The Role of Third-party Evaluation in IoT Security Explained

Skip to content

The security evaluation labs that contributed to this article are all founding members of PSA Certified.

Before we invest in a new car, spend on home appliances or even book a holiday, we often turn to a trusted source for the latest information and advice. We do not always accept the claims a company makes about its products. So, if we are searching for Internet of Things (IoT) devices, how do we make sure they meet our expectations, and more specifically, ensure they are secure?

To help ease the increasing concern about the security of connected devices and their data, IoT product developers are turning to independent experts. That is, accredited security laboratories that can assess the security features built into a product, and check they align with industry best practice, as well as new and emerging laws, regulations and baseline requirements.

This third-party evaluation and certification process removes any doubt about the statements being made by firms, as Laurens Van Oijen, Project Specialist at UL, explains: “The value of third-party certification lies in the integrity of the outcome of an evaluation. A third-party lab takes an independent, and therefore, purely objective approach to validating whether a product conforms to and complies with the standard or specification it is being measured against.” 

That is good news for businesses and consumers who are trying to navigate the complexities of IoT security. For anyone involved in the development of a device, an external perspective also adds significant value to the end result. That includes:

Third party evaluation has multiple benefits for IoT security

Getting Started

PSA Certified, the industry-backed security framework and assurance scheme, includes a cost-effective and efficient independent evaluation process for system-on-chips, devices and operating systems. Our third-party evaluation labs are based in a number of locations across Europe, North America and Asia Pacific. Their approach to security begins at the silicon level, analyzing the Root of Trust, and builds up through an analysis of best practice security principles for the system software and endpoint device. This helps to ensure security is built into the hardware of the product and all security functions can take place on a trusted foundation.

PSA Certified has four evaluation labs offering IoT security certification

There are three levels of evaluation for increasing robustness.

PSA Certified Level 1 is based on a security questionnaire that is used to confirm that basic security principles have been applied. A third-party lab evaluates the implementation to ensure the security principles have been met.

PSA Certified Level 2 involvesan independent, lab-based evaluation that is designed to ensure the chip’s PSA Root of Trust security component can protect against software attacks. This includes penetration testing.

PSA Certified Level 3 isa third-party lab-based evaluation that provides evidence of protection against substantial hardware and software attacks. Again, penetration testing will be performed at this stage.

Certification is the final step in the process and helps you to demonstrate to your customers that the product has been designed with security at its heart.

“If you have a report from an accredited laboratory, you can obtain security certification for your products, going beyond the claim ‘trust me, my product is secure’ and you are helping the market focus the conversation about security on specifics,” says Thomas Jorgensen, CCO of SGS Brightsight. Thomas goes on to say, “Developers can also use the security certificate as a differentiator or communication tool, and even to evidence the inclusion of premium security features.”

In summary, the benefits of engaging an independent security evaluation lab include:

In addition to third party evaluation and certification from trusted labs with an extensive footprint, PSA Certified provides:

Learn more about the security labs mentioned above and our other founders.