iThome: CRA Countdown — Secure Vectors Surveillance Allies with Applus+ for One-Stop EN 18031 & CRA Testing in Taiwan
Secure Vectors Surveillance signs an alliance with Applus+ Laboratories, becoming a recognized security lab offering full EN 18031 testing and a one-stop CRA compliance path in Taiwan. (iThome coverage)

Coverage by iThome
With connected devices multiplying worldwide, cybersecurity has risen from an operations concern to a condition of market entry. The EU Cyber Resilience Act (CRA) took effect in December 2024, and together with the amended Radio Equipment Directive (RED) it is rewriting the export rules for Products with Digital Elements (PDEs). The change is more than a standards update — it is a test of the industry's compliance capability: security has become the foundation of trust, and only manufacturers able to manage global security compliance continuously will keep their footing.
Against this backdrop, Secure Vectors Surveillance Inc. (SV Surveillance) has signed an alliance agreement with Applus+ Laboratories, one of the world's leading testing, inspection and certification (TIC) groups, becoming an alliance partner and recognized security laboratory — building a “local testing × global certification” compliance chain.
SV Surveillance is a subsidiary of Secure Vectors Information Technologies Inc., which has specialized in payment security certification and PCI DSS compliance since 2010 and operates one of the few ISO 17025-accredited security laboratories — able to complete the full EU EN 18031 series (network resilience, privacy, fraud prevention) in Taiwan, extending to IoT and medical device testing. Applus+ Laboratories traces its origins to the LAGI laboratory founded in 1907; headquartered in Barcelona, it employs over 30,000 people across more than 65 countries, holds dual MDR Notified Body designations (NB 2764 & NB 3121), has more than 20 years of Common Criteria testing experience, and is actively applying for CRA Notified Body status. The alliance targets the EN 18031 testing mandatory since August 2025, FDA and MDR certification, and the CRA taking full effect in December 2027 — letting Taiwanese manufacturers test locally while connecting to European and US standards.
CRA rewrites export rules for digital products; supply-chain compliance stakes rise
Josep Prat, General Manager for China at Applus+ Laboratories, notes that the CRA is the world's first mandatory law aimed at Products with Digital Elements: any product whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to another device or network falls in scope — covering virtually every connected product with firmware, a microprocessor or software logic (Wi-Fi, Bluetooth and so on). Products are classified by risk as default, important or critical: the default class may self-declare conformity, the important class may require Notified Body review depending on sub-category and the state of harmonized standards, and the critical class faces the most demanding verification. From smart meters to consumer electronics, compliance must be re-examined. Vulnerability reporting obligations begin in September 2026, and when the CRA takes full effect in December 2027, every digital product sold into the EU must meet its security requirements or risk being stopped at customs.
Vincent Huang, CEO of SV Surveillance, adds that the price of non-compliance is designed to deter: breaching the CRA's essential cybersecurity requirements carries fines of up to €15 million or 2.5% of global annual revenue, whichever is higher. For ODM/OEM manufacturers, though, the gravest risk is not the fine — it is being dropped from a brand's supply chain. Brands, as the bearers of legal responsibility, have begun demanding software bills of materials (SBOMs) and test evidence from suppliers, making these documents the ticket into the European market.
Security governance is dynamic by nature: the old “certify once” mindset no longer works. Manufacturers must shift from selling products outright to whole-lifecycle governance — post-market monitoring, vulnerability management, simultaneous reporting through the EU Single Reporting Platform to the designated national CSIRT and ENISA, and free security updates for at least five years or the product's lifetime. A supply chain can involve hundreds of vendors, yet the brand bears full legal responsibility even when a vulnerability originates with a single supplier — which is why the two companies are building a transparent governance framework to raise supply-chain compliance efficiency.
Smart healthcare faces a dual compliance challenge; lifecycle governance is indispensable
Josep Prat points out that although the CRA's harmonized standards are still in draft, they overlap heavily with EN 18031 — industry estimates put the overlap at a significant proportion. Investing now is not wasted; it lays the groundwork for the CRA. The EU has confirmed the CRA's security provisions will absorb and replace the RED Delegated Act, and certification typically takes 12 to 18 months. Manufacturers who wait until the eve of mandatory enforcement in 2027 will meet a predictable bottleneck: Notified Body capacity will not suffice.
Vincent Huang stresses that for Taiwanese ICT companies moving into smart healthcare the challenge is more complex. A product classified as a medical device must comply with the EU Medical Device Regulation (MDR), whose Annex I §17 extends security requirements to post-market vulnerability monitoring — requiring an SBOM, threat model and penetration test reports. General consumer or industrial ICT devices with wireless functions must instead meet RED 3.3 and its harmonized standard EN 18031. The diversity of smart-medical devices and services raises the review bar beyond hardware to apps, cloud platforms and wireless transmission. The biggest obstacle for Taiwanese manufacturers is integrating the ISO 13485 quality management system, the IEC 62304 software lifecycle and IEC 81001-5-1 security requirements. SV Surveillance provides the review and testing capability, and with Applus+ Laboratories' dual-NB advantage the pair can offer a coherent one-stop solution.
Across the Pacific, the US bar is just as high. Since Section 524B took effect in 2023, the FDA has had explicit statutory power to Refuse to Accept (RTA) 510(k) submissions for insufficient cybersecurity documentation. Security requirements across the US, EU and China are converging — which is why SV Surveillance and Applus+ Laboratories promote “one set of evidence, three submissions”: one SBOM, one penetration test report and one threat model can serve the EU MDR, US FDA and China NMPA simultaneously. Each regulator keeps its own review specifics, but a shared technical core greatly simplifies cross-border compliance.
Security maturity becomes a new competitive dimension; training gets ahead of the curve
Josep Prat notes that meeting EU standards puts a company on the commanding heights of the market, since most major markets reference the EU framework. Early compliers turn compliance into competitive advantage: suppliers of digital products must prove to brands that they can maintain and take responsibility for their products.
SV Surveillance and Applus+ Laboratories propose a three-layer strategy — regulatory Awareness, practical Capability and an industry Ecosystem. The laboratory's standardized, automated tooling supports multi-product certification for a single manufacturer. Vincent Huang advises companies to run a gap assessment first, establish a coordinated vulnerability disclosure (CVD) policy, and build 24-hour early-warning and 72-hour incident-notification capability before the reporting obligations formally begin.
The partners have also launched a joint training program: from July, sessions on the latest EU CRA developments and MDR security hands-on workshops, with ISO 13485 internal auditor training planned — helping companies build internal teams and reduce external dependency. Through the alliance, Taiwanese manufacturers can obtain security test reports recognized by a European Notified Body locally, saving certification time and cost.
The alliance also has broader strategic meaning: the CRA and EN 18031 are increasingly referenced beyond the EU — by the US FDA, the UK's PSTI and Singapore's CLS. Complying early means aligning with multiple jurisdictions at once. For brands, choosing suppliers that have completed EN 18031 testing lowers legal risk and raises market trust.
Taiwan's competitiveness has historically come from specs, price and delivery; over the next decade, security maturity must join that core. Waiting for standards to be finalized before acting is a high-risk strategy — manufacturers should focus on product innovation and leave compliance to internationally authorized experts. As security and governance become consensus, this transformation will decide who wins in exports, and Taiwan's supply chain can rebuild global trust on more transparent foundations.
The SV Surveillance website offers a CRA compliance self-check, an EN 18031 gap-assessment booking form and related training courses — learn more at www.securevectorlab.com. For training sessions and registration, visit the CRA, MDR & ISO 13485 training page; for an in-depth look at the CRA rules, see CRA Countdown: Compliance Guide for Taiwan ICT Manufacturers.
Original coverage: iThome