Secure & comply
Standards compliance for embedded products
Harmonised and industry standards turn regulations into concrete technical requirements. We map them to your device, implement what is missing in firmware and hardware, and prepare the evidence that test laboratories and notified bodies ask for.
· by BCF Embedded engineering team
Standards we work with
Which standards apply depends on the product, its market and its intended use.
EN 18031 (RED)
Cybersecurity requirements of the Radio Equipment Directive for wireless devices, applicable in the EU since 1 August 2025.
IEC 62443-4-1 / 4-2
Secure development lifecycle and technical security requirements for components of industrial control systems.
ETSI EN 303 645
Baseline security for consumer IoT: no default passwords, a defined update policy and vulnerability disclosure.
IEC 62304 and IEC 81001-5-1
Software lifecycle and security activities for medical device software - see medical.
IACS UR E26 / E27
Cyber resilience of ships and on-board equipment, required for ships contracted since July 2024 - see maritime.
IEC 61508
Functional safety of electronic systems: software and hardware developed to a target safety integrity level.
How we prepare a product
- 01
Scope
Standards and requirements that apply, agreed with your compliance advisers or test laboratory.
- 02
Gap analysis
Each requirement checked against the architecture, firmware, hardware and processes.
- 03
Implementation
Missing measures built into the product - from secure boot to development process changes.
- 04
Evidence
Traceability, test reports and technical documentation ready for the assessment.
Evidence that holds up in an assessment
Most of the effort in a compliance project is showing that a requirement is met, not only meeting it.
- Traceability from each clause of the standard to design, code and tests.
- Threat models and risk assessments kept up to date with the product.
- Test reports from our lab, including security and robustness tests.
- SBOM and vulnerability-handling records that also serve the Cyber Resilience Act.
One set of measures, several standards
Security standards overlap: secure updates, key storage, access control and vulnerability handling appear in EN 18031, IEC 62443 and ETSI EN 303 645 alike. Harmonised standards for the CRA are being published in stages and build on the same ground, so measures implemented now usually carry over. Many of them are covered in secure boot and OTA.
What we do and what we don't
We do
- Map the requirements of a standard to your product
- Implement the technical measures in firmware and hardware
- Prepare technical documentation and test evidence
- Support you during laboratory testing and fix the findings
We don't
- Provide legal advice on which regulations apply
- Act as a test laboratory or notified body
- Issue certificates or declarations of conformity
FAQ
Discuss your project
Describe your device and goal. An engineer replies within one business day.