CyberSecurity Certified (CSC): Your smart home device or CIoT product certified, independently of manufacturer
Security concerns about smart home devices are still high. According to a Forsa survey, only one person in three trusts the built-in security functions. With the CyberSecurity Certified (CSC) mark of conformity, manufacturers of smart home devices and consumer IoT products can counter this problem and objectively prove the implementation of security measures.
Are you a manufacturer of a CIoT product and want the security of your (smart home) device confirmed by an independent third party? Then we will be happy to accompany you on your way to a successful CSC certificate: starting with a GAP analysis, through support services and audits, to the final CSC certification.
Free whitepaper "Cybersecurity Conformity Assessment for Consumer IoTs"
Our whitepaper will familiarize you with the CSC audit standard, inform you about its basic principles, and explain why it makes sense from a security perspective to establish the new cybersecurity scheme.
Download with restricted access
Our CSC services for manufacturers of CIoT products
Gap analysis
Determines the maturity level for the planned certification and creates a catalog of measures.
Project support
Support in achieving a planned goal, e.g. a security level.
Audit
Document & product assessment; additional penetration testing depending on CSC level.
Certification audit
Final certification by our certification partner TÜV NORD CERT.
Better security in consumer IoT: The test levels for CSC certification
Our evaluation concept enables certification in the Basic, Substantial and High levels, depending on the scope and depth of testing. Both the IoT product and the development and production process are tested. The entire process is based on internationally recognized norms and standards.
Further test objects can be individually coordinated with us.
The benefits of CSC certification
- Proof of trust & compliance: With a CSC certificate, you objectively prove the security of your CIoT product and enjoy greater confidence in the market.
- Competitive advantages: The proven security of your product sets you apart from other manufacturers.
- Identification of vulnerabilities: CSC certification reveals existing security deficiencies, the remediation of which reduces potential IT risks and hazards many times over (risk analysis).
- Higher security level: Continuously improving the safety of your product throughout its life cycle.
- Two-in-one testing: In addition to the IT security of your product, the assessment also focuses on functional device safety.
- Active pioneering role: You actively contribute to strengthening trust in smart home and CIoT products and provide better orientation for consumers.
Why CSC certification?
When it comes to the subject of smart homes, many consumers are fairly critical. This is also confirmed by a Forsa survey conducted on behalf of the TÜV association. According to the survey, 2 out of 3 respondents (66 percent) believe that there is a very high risk of smart devices becoming the target of a hacker attack. 68 percent also fear that smart devices could misuse their personal data.
These security concerns mean that sales figures for smart home devices and CIoT products are currently still well below expectations and the market is only developing slowly.
By having your CIoT product inspected and certified under the new cybersecurity scheme "CyberSecurity Certified (CSC)", you remove existing uncertainties for customers and objectively demonstrate the IT security of your product. This benefits not only you as manufacturer, but also end consumers. This is because labeling a CIoT product with an independent mark of conformity for smart home devices creates trust, provides orientation, and has a positive effect on upcoming purchasing decisions.
Source: TÜV Association, February 2021
The subject of the test is, on the one hand, the CIoT product itself, which is tested with regard to both IT security aspects and its functional safety. In addition, however, the underlying business processes, data protection aspects and other services, such as connection to a cloud, are considered based on internationally recognized standards. Depending on the test level, additional penetration tests are also carried out.
The inspection and certification are based on internationally recognized norms and standards, such as ETSI EN 303 645, IEC 62443, ISO 27001, and the C5 catalog.
Since CSC certification is based among other things on ETSI EN 303 645, manufacturers use it to simultaneously cover the requirements of the European Cybersecurity Act (CSA).
The project duration within the scope of a CSC certification can be approx. 1 month to approx. 3 months.
Tel.: +49 201 8999-614
Fax: +49 201 8999-666
a.padberg@tuvit.de