For teams shipping mobile apps, and for manufacturers of connected products with a companion app.
The Cyber Resilience Act covers products with digital elements placed on the EU market, including mobile apps and their integral remote data processing, subject to the regulation's scope and exclusions. Our service provides technical evidence for applicable requirements in both parts of Annex I:
- Product security (Part I): assessment of the app and its backend interfaces within the agreed scope, with findings mapped to applicable requirements and supporting runtime evidence.
- Vulnerability handling (Part II): recurring release testing over the agreed support period, an inventory of shipped third-party components and checks for known vulnerabilities to support your vulnerability handling process.
We agree the app, interfaces, applicable requirements, testing cadence and test conditions before testing begins. Technical testing supports your conformity assessment; it does not replace your other product and vulnerability handling obligations.