Skip Navigation

WISESTONEBUSINESS

TEST REPORT

Cybersecurity testing

Overview

Cybersecurity testing is a comprehensive assessment conducted in accordance with international standards to verify the confidentiality, integrity, authentication,
and threat-response capabilities of security-related functions such as communication mechanisms and cryptographic algorithms in internet-connected devices.
This testing proactively identifies security vulnerabilities based on best-practice evaluation criteria and aims to enhance product reliability and strengthen cybersecurity readiness. It also serves as a core strategy for achieving global certification and improving consumer protection.
  • EN 18031-1, EN 18031-2, EN 18031-3 : A series of standards defining cybersecurity requirements for distributing secure wireless devices in the European market, in accordance with the RED provisions.
  • ETSI EN 303 645 : A standard designed to ensure the integrity of consumer IoT (Internet of Things) devices, minimize vulnerabilities, and safeguard cybersecurity and data protection.

Necessity of Cybersecurity Testing

Cybersecurity Test Targets

WISESTONE’s cybersecurity testing evaluates a wide range of internet-connected devices including smart devices, IoT hubs, and payment terminals to assess their personal data protection capabilities and resilience against security threats.

- EN18031(applies to wireless devices that use the internet)

  • Wireless Gateway Devices
    (IoT hubs, smart routers, etc.)

  • Wireless Electronic Devices
    (laptops, smartphones, etc.)

  • Wireless Wearable Devices
    (smartwatches, smart glasses, fitness bands, etc.)

  • Wireless Devices
    that Store or Transmit Collected
    Personal or Sensitive Data via Mobile Apps or Servers
    (home CCTV systems, etc.)

  • Wireless Payment and
    Authentication Devices
    (card readers, wireless crypto wallets, etc.)

  • Industrial IoT Wireless Devices
    (automation, monitoring, etc.)

  • Wireless Devices for Children
    (toys, drones, etc.)

  • Wireless Home Appliances
    (smart refrigerators, smart ovens,
    smart TVs, etc.)

- ETSI EN 303 645(applies to both wired and wireless devices that use the internet)

  • Wired and Wireless Communication Devices

  • Devices That Process Personal and Sensitive Information

  • Wearable Devices

  • Smart Home Appliances

  • IoT Toys and Devices for Children

  • Wireless Payment and Authentication Equipment

  • IoT Hubs and Gateway Devices

Cybersecurity Testing Standards

Category EN 18031-1, EN 18031-2, EN 18031-3 ETSI EN 303 645
Target All wireless equipment that communicates over the internet and falls under the cybersecurity requirements specified in Article 3.3 (d), (e), and (f). All Consumer IoT Products
Mandatory Requirement Mandatory Implementation for CE RED Certification Certification Guidelines
Content Developed under EU policy to prevent security incidents involving internet-connected wireless devices distributed within Europe, this technical standard is based on security and network requirements and includes additional personal data and financial-related requirements according to product characteristics. Defines the minimum security requirements and privacy protection principles that must be ensured, providing manufacturers and developers with clear security guidelines for design, development, and lifecycle management.
Test Execution Testing of All Applicable Requirements within the Relevant Standard for the Product
Standard Target
EN 18031-1 Security Network
EN 18031-2 Personal Data
EN 18031-3 Financial
The framework consists of 15 requirements for both documentation and products, comprising mandatory and recommended detailed requirements. Testing is conducted based on the selected requirements according to implemented functionalities and predefined conditions.
Selectable Scope of Requirements
Testing of Mandatory Requirements Only Testing of Mandatory + Recommended Requirements
Standards by Target Device

Cybersecurity Test Preparation Requirements and Duration

Category EN 18031-1, EN 18031-2, EN 18031-3 ETSI EN 303 645
Product Two units of the product with the same model and identical specifications are required.
Required Documents Firmware / Software Information Product Function Description Technical Specifications User Manual Security Mechanism Implementation Document (Functions & Data) Update Mechanism Implementation Document Protocol Implementation Document Risk Management and Assessment Report Test Plan and Results (Optional)
Duration Test clauses and test items vary depending on the applicable standard.
Estimated duration: 2 to 4 weeks.
Varies depending on the functions, complexity, and scope of the items implemented in the product.
Estimated duration: 2 to 4 weeks.

※ ※ The duration is calculated based on the test start date after all required documents have been submitted.

Cybersecurity Testing Procedure

  • 1

    Application

  • 2

    Registration
    Required documents for submission and preparation are provided during the in-person meeting after registration.

  • 3

    Agreement
    Review of submitted materials followed by agreement on the applicable standards and test scope.

  • 4

    Contract Execution
    Issuance of quotations based on standards and scope, followed by contract signing.

  • 5

    Test Execution
    Testing is performed for each requirement based on the product and submitted documents.

  • 6

    Issuance of Test Report

  • 7

    Post-Management Process
    Follow-up actions after the testing process, including additional tests requested by the Notified Body.
    *Post-management applies only to tests under EN 18031-1, EN 18031-2, and EN 18031-3.

Cybersecurity Consulting Procedure

Cybersecurity consulting is conducted during the technical meeting stage at the time of test registration.

Contact & Consultation