
Founded in 2013, CCLab Ltd. is an agile cybersecurity laboratory specializing in Common Criteria evaluations and consultations. Our cybersecurity lab has been accredited by OCSI (Certification Body of the Italian Scheme) since 2015 and BSI (Certification Body of the German Scheme) since 2022.
We have successfully executed numerous projects, with the scale and quality of evaluations consistently increasing each year.
In 2023 CClab joined the QIMA group, a global Testing, Inspection, and Certification player, operating in more than 100 countries from 60 offices and labs.
Navigate the complex landscape of cybersecurity certifications
with expert guidance
ISO 15408 Common Criteria Compliance and Certification up to EAL4+ or EAL5.
Professional support to prepare for a successful Common Criteria evaluation saves you cost and effort.
Comply with ETSI EN 303 645 standards, providing guidelines and expertise for the security of consumer Internet of Things (IoT) devices.
Data security solutions for smart metering system components with independent verification by out certified laboratory.
Learn more about the Radio Equipment Directive (RED) specifying cybersecurity requirements for radio equipment sold within the EU.
How to get your connected device compliant with the upcoming cybersecurity regulation in the UK, the Product Security and Telecommunications Infrastructure (PSTI) Act.
Cybersecurity evaluation and certification of industrial automation and control system based on ISA/IEC 62443-4-1 and 62443-4-2 standards.
Get your IoT, IIoT device certified after successful evaluation and testing based on ETSI 3030 645 or IEC 62443-4-1, 62443-4-2.
What does it mean?

9
min reading time
The August 1, 2025 deadline for the Radio Equipment Directive (RED) Delegated Act has passed. You have likely spent the last year scrambling to test devices, freeze software, and secure approvals. But just as the dust settles, a new challenge looms: the Cyber Resilience Act (CRA) is now getting in force, with full application expected by December 11, 2027. The immediate worry for many manufacturers is simple: Was the investment for RED wasted? Is the work done for the 2025 deadline just a temporary fix destined to be withdrawn when the CRA takes over? The answer is no, if a strategic approach is taken. The two regulations are "in sync," and the work done for RED-DA is the essential foundation for future CRA compliance.

9
min reading time
The European Union has launched an ambitious digital transformation initiative centered on digital identity and trust services. Building upon the foundation of the original eIDAS Regulation (Regulation (EU) No. 910/2014), the updated eIDAS 2.0 framework (Regulation (EU) 2024/1183) establishes a European Digital Identity (EUDI) Framework that requires all Member States to make interoperable EU Digital Identity Wallets available to citizens and businesses by 2026. This effort aims to create consistency in legal certainty, interoperability, and data protection across borders, strengthening trust in Europe’s digital landscape.

6
min reading time
Your product is days from launch. A last-minute test exposes an OTA configuration path that 5G network slicing can abuse, and now your file is blocked. In the 5G era, small gaps escalate fast. The fix isn’t one more patch; it’s designing RED cybersecurity into the way your device behaves on modern networks, before certification even starts.
Join our captivating cybersecurity events to enhance your knowledge and engage with our team of experts.
.png)
CCLab is excited to be part of the 24th International Common Criteria Conference taking place from 21st to 23rd of October 2025 at the Central Park Hotel in Songdo, Korea.

Internetkapcsolattal rendelkező rádióberendezésekkel vagy vezeték nélküli IoT eszközökkel dolgozik, és szeretné megtudni, hogyan felelhet meg a RED irányelv és a kiberbiztonsági harmonizált szabványok követelményeinek?