Navigate Security Requirements with Greater Confidence

Our laboratories hold accreditation, authorization, and approval across a broad range of recognized security programs, and perform independent evaluations against each scheme's own requirements. Security certification programs differ in scope, assurance level, evidence requirements, and approval process, and selecting the right route early reduces unexpected findings, repeated testing, and delays during formal evaluation.

Keysight works with manufacturers, semiconductor vendors, software providers, payment companies, automotive organizations, and connected-device developers. Depending on the applicable scheme, our involvement can range from readiness assessment and documentation review through to formal security evaluation, vulnerability analysis, reporting, and coordination with the relevant certification or approval body.

Regulatory and Cross-Market Evaluation

illustration of an embedded device

Certify hardware, software, secure components, operating systems, cryptographic libraries, and complete products against Common Criteria or EUCC requirements — regardless of market or product category.

As a licensed ITSEF, Keysight supports certification planning, design review, vulnerability analysis, evidence preparation, site readiness and site audits, and formal evaluation across applicable Evaluation Assurance Levels and protection profiles.

Prepare products with digital elements for the security and lifecycle requirements of the EU Cyber Resilience Act.

Keysight can support product classification, risk assessment, technical documentation, vulnerability handling, security testing, evidence generation, and planning for the applicable conformity-assessment route.

Connected Devices, Chips and Infrastructure

secure embedded device

Evaluate IoT platforms and components against the Security Evaluation Standard for IoT Platforms. SESIP provides tiered security assurance based on Common Criteria principles and helps vendors demonstrate that their platforms provide appropriate protection for their intended use cases.

Keysight supports preparation, pre-certification assessment, formal evaluation, and the technical evidence required for the selected SESIP assurance level.

Demonstrate the security of IoT chips, software platforms, and devices through the PSA Certified framework.

Keysight supports product scoping, readiness assessment, formal evaluation, vulnerability analysis, physical attack testing where applicable, and delivery of the Evaluation Technical Report used by the PSA Certified program.

Evaluate trusted execution environments and related technologies against GlobalPlatform security and interoperability requirements.

Keysight can assess how sensitive data and functions are isolated, stored, and processed within the trusted environment and support both GlobalPlatform-compliant and tailored TEE implementations.

Prepare data-center hardware and firmware for review under the Open Compute Project Security Appraisal Framework and Enablement program.

As an approved OCP Security Review Provider, Keysight performs security conformance reviews covering areas such as secure boot, firmware protection, cryptography, secrets handling, update mechanisms, and platform security. The resulting report supports submission to the OCP S.A.F.E. program.

Digital Identity and Public Sector

an employee working with software

Bring trust services, signature creation devices and identity products in line with the security requirements underpinning the EU eIDAS regulation.

Our licensed ITSEF works with vendors and trust service providers on protection profile selection, evidence preparation, site audits, and formal evaluation ahead of certification and notification.

Qualify products for the Japanese Public Key Infrastructure scheme governing the individual authentication services on Japan's national ID card.

Keysight's evaluators assist card and chipset vendors, secure element providers, and application developers with scheme interpretation, evidence preparation, and evaluation against the applicable requirements.

Evaluate products intended for use in sensitive Dutch government environments against Baseline Security Product Assessment requirements.

Keysight supports pre-certification preparation, tailored security analysis, formal evaluation activities where applicable, and the identification of issues that could affect successful BSPA approval.

Payments, Credentials and Ticketing

mobile phone held in hand

Prepare and evaluate mobile payment acceptance products under the PCI MPoC program.

Keysight supports solution scoping, readiness review, documentation, security evaluation, implementation-change assessments, delta evaluations, and annual checkpoints throughout the MPoC product lifecycle.

Evaluate digital wallets and payment service provider solutions against European Payments Initiative security requirements.

Keysight supports standalone wallets, wallet applications embedded within PSP solutions, and PSP evaluations covering both consumer and acceptor environments.

Evaluate integrated circuits, platforms, cryptographic libraries, system-on-chip solutions, embedded secure elements, and integrated secure elements against EMVCo security requirements.

Keysight combines payment-security expertise with advanced chip-level testing to support product approval by EMVCo and participating payment schemes.

Evaluate software-based mobile payment components and complete solutions under the EMVCo SBMP program.

Supported technologies include host card emulation, software protection tools, trusted execution environments, mobile payment SDKs, consumer device cardholder verification methods, and OEM payment solutions.

Evaluate eSIM devices and components against applicable GSMA security assurance requirements.

Keysight performs Common Criteria-based assessments addressing the security objectives defined in relevant GSMA protection profiles for consumer and machine-to-machine products.

Evaluate digital-key components and implementations against Car Connectivity Consortium security requirements.

Keysight supports automotive manufacturers, semiconductor vendors, mobile-device providers, and technology suppliers in validating secure key provisioning, storage, sharing, access management, and related digital-key functions.

Take FeliCa-based products through the security evaluation required under the FeliCa Approved Security Technology scheme.

Keysight supports chipset vendors, secure element and eSE providers, and handset manufacturers in assessing cryptographic implementation, key management and provisioning, and resistance to physical and side-channel attack, then reports findings against the scheme requirements.

Demonstrate that products implementing MIFARE technology meet the security requirements of the MIFARE certification programme.

Keysight supports semiconductor vendors, secure element providers, and transit and access-control product manufacturers in evaluating cryptographic implementation, key storage and diversification, and resistance to invasive, fault and side-channel attack, with reporting aligned to the certification submission.

Media and Content Protection

connected digital elements

Evaluate devices and embedded platforms against the PlayReady compliance and robustness requirements.

Keysight assesses the trusted execution environment, secure boot and key provisioning, hardware key ladder, secure media path, and output protection enforcement, then reports gaps against the target security level with prioritised remediation.

Evaluate devices and embedded platforms against the Widevine compliance and robustness requirements.

Keysight reviews the OEMCrypto implementation, keybox provisioning and factory practice, TEE isolation, secure video path, and output protection enforcement, then reports gaps with prioritised remediation.

ChinaDRM is the national content protection scheme for the Chinese market, governed by ChinaDRM Lab. Certification is a practical prerequisite for devices intended to carry high-value domestic content, and requirements extend to chipsets as well as finished terminals.

Keysight assesses the hardware root of trust, trusted execution environment, cryptographic implementation and key management, secure media path, and usage and output restrictions, then reports gaps with prioritised remediation and support in preparing certification evidence.

See What Our Customers Are Saying

Want help or have questions?