Taking a product through security certification.
Buyers increasingly make security certification a condition of purchase. We work with product suppliers through the whole route — building the secure development lifecycle, generating the evidence, and preparing for the certification body — across industrial, automotive and connected product schemes.
- IEC 62443-4-1/4-2
- Industrial products
- ISO/SAE 21434
- Automotive
- SL 1–4
- Capability levels
Standards in scope
IEC 62443-4-1
Secure product development lifecycle requirements
IEC 62443-4-2
Technical security requirements for components
ISO/SAE 21434
Automotive cybersecurity engineering
Certification schemes
Conformity assessment routes
Schemes and standards we prepare products for.
Certification is won or lost on evidence, not intent. We build the development process and the artefacts it produces so the assessment becomes a review of work already done.
Secure product development lifecycle requirements
The process standard for product suppliers: security management, requirements, design, implementation, verification, defect management, update management and guidelines.
How we support you
- Practice-by-practice gap assessment across all eight practices
- Secure development lifecycle process definition
- Threat modelling method and worked examples
- Security requirements and design documentation
- Verification and validation evidence structure
- Defect and vulnerability handling processes
Technical security requirements for components
The capability requirements a component must demonstrate — identification, use control, data integrity, confidentiality, restricted data flow, timely response and resource availability.
How we support you
- Component capability gap analysis by foundational requirement
- Security level capability determination
- Requirement allocation to hardware and firmware
- Test case derivation and evidence mapping
- Security guidelines documentation for integrators
- Remediation plan for capability gaps
Automotive cybersecurity engineering
Cybersecurity engineering across the vehicle E/E lifecycle, including supplier obligations, TARA and the cybersecurity case used in assessment.
How we support you
- CSMS and project-level process definition
- TARA methodology and worked analyses
- Cybersecurity interface agreement templates
- Work product set aligned to the standard
- Cybersecurity case assembly
- Assessment dry-run and readiness review
Conformity assessment routes
Which scheme fits your product and market — recognised industrial certification programmes, automotive type approval routes and cloud assurance schemes — and what each expects at submission.
How we support you
- Scheme selection and applicability analysis
- Submission documentation structure
- Pre-assessment internal audit
- Evidence pack assembly and review
- Finding response and corrective action support
- Surveillance and re-certification planning
What a certification engagement covers.
The same seven services run across every practice, so you can compare scope without re-learning the menu.
Risk assessment
Threat modelling and security risk analysis at the product level, feeding requirements rather than sitting in a separate report.
Advisory & consulting
Choosing the right scheme and target level for your market, and designing a development process your team will realistically follow.
VA-PT & security testing
Security verification and validation, fuzzing and robustness testing, and interface testing against the declared capabilities.
Compliance & audit readiness
Gap assessment, evidence assembly and pre-assessment audit so submission is a formality rather than a discovery exercise.
Implementation support
Embedding the lifecycle into engineering — templates, gates, tooling and the review cadence that keeps it alive.
Security operations
Vulnerability handling, security update processes and post-release obligations after the certificate is issued.
Training & capability
Developer and product manager training on the standard, threat modelling and secure coding for the relevant platform.
Product types we support
- PLCs, RTUs and industrial controllers
- Protection relays and substation devices
- SCADA and control system software
- Automotive ECUs, gateways and telematics units
- Connected and IIoT devices
- Industrial gateways and edge platforms
- Embedded firmware and RTOS-based products
- Cloud-connected product back-ends
What you receive
- Gap assessment against the target standard and level
- Secure development lifecycle process documentation
- Threat model and security requirements specification
- Verification and validation evidence matrix
- Security guidelines and hardening documentation
- Submission-ready evidence pack and audit response plan
Certifying a product?
Tell us the product, the target scheme and the deadline. We will tell you honestly whether it is achievable and what the gap looks like.