Your strategic partner in testing and certification

Complete our quick form

GET A QUOTE

Why are IoT security evaluation services Important for market access?

IoT cybersecurity has become a key enabler for global market access, as manufacturers must address a growing set of regulatory requirements, technical standards and certification schemes that vary across countries, sectors and markets.
Applus+ Laboratories supports IoT manufacturers with independent, product-focused cybersecurity evaluations, helping them meet applicable requirements today while preparing for evolving regulatory frameworks worldwide.

IoT cybersecurity requirement mapping for market access

Depending on the target markets and product category, IoT manufacturers may need to address a combination of regulatory requirements and voluntary cybersecurity schemes, which can include, for example, Common Criteria, the EU Cyber Resilience Act (CRA), the Radio Equipment Directive (RED), IEC 62443, ETSI EN 303 645, or emerging initiatives such as the U.S. Cyber Trust Mark.

Applus+ Laboratories supports this diversity through a requirements-mapping approach, identifying common technical foundations and enabling the reuse of cybersecurity assessments and evidence across frameworks, rather than treating each requirement in isolation.

IoT cybersecurity testing and certification at all levels

An IoT solution is built from multiple layers, ranging from hardware and software components to end devices and, in some cases, platforms or backend services.

Cybersecurity expectations differ at each level, as do the applicable certification schemes and regulatory frameworks.

Applus+ Laboratories provides cybersecurity evaluation services across all IoT levels, supporting manufacturers of components, devices and industrial or consumer IoT products.

IoT component cybersecurity evaluations

IoT devices rely on hardware and software components that implement critical security functions, such as cryptographic operations, secure storage, identity management or secure boot.

Applus+ Laboratories provides independent cybersecurity evaluations of IoT components, supporting semiconductor vendors, component suppliers and technology providers.

Applicable schemes at component level include:

These evaluations provide trusted security building blocks, which are often reused to support subsequent device-level certification and regulatory compliance activities.

Customised, independent evaluations are also available when formal certification is not required, including design and architecture review, vulnerability analysis, source code review and white/grey/black-box testing.

IoT device cybersecurity evaluations

At device level, cybersecurity evaluations address how IoT products implement security mechanisms in line with both certification schemes and regulatory requirements, depending on the target market and use case.

Applus+ Laboratories supports manufacturers of consumer and industrial IoT devices through regulation-driven and scheme-based evaluations, including:

Certification schemes (when applicable)

  • PSA Certified (device level)
  • Common Criteria
  • SESIP
  • IEC 62443-4 for industrial IoT devices

Regulatory and market frameworks

Evaluations are tailored to the device's function, risk profile and deployment context, and are always performed independently from product development activities.

Technical scope of IoT device cybersecurity evaluations

IoT device cybersecurity evaluations performed by Applus+ Laboratories cover the core technical security domains required by regulations, certification schemes and recognised international baselines.

  • Data protection and asset security
  • Interface and access security
  • Secure update mechanisms
  • Secure boot and lifecycle security

These technical evaluations support compliance with RED, CRA, IEC 62443-4, PSA Certified, Common Criteria, SESIP, ETSI EN 303 645 and NIST IR 8259, depending on the applicable framework.

Methodologies and good-practice references

  • ETSI EN 303 645 (Consumer IoT security baseline)
  • GSMA IoT Security Guidelines and Assessment
  • OWASP IoT Top 10
  • Code of Practice for Consumer IoT Security
  • ENISA Baseline Security Recommendations for IoT

These references are used to complement regulatory and certification requirements and to support risk-based, use-case-driven evaluations.

IoT system and platform cybersecurity evaluations

The security of an IoT solution goes beyond protecting individual devices. Once deployed and interconnected, new system-level threats can emerge, and supply-chain trust becomes a critical factor.

Applus+ Laboratories provides system and platform-level cybersecurity evaluations when required, for example for industrial IoT systems, platforms, gateways or backend services.

Typical activities include:

  • Assessment of system-level risks and threats
  • Supply-chain cybersecurity assessments
  • Security audits of development and production processes
  • Evaluation of cloud, backend, fog or remote management layers and their interfaces
  • Security testing of solutions that do not hold a recognised cybersecurity certificate

These evaluations are scoped to specific products or systems and aligned with applicable regulatory or industry frameworks.

IoT Systems Evaluation

Why choose Applus+ Laboratories for IoT cybersecurity solutions

Applus+ Laboratories combines accredited cybersecurity testing capabilities, recognised certification expertise and extensive experience supporting manufacturers across components, devices and complete IoT systems.

GET A QUOTE

Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.

Cookie settings panel