Skip to content
ReadinessNavigator

Services · Coming soon

SVV as a service

Planned: security verification and validation testing for your product, covering the four testing activities SVV-1 to SVV-4 with the tester independence SVV-5 requires, to support the regular security testing required by CRA Annex I Part II.

Beyond mapping SVV: running it and handing you the evidence

Security verification and validation turns security requirements and threat mitigations into tests against the product. The planned service will cover SVV-1 to SVV-4 and provide the tester independence SVV-5 requires, documented as part of the evidence. Before testing begins, we will agree the product scope, interfaces, test methods and any specialist tooling.

The four testing activities

  • SVV-1

    Security requirements testing

    The service will test each applicable security requirement and record the result, creating traceability from requirement to test and evidence.

  • SVV-2

    Threat mitigation testing

    The service will exercise the mitigations identified in the threat model to confirm that they work as intended and record the result.

  • SVV-3

    Vulnerability testing

    The service will test for vulnerabilities before release through malformed-input and fuzz testing of agreed external interfaces and protocols, attack-surface analysis, known-vulnerability scanning of the product as shipped, software composition analysis of binary components, and runtime testing for memory and resource-management flaws. Fuzz testing of industrial or proprietary protocols will be scoped per product as a bespoke engagement.

  • SVV-4

    Penetration testing

    The service will perform adversarial testing and produce a penetration test report traceable to the security requirements under test.

An evidence trail an auditor can follow

The service will record the agreed scope, test method, environment, result, findings, remediation status, and tester and reviewer for each activity. This gives an auditor a traceable path from the security requirement to the test evidence.

Independence through staffing and review

SVV-5 requires testing to be independent of the developers whose work is being tested. Our testers will perform the work independently of the customer’s development team, and the evidence will identify who planned, performed and reviewed each test.

Cloud-backed products

Where the CRA applies, a remote data processing solution whose absence would prevent the product from performing one of its functions forms part of the product scope. Its exposed services and configuration will therefore be included in the attack-surface analysis.

Related secure-development work

Static code analysis and secret scanning can be included as secure implementation review activities under SI-1. Continuous post-release monitoring will be handled separately under defect management and CRA vulnerability handling.

What it is not

  • The service does not provide an accredited test-laboratory report or certification.
  • It does not establish CRA conformity.

Get in touch

Security verification and penetration testing — coming soon

You need IEC 62443-4-1 SVV evidence — security requirements, threat mitigation, vulnerability and penetration testing, traceable to your requirements. This service is launching soon; ask us about early access.

We reply within two working days.

Full contact details
consulting@readinessnavigator.com
Book a 30-minute call

Opens our scheduling page in a new tab — pick a slot that suits you.

Worth including in a first message

  • What you build, and how many product lines are in scope.
  • Which regulations, standards or customer requirements are in view.
  • What is driving the timeline — customer requirement, audit, or CRA deadline.
  • Which package or engagement you are interested in.

Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.