Professional compliance testing software for EN 18031‑1:2024, EN 18031‑2:2024, and EN 18031‑3:2024 standards. Our solution has helped multiple laboratories achieve A2LA / CNAS accreditation.
Our comprehensive cybersecurity testing suite provides all the tools needed for EN 18031 compliance assessment and accreditation.
Streamline your testing process with automated test execution and comprehensive reporting for all EN 18031 requirements.
Monitor test progress, identify vulnerabilities, and track compliance metrics with our advanced dashboard.
Our software includes workflows and documentation templates designed to help labs achieve A2LA / CNAS accreditation.
Experience the full power of the EN 18031 testing suite with these advanced capabilities.
Create, edit, and manage detailed test plans with asset declaration and mechanism binding for full traceability.
Generate compliance reports in English, Chinese, Japanese, Korean, and Hindi with one click. Word and PDF formats supported.
Upload connection diagrams and product photos directly into the project, view them in an integrated gallery.
Clearly link security assets to test mechanisms, ensuring full coverage of EN 18031 requirements.
Interactive self-assessment tool for manufacturers to evaluate readiness before formal testing.
Centralized storage for all test results, SBOM analysis, and network scans with full traceability.
Group assets by security mechanisms and evaluate conceptual, completeness, and sufficiency together.
Interactive decision trees with multi‑language support guide testers through complex evaluation paths.
Our software follows a structured approach to ensure complete coverage of EN 18031 requirements.
Verify that the intended security mechanisms are correctly identified and justified. Decision trees help determine applicable requirements based on device capabilities.
Compare declared assets against discovered assets to ensure no security gap exists. Automated asset verification and bulk import streamline the process.
Execute test procedures to validate that mechanisms operate as intended. Step‑by‑step test execution with result logging and evidence attachment.
Instead of testing each asset individually, our software groups related assets under security mechanisms (e.g., Authentication, Encryption, Secure Storage). This reduces redundancy and provides a holistic view of security implementation.
Mechanism data is loaded from your test plan JSON files, allowing full customization per product.
Our testing suite provides comprehensive coverage for all three EN 18031 cybersecurity standards.
Network Security Testing
Privacy & Data Security
Financial Transaction Security
Complete pre‑assessment and testing for the new EU regulation – mandatory from 2027.
The EU Cyber Resilience Act (CRA) entered into force on December 10, 2024. It imposes mandatory cybersecurity requirements on products with digital elements (PDEs) across their entire lifecycle. Compliance is required by December 11, 2027, with key milestones in 2026 for vulnerability reporting.
~90% of products (e.g. consumer IoT, smart home, general software) – self‑assessment (Module A).
Class I (password managers, routers) & Class II (firewalls, IDS/IPS) – may require Notified Body involvement.
HSM, smart cards, secure elements – mandatory third‑party assessment or EU certification (EUCC).
Verify that the product is secure out‑of‑the‑box, with no known vulnerabilities, secure default configuration, and minimal attack surface.
Ensure that unauthorized access is prevented and authentication mechanisms are robust against brute‑force and credential attacks.
Verify that stored data is encrypted, integrity is ensured, and only necessary data is collected.
Confirm that the update mechanism is secure, and that vulnerability handling procedures are in place.
Test the product's resistance to denial‑of‑service attacks and its ability to recover from failures without affecting other systems.
Ensure that security‑relevant events are logged and that anomalies are detected and reported.
Validate that all residual data can be securely erased at end‑of‑life.
Our software has helped multiple laboratories achieve A2LA / CNAS accreditation for EN 18031 compliance testing.
Explore the powerful features of our EN 18031 compliance testing platform.
Manage multiple testing projects with our intuitive dashboard that provides real-time status updates and progress tracking.
Generate detailed compliance reports in multiple formats (PDF, Word) with customizable templates for different accreditation bodies.
Execute standardized test procedures automatically with configurable test plans and parameterized test cases.
Store and manage all test data, evidence, and documentation in a secure, centralized database with version control.
Launch analysis tools directly from the testing interface to collect evidence.
Discover open ports, services, and potential vulnerabilities.
Extract and analyze firmware for hardcoded secrets.
Test BLE devices for pairing security and MITM risks.
Assess wireless network configuration and encryption.
Identify debug interfaces that may expose sensitive data.
Check software components for known vulnerabilities.
Interact with Android devices for deeper inspection.
Evaluate authentication mechanisms against dictionary attacks.
Stay informed about new features, standards, and accreditation tips.
The EU Cyber Resilience Act (CRA) is a mandatory regulation aimed at strengthening the security of hardware and software products with digital elements. The Act requires products to meet cybersecurity standards throughout their entire lifecycle — from design and production to market placement — and to bear the CE marking. The regulation will be fully enforced in 2027, with the goal of increasing consumer trust, addressing security vulnerabilities, and imposing substantial fines for non‑compliant products.
Core Content and Key Information:
Effective Date: The Act was adopted at the end of 2024; the core requirements are expected to be fully enforced on December 11, 2027. Obligations related to product reporting will apply from September 2026.
Scope: Covers all digital products that are directly or indirectly connected to a network, whether hardware (IoT devices, routers, computers) or software (operating systems, applications).
Core Requirements: Products must incorporate security by design, provide security update support, manage vulnerabilities, and come with secure default settings.
CE Marking: Products placed on the EU market must demonstrate compliance with cybersecurity standards and bear the CE marking.
Penalties: Manufacturers that fail to comply may face fines of up to €15 million or 2.5% of their total worldwide annual turnover from the previous financial year.
Affected Parties:
This Act has a significant impact on hardware and software manufacturers, importers, and distributors that sell products in the EU. It requires them to manage cybersecurity throughout the entire lifecycle of their products.
We are excited to launch our redesigned platform with enhanced EN 18031 testing tools and a new admin backend.