Skip to content

CSC - discovered, explained

CyberSecurity Certified (CSC)

Security of smart home devices & consumer IoTs

There are still major security concerns about smart home devices. With the CyberSecurity Certified (CSC) certification mark, manufacturers of smart home devices and consumer IoT products can counter this problem and objectively demonstrate the implementation of security measures.

What is CyberSecurity Certified (CSC)?

"CyberSecurity Certified (CSC)" is a certification scheme that manufacturers can use to increase, continuously improve and objectively prove the security of their CIoT products.

The scheme is based on recognised norms and standards, such as ETSI EN 303 645, and contains 3 possible test levels that differ in terms of the scope and depth of the test. Both IT security and functional safety requirements for products are taken into account.

The test levels according to CyberSecurity Certified

Basic

Secure development and secure operation
Review of internal processes

Substantial

Basic requirements

+ Penetration tests
+ Cloud verification
+ Supply chain verification

High

Substantial requirements

+ Additional TÜVIT penetration test
+ In-depth testing of the solution
+ (additional test criteria)
Safety through test marks

Special features of CyberSecurity Certified (CSC)

  • Based on internationally recognised norms and standards (including ETSI EN 303 645)
  • Focuses both on the IT security of CIoT products and on functional device security (safety)
  • Also includes processes within the company in the test
  • Helps to uncover existing security deficiencies and minimise IT risks

We will support you – no matter what

Get started at last!

We advise you


TÜV NORD IT Secure Communication I Berlin
Goal achieved?

We check it


TÜV Information Technology I Essen

Frequently Asked Questions (FAQ)

What you need to know about CSC

On the one hand, the audit focuses on the CIoT product itself, which is analysed with regard to both IT security aspects and its functional security. However, the underlying business processes, data protection aspects and other services, such as the connection to a cloud, are also examined on the basis of internationally recognised standards. Depending on the test level, penetration tests are also carried out.

Testing and certification are based on internationally recognised norms and standards, such as ETSI EN 303 645, IEC 62443, ISO 27001 or the C5 catalogue.

As the CSC certification is based on ETSI EN 303 645, among others, manufacturers also cover the requirements of the European Cybersecurity Act (CSA) with this certification.

The project duration within the scope of a CSC certification can be between approx. 1 month and approx. 3 months.

Consumers in Germany tend to take a critical view of smart homes. This is also confirmed by a Forsa survey conducted on behalf of the TÜV association, according to which 2 out of 3 respondents (66 per cent) believe that there is a very high risk of smart devices becoming the target of a hacker attack. 68 per cent also fear that smart devices could misuse their personal data.

These security concerns mean that sales figures for smart home devices and CIoT products are currently still well below expectations and the market is only developing slowly.

By having your CIoT product tested and certified in accordance with the new"CyberSecurity Certified (CSC)" cybersecurity scheme, you remove existing uncertainties for customers and objectively prove the IT security of your product. This benefits not only you as a manufacturer, but also end users. This is because labelling a CIoT product with an independent test mark for smart home devices builds trust, provides guidance and has a positive effect on upcoming purchasing decisions.