Cybersecurity

Protecting Connected Products Through Structured Security Testing

Get in touch with our experts

Building security into connected products from the start

The increasing interconnectedness of technical products presents companies with new cybersecurity challenges. With the Radio Equipment Directive (RED) and the Cyber ​​Resilience Act (CRA), the European Union has created two key regulatory frameworks that fundamentally change the security requirements for digital products.

What can we check?

CRA Requirements & Standards

Assessment against applicable Cyber Resilience Act (CRA) requirements and harmonised standards

PROFINET Conformance Testing

Verification of interoperability and compliance with PROFINET specifications

Weakness & Vulnerability

Analysis Identification of security weaknesses within your devices and systems

Radio Products under the RED

Cybersecurity assessment under EN 18031-x for radio equipment placed on the EU market

IoT Device Cybersecurity

Evaluation in accordance with EN 303 645 for connected consumer devices

Our additional services

Cooperation

on site in our laboratory

Worldwide Approval

international Type Approval
See more

Seminars & Training

Deepen your understanding of complex regulatory and technical requirements
See more

Advisory

Specialist guidance to strengthen expertise and support informed decisions
See more

FAQ – Cybersecurity

Why is cybersecurity important?

Cybersecurity is not a technical detail, but a decisive value add for marketable, future-proof products. By implementing a consistent cybersecurity strategy, you reduce risks and build trust in the market. In addition, cybersecurity is increasingly becoming a prerequisite for market access and is therefore a key factor for sustainable business success in a connected world.

Is my product affected by regulatory cybersecurity requirements?

The European Union is a global leader in regulating cybersecurity requirements for products. Currently, these requirements are defined by the Radio Equipment Directive (RED) and the upcoming Cyber Resilience Act (CRA). If your product includes a radio interface, it falls under the RED and must therefore comply with its cybersecurity requirements.

As of December 11, 2027, the CRA will be fully applicable, and from that point onwards all products with digital elements must meet its cybersecurity requirements. The obligation for manufacturers to report vulnerabilities in their products to authorities will already come into force on September 11, 2026.

Which radio products fall under the RED?

All products with a radio interface must comply with the requirements of the RED if they are placed on the EU market after August 1, 2025. It does not matter which radio technology is used or whether a product is designed solely as a receiver. Examples include GNSS, NFC, Bluetooth, Wi-Fi, LoRaWAN, etc.

Which products fall under the CRA (Cyber Resilience Act)?

All products with digital elements are covered, including both hardware and software products. If a cloud connection is part of the product (e.g., control of a smart refrigerator), this remote data processing is also considered part of the product. This includes, for example, mobile apps, firmware, operating systems, drivers, sensors, consumer electronics, IoT devices, microprocessors, routers, switches, etc.

Is my product also subject to RED and CRA requirements if I source the relevant components from another manufacturer and merely integrate them into my product?

As the manufacturer, you are responsible and liable for the entire product, including all integrated components. Even if you incorporate hardware or software components from third-party manufacturers, it is ultimately your responsibility to ensure how these components perform and behave within your product.

How can Testlab help?

We support you throughout the qualification process, test your product in our laboratory, certify your device where required, and can additionally assist with international approval. We also offer training sessions, seminars, and customer-specific workshops to ensure you stay up to date and well informed.

During the qualification phase, we help you understand the complex requirements and develop a test plan tailored to your products.

In our ISO/IEC 17025 accredited test laboratory, we test your products in accordance with EN 18031-1, EN 18031-2, EN 18031-3, and ETSI EN 303 645 in combination with ETSI TS 103 701.

As a Notified Body under the RED, we can certify your products following successful testing.

If you plan to obtain international approvals, our International Type Approval (ITA) team will be pleased to support you with project management and global market access.

We're always here to listen.

Our experts are happy to assist you. Let’s work together to determine the next steps.

Tobias Vogler MBA

Tobias Vogler MBA

Section Manager Cyber Security

Planning a project and looking for expertise? Let's talk about it.

Request a quote