CRA & EN 18031 Cybersecurity Testing Suite

Professional compliance testing software for EN 18031‑1:2024, EN 18031‑2:2024, and EN 18031‑3:2024 standards. Our solution has helped multiple laboratories achieve A2LA / CNAS accreditation.

Powerful Testing Platform

Our comprehensive cybersecurity testing suite provides all the tools needed for EN 18031 compliance assessment and accreditation.

Automated Compliance Testing

Streamline your testing process with automated test execution and comprehensive reporting for all EN 18031 requirements.

Real-time Analytics

Monitor test progress, identify vulnerabilities, and track compliance metrics with our advanced dashboard.

CNAS

A2LA / CNAS Accreditation Support

Our software includes workflows and documentation templates designed to help labs achieve A2LA / CNAS accreditation.

What Our Software Offers

Experience the full power of the EN 18031 testing suite with these advanced capabilities.

Test Plan Management

Create, edit, and manage detailed test plans with asset declaration and mechanism binding for full traceability.

Multi-language Reports

Generate compliance reports in English, Chinese, Japanese, Korean, and Hindi with one click. Word and PDF formats supported.

Image Gallery & Diagram

Upload connection diagrams and product photos directly into the project, view them in an integrated gallery.

Asset-Mechanism Binding

Clearly link security assets to test mechanisms, ensuring full coverage of EN 18031 requirements.

Manufacturer Pre‑assessment Tool

Interactive self-assessment tool for manufacturers to evaluate readiness before formal testing.

Data Center Integration

Centralized storage for all test results, SBOM analysis, and network scans with full traceability.

Mechanism‑Based Testing

Group assets by security mechanisms and evaluate conceptual, completeness, and sufficiency together.

Decision Tree Guidance

Interactive decision trees with multi‑language support guide testers through complex evaluation paths.

Three‑Phase Assessment Methodology

Our software follows a structured approach to ensure complete coverage of EN 18031 requirements.

1

Conceptual Assessment

Verify that the intended security mechanisms are correctly identified and justified. Decision trees help determine applicable requirements based on device capabilities.

2

Functional Completeness

Compare declared assets against discovered assets to ensure no security gap exists. Automated asset verification and bulk import streamline the process.

3

Functional Sufficiency

Execute test procedures to validate that mechanisms operate as intended. Step‑by‑step test execution with result logging and evidence attachment.

Mechanism‑Based Testing

Instead of testing each asset individually, our software groups related assets under security mechanisms (e.g., Authentication, Encryption, Secure Storage). This reduces redundancy and provides a holistic view of security implementation.

  • Group assets by mechanism (ACM, AUM, CRY, …)
  • Evaluate conceptual, completeness, and sufficiency at mechanism level
  • Automatic justification generation based on mechanism properties
  • Clear visibility of which assets are covered by each mechanism

Mechanism data is loaded from your test plan JSON files, allowing full customization per product.

Mechanism-Based Testing Interface

EN 18031 Standards Coverage

Our testing suite provides comprehensive coverage for all three EN 18031 cybersecurity standards.

EN 18031-1:2024

Network Security Testing

  • Network architecture security assessment
  • Encryption and TLS implementation testing
  • Access control and authentication validation
  • Intrusion detection system testing
  • Firewall and network segmentation analysis

EN 18031-2:2024

Privacy & Data Security

  • Personal data protection compliance
  • Privacy-by-design implementation testing
  • Data anonymization and encryption validation
  • Consent management system assessment
  • Data breach response testing

EN 18031-3:2024

Financial Transaction Security

  • Payment system security assessment
  • Financial transaction encryption validation
  • Fraud detection system testing
  • Regulatory compliance verification
  • Secure payment gateway analysis

EU Cyber Resilience Act (CRA) Support

Complete pre‑assessment and testing for the new EU regulation – mandatory from 2027.

Overview & Timeline

The EU Cyber Resilience Act (CRA) entered into force on December 10, 2024. It imposes mandatory cybersecurity requirements on products with digital elements (PDEs) across their entire lifecycle. Compliance is required by December 11, 2027, with key milestones in 2026 for vulnerability reporting.

  • 2024-12-10: CRA enters into force
  • 2026-06-11: Requirements for conformity assessment bodies apply
  • 2026-09-11: Mandatory 24‑hour vulnerability reporting (ENISA SRP)
  • 2027-12-11: Full application – all new products must bear CE marking

Risk‑Based Classification

Default

~90% of products (e.g. consumer IoT, smart home, general software) – self‑assessment (Module A).

Important

Class I (password managers, routers) & Class II (firewalls, IDS/IPS) – may require Notified Body involvement.

Critical

HSM, smart cards, secure elements – mandatory third‑party assessment or EU certification (EUCC).

Key Requirements (Annex I)

  • Secure by Design & Default
  • Vulnerability Handling & SBOM
  • Access Control & Authentication
  • Data Confidentiality & Integrity
  • Attack Surface Limitation
  • Security Logging & Monitoring
  • Exploit Mitigation & Resilience

CRA Test Modules – Technical Workflows

Secure by Design & Default

Verify that the product is secure out‑of‑the‑box, with no known vulnerabilities, secure default configuration, and minimal attack surface.

  • SBOM Generation & Vulnerability Scan – generate or import SBOM (SPDX, CycloneDX, JSON) and cross‑reference with NVD/CVE databases.
  • Default Configuration Audit – scan open ports, services, and test for default credentials (using SecLists dictionaries).
  • Attack Surface Minimization – check for debug interfaces (UART, JTAG, ADB) and unnecessary services (FTP, Telnet).

Access Control & Authentication

Ensure that unauthorized access is prevented and authentication mechanisms are robust against brute‑force and credential attacks.

  • Access Point Enumeration – identify all network ports, physical interfaces, and API endpoints.
  • Unauthenticated Access Testing – attempt to access each endpoint without credentials.
  • Authentication Strength Validation – verify password policies, account lockout, session management, and MFA implementation.

Data Protection (Confidentiality, Integrity, Minimisation)

Verify that stored data is encrypted, integrity is ensured, and only necessary data is collected.

  • Data at Rest Encryption – check database, file system, and key management practices.
  • Data Integrity – validate checksums, hashes, and digital signatures for critical files.
  • Data Minimisation – review collected data against functional necessity, retention, and deletion policies.

Security Updates & Vulnerability Handling

Confirm that the update mechanism is secure, and that vulnerability handling procedures are in place.

  • Update Delivery Security – verify OTA/online update authenticity (signature verification, certificate chain).
  • Update Integrity & Rollback – check checksum validation and rollback protection.
  • Exploit Mitigation – confirm ASLR, DEP/NX, stack protection, and CFG are enabled.

Resilience & Availability

Test the product's resistance to denial‑of‑service attacks and its ability to recover from failures without affecting other systems.

  • DoS Protection – test with connection floods, Slowloris, and HTTP floods; verify resource limits.
  • Failure Recovery – simulate process crashes, network partitions, database failures; check graceful degradation.
  • Cascading Impact – verify isolation mechanisms (resource, network, process) to limit failure propagation.

Security Logging & Monitoring

Ensure that security‑relevant events are logged and that anomalies are detected and reported.

  • Security Logging – verify that authentication, access, and configuration changes are logged with tamper‑proof protection.
  • Anomaly Detection – test detection mechanisms (threshold‑based, signature‑based) and alerting (email, SMS, dashboard).

Secure Decommissioning

Validate that all residual data can be securely erased at end‑of‑life.

  • Residual Data Identification – locate non‑volatile storage, volatile memory, caches, and logs.
  • Secure Erasure – test software overwrite, factory reset, and key destruction; attempt recovery to verify effectiveness.

Trusted by Testing Laboratories

Our software has helped multiple laboratories achieve A2LA / CNAS accreditation for EN 18031 compliance testing.

"DigiInfo's EN 18031 Testing Suite was instrumental in our laboratory achieving A2LA / CNAS accreditation. The software streamlined our testing process and provided comprehensive reporting that met all accreditation requirements."
Victor Yau

Victor Yau

Director, Advanced Security Testing Lab

Software Interface Demo

Explore the powerful features of our EN 18031 compliance testing platform.

Software Interface

Project Management Dashboard

Manage multiple testing projects with our intuitive dashboard that provides real-time status updates and progress tracking.

Comprehensive Reporting

Generate detailed compliance reports in multiple formats (PDF, Word) with customizable templates for different accreditation bodies.

Automated Test Execution

Execute standardized test procedures automatically with configurable test plans and parameterized test cases.

Centralized Data Repository

Store and manage all test data, evidence, and documentation in a secure, centralized database with version control.

Integrated Security Testing Tools

Launch analysis tools directly from the testing interface to collect evidence.

Network Scanner

Discover open ports, services, and potential vulnerabilities.

Firmware Analyzer

Extract and analyze firmware for hardcoded secrets.

Bluetooth Scanner

Test BLE devices for pairing security and MITM risks.

Wi-Fi Security

Assess wireless network configuration and encryption.

UART / JTAG

Identify debug interfaces that may expose sensitive data.

SBOM Analyzer

Check software components for known vulnerabilities.

ADB / Shell

Interact with Android devices for deeper inspection.

Brute Force Tester

Evaluate authentication mechanisms against dictionary attacks.

Latest News & Updates

Stay informed about new features, standards, and accreditation tips.

EU Cyber Resilience Act (CRA)

March 22, 2026

The EU Cyber Resilience Act (CRA) is a mandatory regulation aimed at strengthening the security of hardware and software products with digital elements. The Act requires products to meet cybersecurity standards throughout their entire lifecycle — from design and production to market placement — and to bear the CE marking. The regulation will be fully enforced in 2027, with the goal of increasing consumer trust, addressing security vulnerabilities, and imposing substantial fines for non‑compliant products.

Core Content and Key Information:

Effective Date: The Act was adopted at the end of 2024; the core requirements are expected to be fully enforced on December 11, 2027. Obligations related to product reporting will apply from September 2026.

Scope: Covers all digital products that are directly or indirectly connected to a network, whether hardware (IoT devices, routers, computers) or software (operating systems, applications).

Core Requirements: Products must incorporate security by design, provide security update support, manage vulnerabilities, and come with secure default settings.

CE Marking: Products placed on the EU market must demonstrate compliance with cybersecurity standards and bear the CE marking.

Penalties: Manufacturers that fail to comply may face fines of up to €15 million or 2.5% of their total worldwide annual turnover from the previous financial year.

Affected Parties:

This Act has a significant impact on hardware and software manufacturers, importers, and distributors that sell products in the EU. It requires them to manage cybersecurity throughout the entire lifecycle of their products.

Welcome to the new DigiInfo website!

March 21, 2026

We are excited to launch our redesigned platform with enhanced EN 18031 testing tools and a new admin backend.