Cyber Resilience Act testing for mobile apps.

Build the evidence your Android or iOS app needs under the EU Cyber Resilience Act. Get test reports written for your technical documentation, fixes your team can act on, and regular testing across the support period.

For teams shipping mobile apps, and for manufacturers of connected products with a companion app.

The Cyber Resilience Act covers products with digital elements placed on the EU market, including mobile apps and their integral remote data processing, subject to the regulation's scope and exclusions. Our service provides technical evidence for applicable requirements in both parts of Annex I:

  • Product security (Part I): assessment of the app and its backend interfaces within the agreed scope, with findings mapped to applicable requirements and supporting runtime evidence.
  • Vulnerability handling (Part II): recurring release testing over the agreed support period, an inventory of shipped third-party components and checks for known vulnerabilities to support your vulnerability handling process.

We agree the app, interfaces, applicable requirements, testing cadence and test conditions before testing begins. Technical testing supports your conformity assessment; it does not replace your other product and vulnerability handling obligations.

We know what an assessor looks for.

Our team spent years as evaluators in security laboratories, reviewing the evidence manufacturers submit under Common Criteria and PCI schemes. We know what an assessor looks for because we were the assessor.

Our reports are written for whoever assesses your conformity: your own team, or a notified body where the CRA requires one.

Tell us about your app and the product it belongs to. We help you identify what needs testing and what evidence your technical file is missing.

You get clear findings, practical guidance on fixes and test reports ready to include in your technical documentation.

Explore the technology behind our testing
Do we need a notified body?

Most mobile apps fall into the default category, where the manufacturer can self-assess. Important or critical products may require a different route, including third-party assessment. The product's function and classification determine the route. We are not a notified body; we produce technical test evidence for your assessment. See the European Commission's conformity assessment guidance.

What do you test against?

We map the agreed tests to applicable Annex I requirements, using OWASP MASVS and MASTG as mobile security references. We contribute to OWASP MAS and track relevant CRA harmonised standards as they are adopted.

Does this replace a pentest or an OWASP MASVS assessment?

It builds on them, connecting the evidence to your CRA technical documentation. If you only need to understand your app's vulnerabilities, start with mobile application penetration testing. For control coverage, explore an OWASP MASVS assessment.

A necessary cookie remembers your choice for up to 180 days. Privacy policy.