測試服務技術測試諮詢與驗證
Industry
EU CRAFDA & MDR支付與金融新聞關於我們
EN繁中
聯絡我們
Technical Testing

One-Stop Cybersecurity Laboratory Service

[ ISO/IEC 17025 accredited ] SBOM · vulnerability scanning & pen testing · firmware & code review — evidence for EU CRA · FDA & MDR · PCI
Applus+ Laboratories Alliance Partner
ISO 13485 內部稽核員培訓
2026 年 5 月 16 日
已結束
Register
MDR 醫療器材資安實作坊
2026 年 6 月 13 日
已結束
Register
EU CRA 法規動態
2026 年 6 月 30 日
已結束
Register
MDR 醫療器材資安實作坊
2026 年 7 月 29 日
已結束
Register
EU CRA 法規動態
2026 年 9 月 18 日 · 14:00 · 台北
開放報名
Register
ISO 13485 內部稽核員培訓
即將公布
開放報名
Register
MDR 醫療器材資安實作坊
即將公布
開放報名
Register
Service catalog

選擇適合的路線。

規劃、準備、驗證——三條路線,同一團隊。GMA 平台將整個專案串連在一起。

Track 01 · Plan

在動工之前,先掌握自己的位置。

範圍界定、差距分析與路線規劃——在預約任何一項測試之前完成。

法規範圍界定與分類

釐清哪些法規與分類適用於貴公司的產品——及早確定,而非事後才發現。

就緒評估與差距分析

我們依基本要求評估貴公司的產品,並回覆排定優先順序的改善清單。

驗證策略

通往每個目標市場、最快且站得住腳的路徑。

培訓課程

免費課程,涵蓋 EU CRA、MDR 與 ISO 13485,由 Applus+ Laboratories 公告機構審查員親自授課。

Track 02 · Prepare

經得起審查的文件。

技術文件、SBOM 以及背後的流程——為下一位審閱文件的審查員而寫。

技術文件與 EU 符合性聲明(DoC)

完整的技術文件與歐盟符合性聲明,依附件要求的架構建立。

SBOM 建置與分析

可供佐證的 SPDX / CycloneDX SBOM。我們負責建置與維護 SBOM 本身;針對 SBOM 的安全測試則屬於技術測試服務。

第三方元件已是現代軟體與醫療器材開發的主流。我們建置並核對貴公司的軟體物料清單,比對已知 CVE 與授權義務,交付符合 FDA Section 524B 與 EU MDR 要求的機器可讀 SPDX / CycloneDX 檔案,並以 VEX 文件說明各項發現的可利用性,供供應鏈稽核使用。

送件文件

FDA §524B/510(k) 與公告機構所需的資安文件。

我們將測試證據彙整為符合法規等級的交付文件:資安管理報告、安全架構視圖、威脅建模文件與 VEX 文件——並依 FDA 510(k)/PMA 審查人員與歐盟 MDR 公告機構的閱讀習慣編排。

QMS 整合

將 IEC 81001-5-1 的資安流程融入既有的 ISO 13485 品質管理系統。

事故通報標準作業程序

符合 CRA Article 14 所訂 24 小時與 72 小時期限的通報機制。

Track 03 · Certify & Maintain

從測試報告到產品上市。

最後一哩路——標誌、公告機構、方案核准,以及上市之後的工作。

CE 標誌取得路徑

取得 CE 標誌的符合性評鑑路徑,逐一模組說明。

公告機構協調

透過 Applus+ Laboratories 集團旗下兩家歐盟公告機構完成驗證。

支付方案驗證

EMVCo、PCI 與卡組織核准,全程一手管理。

多市場一致對應

一套證據,同時對應 FDA、MDR、NMPA 與 TFDA。

上市後與監督

弱點揭露、SBOM 更新與年度審查。

CRA (EN 18031 / RED) · FDA/MDR · Payment & Finance

5 Technical Tests.
3 Global Regulatory Frameworks.

One technical capability, built once, mapped to three compliance regimes. Scan the matrix, then expand any row for detail.

Technical Test CRA
EN 18031 / RED
FDA / MDR Payment & Finance
01Penetration Testing
02Vulnerability Scanning
03Source Code Review
04SBOM & Supply Chain Security
05Firmware & Embedded Systems
Core fit Depends on product type (e.g. connected payment terminals)

Our engineers simulate real attacks against your systems and existing controls, following OSSTMM methodology, to precisely identify exploitable weaknesses. Testing can be scoped to your operating context — including healthcare settings such as HIS, PACS or telehealth platforms.

Test Type
White-boxGray-boxBlack-box
Scope
System / Network / OSWeb App / APIMobile App / IoMT
Methodology
OSSTMM

We help you plan the right scanning strategy — advising on tool selection and tuning, or running scans directly across enterprise servers, cloud environments and hospital-connected hosts. Every scan closes with a risk assessment report and remediation guidance.

Scan Scope
Enterprise ServersCloudHospital-Connected Hosts
Compliance
PCI DSS3DSMedical Device Security Rules

Secure coding is the foundation of software resilience. We combine automated tooling with expert manual review to surface common security flaws and logic issues, and can train development teams — including SaMD/SiMD engineers — on secure coding fundamentals. Reviews integrate directly into your DevSecOps and CI/CD pipeline.

Integration
DevSecOpsCI/CD
Applies To
Software TeamsSaMD / SiMD Developers
Compliance
PCI DSS3DSFDA

Third-party components are now standard in software and medical device development, making supply chain security essential. We produce machine-readable SBOMs (SPDX or CycloneDX) that satisfy FDA (FD&C Act §524B) and EU MDR requirements, with VEX-format vulnerability disposition where needed.

Output Format
SPDXCycloneDXVEX
Compliance
FDA §524BEU MDR

For IoT devices, connected products, industrial control systems and smart medical devices, we run static and dynamic firmware analysis: reviewing firmware structure, flagging known third-party component vulnerabilities and hardcoded secrets, and assessing OTA update mechanisms and encryption strength. Deliverables include a security assessment report and threat-modeling reference.

Applies To
IoT / Connected DevicesICSSmart Medical Devices
Compliance
FDA Premarket GuidanceISO 14971IEC 81001-5-1
Testing scope and capabilities are subject to the latest official scope of accreditation.
How We Work

Four Steps. Fully Scoped.

01
STEP 01

Scoping

Define targets, standards and depth — a fixed scope, quote and timeline before anything starts.

Fixed quote + timeline
02
STEP 02

Testing

The lab runs the agreed scope; anything critical reaches you immediately, not in the final report.

Interim critical alerts
03
STEP 03

Report & Remediation

Findings with risk ratings and concrete remediation guidance, in the format your regulator expects.

Submission-ready report
04
STEP 04

Retest Verification

The lab verifies your fixes and reissues the report — closed findings, on the record.

Clean final evidence
FAQ

常見問題

最常被問到的三個問題。

測試結果可以直接送審嗎?

可以,這正是交付格式的設計目的:CRA 與醫療器材案件會產出一份「資安管理報告」,格式對應 Annex VII、FDA Section 524B 與 MDR technical file 的要求;金融支付案件則依評估機構(assessor)預期的格式,產出各 scheme 專屬報告。

測試都要送到實驗室,還是可以遠端進行?

看測試的是什麼。軟體、雲端與應用程式類的部分可以完全遠端執行;硬體、韌體與 RED 無線電一致性測試則需要進實驗室,多數在我們位於台灣、通過 ISO/IEC 17025 認證的實驗室完成,部分特殊測試項目會交由 Applus+ 體系內其他實驗室執行。不論測試在哪裡進行,都由安合規律檢驗(SVS)在台灣統一對接——時區、語言與後續輔導不會中斷。

一個案子通常要花多久?

取決於範疇:聚焦型的弱點掃描通常幾天內完成;含複測驗證的完整滲透測試,一般需要數週。