Skip to content

Product cybersecurity: obligation, evaluation, label

Guide, understanding product cybersecurity

Three unlike things are called cybersecurity certification, and a product usually needs one from more than one of them. Confusing them is expensive in a specific way: teams buy an evaluation believing it discharges a legal duty, or assume a lawful marking implies a security assessment. Neither follows. This page separates the three, and says what each one is actually evidence of.

Legal obligations decide whether the product may be sold. The Cyber Resilience Act is the broad one in the European Union, and article 3(3) of the 2014/53/EU covers radio equipment. Failing these is not a commercial setback; the product cannot lawfully be placed on the market.

Evaluation methodologies grade how deeply a product was examined, and by whom. Common Criteria, SESIP and PSA Certified belong here, as do FIPS 140-3 for cryptographic modules and CSPN in France. The output is a certificate describing what was tested and to what depth.

Baselines and labels are checklists a product can conform to, usually voluntarily. EN 303 645 for consumer IoT, NISTIR 8425 and the US Cyber Trust Mark built on it, and Cyber Essentials in the UK. They set a floor and are readable by non-specialists, which is the point.

AnswersIssued byFailing means
ObligationMay this be sold?The law, via a conformity routeCannot be placed on the market
EvaluationHow deeply was it examined?An accredited laboratoryNo certificate, contract may be lost
Baseline or labelDoes it meet this floor?Often self-declaredNo logo, no listing

An evaluation certificate does not discharge a legal obligation. It is evidence about the product's security properties. A legal obligation is a duty owed to a regulator, discharged through the conformity assessment route that the law itself names. Evidence from an evaluation can support that route, sometimes substantially, but the duty is met only when the law's own procedure has been followed.

The reverse is equally untrue. A product lawfully carrying a marking has not thereby been evaluated to any assurance level. The marking says a procedure was followed. It says nothing about how hard anyone tried to break the device.

The clearest illustration is EN 303 645. It is a voluntary ETSI standard and it is not listed as a harmonised standard under article 3(3) of the RED. Conforming to it is useful and widely asked for commercially, and it is a reasonable basis for a security argument. It does not by itself confer the presumption of conformity that a harmonised standard gives. A team that treats it as the route to RED compliance has bought a good baseline and not the legal outcome they wanted.

A level describes how hard someone tried to break the product, and with what access. It is not a score for how secure the product is.

Common Criteria uses Evaluation Assurance Levels; the SOG-IS arrangement in Europe recognised certificates up to EAL 7 for the technical domains it covered. SESIP and PSA Certified use shorter ladders aimed at IoT silicon and platforms, and they map onto one another: PSA level 2 corresponds in practice to SESIP level 3, a black-box penetration test, and PSA level 3 to SESIP level 4 or 5 depending on scope.

Two consequences follow. A high level on a narrow target of evaluation can be worth less than a modest level on the whole product, because the level says nothing about what was in scope. And levels are not comparable across families without a mapping like the one above; an EAL and a PSA level are not the same currency.

The Cyber Resilience Act is the one most manufacturers will meet first, and its obligations do not all start together. The reporting duties for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, ahead of the main body of the regulation. The CRA guide sets out the full sequence.

For radio products, article 3(3) of the RED is the other gate, and it interacts with the CRA rather than duplicating it. For industrial control systems, IEC 62443 is the reference framework, and for anything sold to the US defence supply chain, CMMC applies on top.

  1. Legal obligations first. They gate market access and their dates are set by instruments that will not move for your schedule.
  2. Then contractual requirements. For silicon and platforms that usually means an evaluation scheme; for consumer products, a baseline or label.
  3. Evaluations are the long pole. They need a stable design, a laboratory booking and a defined target of evaluation. Starting one against a moving product wastes the fee.
  4. Labels and self-declared baselines last. Cheapest, fastest, and they depend on the rest being settled.
  • Three different things share the name: legal obligations, evaluation methodologies, voluntary baselines and labels.
  • An evaluation does not discharge a legal duty, and a lawful marking does not imply an evaluation.
  • EN 303 645 is voluntary and not harmonised under RED article 3(3), which is the standing example of why that matters.
  • An assurance level describes evaluation depth, not security, and levels do not compare across families without a mapping.
  • Obligations first, evaluations early because they are slow, labels last.

Sources & references

  1. Regulation (EU) 2024/2847, the Cyber Resilience Act , EUR-Lex eur-lex.europa.eu/eli/reg/2024/2847/oj
  2. Directive 2014/53/EU on radio equipment (RED) , EUR-Lex eur-lex.europa.eu/eli/dir/2014/53/oj
  3. NIST IR 8425, profile of the IoT core baseline for consumer IoT products , NIST csrc.nist.gov/pubs/ir/8425/final
  4. NIST SP 800-213, IoT device cybersecurity guidance for the federal government , NIST csrc.nist.gov/pubs/sp/800/213/final

Frequently asked questions

Why are there so many cybersecurity certifications?
Because three unlike things share the name. Some are legal obligations that decide whether a product may be sold at all, such as the Cyber Resilience Act in the European Union or article 3(3) of the Radio Equipment Directive. Some are evaluation methodologies, which grade how deeply a product's security was examined and by whom: Common Criteria, SESIP, PSA Certified. And some are voluntary baselines and labels, a checklist a product can declare conformity with, such as ETSI EN 303 645 or the US Cyber Trust Mark. They answer different questions, so a product often needs one from more than one group, and holding one of them says nothing about the others.
Does passing an evaluation scheme satisfy a legal obligation?
Not by itself, and assuming otherwise is the most expensive mistake in this area. An evaluation certificate is evidence about a product's security properties, produced by a laboratory against a methodology. A legal obligation is a duty owed to a regulator, discharged through the conformity assessment route that the law itself names. Evidence from an evaluation can support that route, sometimes substantially, but the obligation is only met when the law's own procedure has been followed. The reverse also holds: a product that lawfully carries a marking has not thereby been evaluated to any assurance level.
What do assurance levels actually mean?
How hard someone tried to break it, and with what access. Common Criteria uses Evaluation Assurance Levels, and the SOG-IS arrangement in Europe recognised certificates up to EAL 7 for the technical domains it covered. SESIP and PSA Certified use their own shorter ladders aimed at IoT silicon and platforms, and they map onto each other: PSA level 2 corresponds in practice to SESIP level 3, a black-box penetration test, and PSA level 3 to SESIP level 4 or 5 depending on scope. A level is a statement about the depth of the evaluation, not a score for how secure the product is.
Is EN 303 645 what the Radio Equipment Directive requires?
No, and this is the clearest example of why the three groups must not be confused. EN 303 645 is a voluntary standard published by ETSI, and it is not listed as a harmonised standard under article 3(3) of the RED. Conforming to it is useful, widely asked for commercially, and a reasonable basis for a security argument, but it does not by itself give the presumption of conformity that a harmonised standard confers. A manufacturer who treats it as the route to compliance has bought a good baseline and not the legal outcome they intended.
In what order should these be tackled?
Legal obligations first, because they gate market access and their dates are fixed by instruments that will not move for your schedule. Then whatever a customer or ecosystem contractually requires, which for silicon and platforms usually means an evaluation scheme, and for consumer products usually means a baseline or label. Evaluations are the long pole: they need a stable design, a laboratory booking and a defined target of evaluation, so starting one against a moving product wastes the fee. Labels and self-declared baselines are the cheapest and can run last.