FAQs: Cybersecurity Certification

Frequently asked questions for cybersecurity certification.

What are the benefits of getting your product CB certified?

For several decades, the CB Scheme has garnered recognition in over 50 countries as an international product certification initiative. It plays a crucial role in facilitating global trade by offering international recognition of CB Certificates for national approvals. This streamlined approach provides manufacturers with a "one-stop" service, allowing them to undergo testing once and gain access to multiple markets.

In recent years, the importance of cybersecurity within the CB Scheme has grown significantly. Over the past five years, a staggering 583,533 certificates have been issued, highlighting the increasing awareness of cybersecurity risks. Notably, approximately 80% of product categories covered by the scheme may be susceptible to cybersecurity vulnerabilities. These categories include household appliances (25%), information technology and audio/video equipment (23%), office equipment (15%), lighting products (6%), electronic components and accessories (4%), medical devices (3%), measurement and test equipment (2%), among others.

With the proliferation of connected products, such as consumer IoT devices and industrial control systems, the need to address cybersecurity concerns has become paramount. Consequently, national legislators have begun to prioritize cybersecurity alongside traditional safety and electromagnetic compatibility (EMC) risks, reflecting the evolving landscape of product certification and regulation.

Where is a CB certificate accepted?

A CB certificate is accepted in over 50 countries that participate in the CB Scheme. This international product certification initiative facilitates international trade by enabling the recognition of CB Certificates for national approvals, providing manufacturers with streamlined access to multiple markets. More information: https://www.iecee.org/members/member-bodies

What type of products can be CB-certified by QIMA?

  1. Consumer IoT devices, covered by ETSI 303 645 standards. These are internet-connected devices that any person can have at home nowadays. This standard covers consumer IoT devices that are connected to network infrastructure and their interactions with associated services, like smart tv’s, CCTV cameras, speakers, connected home automation devices, IoT gateways, base stations, HUBs, wearable health trackers, baby monitors, IoMT devices, connected home appliances like smart refrigerators and washing machines, or connected alarm systems, door locks, smoke detectors, among many others.

  2. Industrial automation and control system components, covered by ISA/IEC 62443-4-1 and ISA/IEC 62443-4-2. ISA/IEC 62443-4-1 standard defines the safe development life cycle for products used for IACS. This includes, for example, industrial automation devices, controllers, sensors, and related software and systems. ISA/IEC 62443-4-2 standard specifies technical security requirements for IACS components, in particular for embedded devices, network components, host components, and software applications. This standard deals in detail with the challenges and requirements arising in the field of industrial control systems, industrial networks, and their protection.

How long does it take to get your product CB certified based on ETSI 303 645 or based on ISA/IEC 62443-4-2?

The evaluation according to ETSI EN 303 645 takes up to 3 weeks, but this requires thorough preparation on the part of the manufacturer as well. To do this, we recommend that you download our free infographic, which presents the evaluation process according to ETSI standards.

The length of the evaluation according to ISA/IEC 62443-4-1 and 4-2 may varydepending on the complexity of the product, the evaluation conditions, and other factors. However, these assessments can usually take several months to several years. The process includes the preparation of product documentation, evaluation activities, tests, possible risk assessment, and finalization. It is important to note that the duration of the evaluation can also be influenced by how prepared the manufacturers and developers are for the evaluation process, as well as how well the product documentation and test results meet the standards. Therefore, we recommend that you ask for a consultation from our colleague or view our service page to obtain more information.

After a successful evaluation, the certification procedure takes 1-2 weeks, the certificate will be published on the IECEE website.