Cybersecurity Testing
BTL provides cybersecurity regulatory assessment, product security testing, and test report services for connected and digital products. Services cover the EU RED EN 18031 series, Cyber Resilience Act (CRA), UK PSTI, U.S. Cyber Trust Mark, Japan JC-STAR, Singapore CLS, and Australian smart device security requirements. Based on product requirements, BTL can also perform penetration testing, fuzz testing, vulnerability scanning, and source code scanning.

Before connected products enter different markets, applicable cybersecurity regulations, standards, labeling schemes, and conformity assessment requirements must be identified based on product type, communication interfaces, data processing methods, and target markets.
Based on product functions and target markets, BTL provides regulatory applicability analysis, test planning, product security testing, and test reports to support subsequent market access and certification applications.
Identifies applicable cybersecurity requirements, testing scope, and areas requiring improvement based on product functions, target markets, and applicable standards.
Simulates attacks against product interfaces, services, and communication functions to evaluate the product's ability to withstand common cybersecurity threats.
Inputs abnormal, random, or unexpected data into product interfaces or communication protocols to identify crashes, improper error handling, or security vulnerabilities.
Detects known vulnerabilities and insecure configurations in product systems, services, software packages, and exposed interfaces.
Identifies security flaws, insecure functions, sensitive information, and common software vulnerabilities in source code.
Summarizes the testing scope, test methods, findings, and results for use in subsequent compliance assessments and certification applications.
Applicable to relevant wireless equipment placed on the EU market that connects through wireless interfaces such as Wi-Fi, Bluetooth, and cellular networks.
- Delegated Regulation (EU) 2022/30
- RED 2014/53/EU Article 3.3 (d), (e), and (f)
- Applicable from August 1, 2025
- Network protection
- Personal data and privacy protection
- Fraud prevention
- EN 18031-1 / -2 / -3
- CE conformity assessment
Applicable to products with digital elements placed on the EU market, including hardware, software, and associated remote data processing functions.
- Regulation (EU) 2024/2847
- Security by design and secure-by-default requirements
- Vulnerability management and Software Bill of Materials (SBOM)
- Security updates and support period information
- Conformity assessment for certain important and critical products
- CE marking and technical documentation
- Vulnerability and incident reporting obligations apply from September 11, 2026
- Fully applicable from December 11, 2027
Applicable to consumer connectable products placed on the UK market, with obligations covering manufacturers, importers, and distributors.
- Mandatory from April 29, 2024
- Prohibits universal default passwords
- Requires a method for reporting security issues and vulnerabilities
- Requires disclosure of the minimum security update support period
- Requires a statement of compliance to be issued and supplied with the product
- Baseline requirements derived from ETSI EN 303 645
A voluntary cybersecurity labeling program for consumer wireless IoT products promoted by the FCC, helping consumers identify products that meet applicable cybersecurity requirements.
- Technical baseline based on NIST IR 8425
- Applicable to consumer wireless IoT products
- Product testing performed by recognized CyberLABs
- Authorization reviewed by a Cybersecurity Label Administrator (CLA)
- The label includes a QR Code linking to product cybersecurity registry information
An IoT product cybersecurity assessment and labeling scheme promoted by Japan's Ministry of Economy, Trade and Industry and operated by IPA, designed to indicate the level of product cybersecurity compliance.
- Operational since March 2025
- Applicable to IoT products with IP communication capabilities
- Uses a multi-level system from STAR-1 to STAR-4
- STAR-1 / STAR-2 use self-declaration of conformity
- STAR-3 / STAR-4 use third-party assessment
- Can support government, critical infrastructure, and enterprise procurement requirements
- Mutual recognition mechanisms have been established with UK PSTI and Singapore CLS
A consumer IoT cybersecurity labeling scheme promoted by Singapore's CSA, using four levels to indicate the cybersecurity requirements and depth of testing completed by a product.
- Level 1: Basic cybersecurity requirements
- Level 2: Mandatory requirements aligned with international standards
- Level 3: Secure design and third-party software binary analysis
- Level 4: Third-party structured penetration testing
- Wi-Fi routers must obtain at least CLS Level 1
- Technical requirements are based on ETSI EN 303 645
- Mutual recognition arrangements have been established with cybersecurity labeling schemes in multiple countries
Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025 take effect on March 4, 2026 and apply to smart devices that can connect directly or indirectly to a network and may be acquired by consumers in Australia.
- Password security requirements
- Security issue and vulnerability reporting methods
- Product support periods and security update information
- Manufacturer statement of compliance
- Statement of compliance must be retained for at least 5 years
- Desktop computers
- Laptop computers
- Tablet computers
- Smartphones
- Certain medical products
- Road vehicles and their components
Devices with Wi-Fi, Bluetooth, cellular, or other wireless connectivity functions.
Smart home products, networking equipment, cameras, smart locks, lighting devices, and other connected products.
Hardware, software, and associated remote data processing functions.
Routers, gateways, communication modules, and other network-connected terminal equipment.