with operational capabilities in the United States, Canada and Australia.

ISO 19790 - Accredited lab to evaluate the international standard on cryptographic modules

MEMeC – cryptographic evaluation methodology

 

Cybersecurity evaluations across industries

We evaluate products against more than 30 cybersecurity standards and certification schemes, supporting multiple industries with security assurance and market access requirements.

Medical devices

Medical Devices Cybersecurity

Cybersecurity assessments aligned with medical device lifecycle.

 

  • FDA Cybersecurity
  • MDR Cybersecurity
  • Pentesting for Medical Devices
  • IEEE 2621 for Connected Medical Devices
Aerospace Defense

Aerospace, Defense & National Security

Security evaluations for sensitive and classified products.

 

  • NATO's NIAPC Catalogue
  • EU LACP Approved Products List
  • Spanish CPSTIC Catalogue
  • Cryptographic Evaluations
  • Cloud-based Product Evaluations
 

Wide experience evaluating secure ICT products

We evaluate a broad range of secure ICT products, components and digital solutions, supporting manufacturers with cybersecurity, cryptographic and security assurance requirements across multiple technologies.

Smart Card & SE

  • Smart Cards
  • Secure Elements
  • Systems on Chip (SoCs)
  • Passive Wearables
  • Development and Production Sites

Hardware Security Boxes

  • Payment Terminals
  • Hardware Security Modules (HSM)
  • Secure Gateways
  • Tachographs
  • Drones

Software

  • Cloud Services - SaaS
  • Remote Biometric Identification Systems
  • Software Solutions such as PAM, IDS, IPS, CASB, SIEM, EDR & EPP
  • Windows, iOS and Linux based OS

Network & Telco Solutions

  • Routers, modems, switches, access points, load balancers, firewalls, VPN, Diodes, WAF, etc.
  • 5G infrastructure, eUICC (eSIM)

Mobile

  • Android / iOS
  • TEE
  • Mobile Applications including Comm Apps
  • Payment Apps, SDK, Wallets and Wearables
 

Involved in the definition of the future of cybersecurity

Our experts are members of key cybersecurity working groups and organizations, actively contributing to the definition of new certification schemes and evaluation methodologies.

Working Groups & Organizations

  • ENISA EUCC WG
  • ENISA 5G WG
  • SCCG members
  • CCUF management committee members
  • ICCC program committee members

Creators of cybersecurity methodologies and schemes

  • Industrial cybersecurity scheme definition for the European Commission
  • Co-creators of the Spanish LINCE methodology
  • Co-creators of cryptographic methodologies for the Spanish National Cryptographic Center

Automation tools

We have automated our laboratories to improve efficiency and accelerate certification projects at different levels.

Tools for vendors

  • CCGen
  • FIPS Portal

Tools for labs

  • CCEval
  • LinceEval
  • Greenlight

Tools for certification bodies

  • CCCAB
 

Pentesting expertise

Comprehensive expertise covering hardware, software, communications and cryptographic security, addressing the full attack surface of connected products.

Hardware Security

State-of-the-art attacks and ad hoc tools made by lab experts. Fault injection, Side Channel, Reverse Engineering

Software Security

Strong background in SW attacks, including web, fuzzing, embedded systems, secure boot, TEE and Cloud Security

Communications Security

Network Scanning, Eavesdropping, Protocol Fuzzing, Brute Forcing, DDoS, Man-in-the-Middle, Replay Attacks

Cryptographic Expertise

Conformance validation of cryptographic implementations, White box crypto, crypto pitfalls

Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.

Cookie settings panel