Our Route to RED Cyber Compliance
To secure compliance for our RS26x series (in this case, in particular, the RS261 which operates in EU LoRaWAN frequencies), we worked with a third-party partner ourselves. There are two phases to securing RED compliance:
- Assessment: Initial phase where Ezurio documents and describes our security architecture and available customer-facing documents to ensure that the security mechanisms are functional and as-described, as well as fully clear and usable by the end user. This is coordinated with the assessment team within a third-party partner’s test house, and results in an Assessment Report.
- Certification: After the Assessment Report is generated, it’s provided to the certification team within the third-party partner’s test house. This team is deliberately kept separate and with only limited contact with the assessment team. This is to ensure a blind verification of the assessment, an unbiased approach to validate the initial findings of the assessment report.
As with any first, Ezurio was able to take advantage of the process for some valuable lessons learned that further aid our continued approach to RED Cyber compliance. Our work with the assessment team gave us insight into the documentation requirements that must be presented to the end user. These best practices go forward with us into future assessments.
Additionally, our RS26x needed a gateway to interface with for the assessment, and we provided our RG1xx LoRaWAN gateway for this portion of the process. This furthered our efforts by providing a natural introduction to this gateway to our compliance partners, and will further speed our future development efforts in certification of the RG1xx, as well as to provide a further insight into our overall security architecture and approach.
Along with all of this, we provided the full suite of software and hardware tools and exposed all features (such as data encryption, firmware updating, and more) to validate each and every security-critical process for inspection and approval. This in-depth analysis will help with future Ezurio assessments, as it’s all part of our overall approach that applies to past and future packaged products we provide.
Once assessed, the certification team was able to take all of these same tools and hardware elements to validate the results of the assessment report. They reviewed and validated hardware and software functionality, product documentation, product labeling, BOMs, schematics, and more in order to ensure that our RS261 met high standards. Another element here is traceability: those product labels must be detailed and accurate in identifying the product’s compliance to the end user.