Testing Services
Industry
EU CRAFDA & MDRPayment & FinanceNewsAbout Us
EN繁中
Contact Us
Technical Testing

One-Stop Cybersecurity Laboratory Service

[ ISO/IEC 17025 accredited ] SBOM · vulnerability scanning & pen testing · firmware & code review — evidence for EU CRA · FDA & MDR · PCI
Applus+ Laboratories Alliance Partner
ISO 13485 Internal Auditor Training
May 16, 2026
Ended
Register
MDR Medical-Device Security Workshop
June 13, 2026
Ended
Register
EU CRA Update
June 30, 2026
Ended
Register
MDR Medical-Device Security Workshop
July 29, 2026
Ended
Register
EU CRA Update
September 18, 2026 · 14:00 · Taipei
Open
Register
ISO 13485 Internal Auditor Training
Coming soon
Open
Register
MDR Medical-Device Security Workshop
Coming soon
Open
Register
Service catalog

Pick a track.

Plan, prepare, certify — three tracks, one team. The GMA Platform ties the whole engagement together.

Track 01 · Plan

Know where you stand before you build.

Scoping, gap analysis and route planning — before a single test is booked.

Regulatory Scoping & Classification

Which regulations and classes apply to your product — decided early, not discovered late.

Readiness & Gap Analysis

We assess your product against the essential requirements and hand back a ranked fix list.

Certification Strategy

The fastest defensible route to every market you sell into.

Training

Free courses on EU CRA, MDR and ISO 13485, taught by Applus+ Laboratories Notified Body reviewers.

Track 02 · Prepare

Files that survive review.

The technical file, the SBOM and the processes behind them — written for the reviewer who reads the file next.

Technical Documentation & EU DoC

The complete technical file and EU Declaration of Conformity, built to the structure the annexes require.

SBOM Build & Analysis

SPDX / CycloneDX SBOMs you can defend. We build and maintain the SBOM itself — security testing against it is a Technical Testing service.

Third-party components dominate modern software and medical devices. We build and reconcile your software bill of materials, match components against known CVEs and license obligations, and deliver machine-readable SPDX / CycloneDX files that meet FDA Section 524B and EU MDR — with VEX documents explaining each finding's exploitability for supply-chain audits.

Submission Files

FDA §524B / 510(k) and Notified Body security documentation.

We consolidate test evidence into regulatory-grade deliverables: the Cybersecurity Management Report, Security Architecture Views, Threat Modeling Documentation and VEX documents — shaped the way FDA 510(k)/PMA reviewers and EU MDR Notified Bodies read them.

QMS Integration

IEC 81001-5-1 security processes, folded into your ISO 13485 QMS.

Incident-Reporting SOPs

CRA Article 14 reporting that meets the 24- and 72-hour deadlines.

Track 03 · Certify & Maintain

From test report to market.

The last mile — marks, Notified Bodies, scheme approvals and what happens after launch.

CE Marking Route

The conformity assessment path to a CE mark, module by module.

Notified Body Coordination

Certification through the two EU Notified Bodies in the Applus+ Laboratories group.

Payment Scheme Certifications

EMVCo, PCI and card-scheme approvals managed end to end.

Multi-Market Alignment

One evidence set for FDA, MDR, NMPA and TFDA.

Post-Market & Surveillance

Vulnerability disclosure, SBOM updates and annual reviews.

CRA (EN 18031 / RED) · FDA/MDR · Payment & Finance

5 Technical Tests.
3 Global Regulatory Frameworks.

One technical capability, built once, mapped to three compliance regimes. Scan the matrix, then expand any row for detail.

Technical Test CRA
EN 18031 / RED
FDA / MDR Payment & Finance
01Penetration Testing
02Vulnerability Scanning
03Source Code Review
04SBOM & Supply Chain Security
05Firmware & Embedded Systems
Core fit Depends on product type (e.g. connected payment terminals)

Our engineers simulate real attacks against your systems and existing controls, following OSSTMM methodology, to precisely identify exploitable weaknesses. Testing can be scoped to your operating context — including healthcare settings such as HIS, PACS or telehealth platforms.

Test Type
White-boxGray-boxBlack-box
Scope
System / Network / OSWeb App / APIMobile App / IoMT
Methodology
OSSTMM

We help you plan the right scanning strategy — advising on tool selection and tuning, or running scans directly across enterprise servers, cloud environments and hospital-connected hosts. Every scan closes with a risk assessment report and remediation guidance.

Scan Scope
Enterprise ServersCloudHospital-Connected Hosts
Compliance
PCI DSS3DSMedical Device Security Rules

Secure coding is the foundation of software resilience. We combine automated tooling with expert manual review to surface common security flaws and logic issues, and can train development teams — including SaMD/SiMD engineers — on secure coding fundamentals. Reviews integrate directly into your DevSecOps and CI/CD pipeline.

Integration
DevSecOpsCI/CD
Applies To
Software TeamsSaMD / SiMD Developers
Compliance
PCI DSS3DSFDA

Third-party components are now standard in software and medical device development, making supply chain security essential. We produce machine-readable SBOMs (SPDX or CycloneDX) that satisfy FDA (FD&C Act §524B) and EU MDR requirements, with VEX-format vulnerability disposition where needed.

Output Format
SPDXCycloneDXVEX
Compliance
FDA §524BEU MDR

For IoT devices, connected products, industrial control systems and smart medical devices, we run static and dynamic firmware analysis: reviewing firmware structure, flagging known third-party component vulnerabilities and hardcoded secrets, and assessing OTA update mechanisms and encryption strength. Deliverables include a security assessment report and threat-modeling reference.

Applies To
IoT / Connected DevicesICSSmart Medical Devices
Compliance
FDA Premarket GuidanceISO 14971IEC 81001-5-1
Testing scope and capabilities are subject to the latest official scope of accreditation.
How We Work

Four Steps. Fully Scoped.

01
STEP 01

Scoping

Define targets, standards and depth — a fixed scope, quote and timeline before anything starts.

Fixed quote + timeline
02
STEP 02

Testing

The lab runs the agreed scope; anything critical reaches you immediately, not in the final report.

Interim critical alerts
03
STEP 03

Report & Remediation

Findings with risk ratings and concrete remediation guidance, in the format your regulator expects.

Submission-ready report
04
STEP 04

Retest Verification

The lab verifies your fixes and reissues the report — closed findings, on the record.

Clean final evidence
FAQ

Common Questions

Three questions we get most.

Can these test results be submitted directly for regulatory review?

Yes. That's what the deliverable structure is for: CRA and medical-device engagements produce one Cybersecurity Management Report shaped for Annex VII, FDA Section 524B and MDR technical files; payment engagements produce per-scheme reports in the assessor's expected format.

How much of the testing happens remotely?

Depends on what's being tested. Software, cloud and application engagements run fully remote. Hardware, firmware and RF/radio-conformance testing (RED) require lab work — most of it at our ISO/IEC 17025-accredited lab in Taiwan, with select test types routed to other labs within Applus+ Laboratories' network. Either way, SVS in Taiwan stays your single point of contact — same time zone, same language, same team guiding you through what's next.

How long does a typical engagement take?

Scope drives it: a focused vulnerability scan lands in days; full penetration testing with retest verification typically runs a few weeks.