Skip to content
TeligenciaLabs

ISO/IEC 17025TUNAC 2-0155ILAC MRA

Ready for the CRA before your competitors are.

For most products with digital elements, the CRA allows self-assessment under Module A — no notified body required. We put you in a position to declare conformity yourself. Where a notified body is mandatory, we prepare your submission.

CRA Article 14

30

days until 11 September 2026

From that date, actively exploited vulnerabilities must be reported to ENISA within 24 hours — including for products already on the market.

The calendar

What changes, and when.

Six dates in EU law that decide when your product needs evidence. Each one links to the text itself.

Flags of European Union member states outside an institutional building.

In force

NIS2 transposition deadline

Member states had to bring the directive into national law. Essential and important entities owe risk management measures, incident reporting and supply chain security — and they pass those requirements to you as a supplier.

Directive (EU) 2022/2555

Read the regulation

The European Parliament building in Brussels behind a European Union flag.

In force

The Cyber Resilience Act enters into force

The first EU law to place cybersecurity requirements on products with digital elements across their whole lifecycle. The clock on every date below starts here.

Regulation (EU) 2024/2847

Read the regulation

A telecommunications mast carrying several antenna arrays against the sky.

In force

Radio Equipment Directive Article 3(3) applies

Network protection, personal data safeguards and fraud protection became mandatory for radio equipment. EN 18031 is the harmonised standard, and it is inside our accredited scope.

Delegated Regulation (EU) 2022/30

Read the regulation

A wireless router with four antennas lit in coloured light.

Ahead

CRA Article 14 reporting begins

Actively exploited vulnerabilities and severe incidents must reach ENISA within 24 hours, with a fuller report at 72 hours and a final one at 14 days. It applies to products already on the market, which is why it lands before everything else.

Regulation (EU) 2024/2847, Art. 14

Read the regulation

An electric vehicle charging station with its cable coiled on the ground.

Ahead

The battery passport becomes mandatory

LMT batteries, industrial batteries above 2 kWh and EV batteries need a Digital Product Passport — the first DPP deadline fixed in law. Iron and steel, textiles, furniture and electronics follow.

Regulation (EU) 2023/1542, Art. 77

Read the regulation

A European Union flag hanging beneath a stone arch in Brussels.

Ahead

The CRA applies in full

Conformity assessment, the CE mark and the technical documentation obligations all bite. A product without a conformity route by this date cannot be placed on the EU market.

Regulation (EU) 2024/2847

Read the regulation

Track record & delivery

German automotive supplier

Complete EN 18031 readiness assessment and gap analysis delivered in four weeks. Fixed budget, no hourly overruns.

EN 18031 · 4 weeks

Asian IoT manufacturer

CRA Article 14 preparation — PSIRT and ENISA workflow — coordinated between the European headquarters and the R&D team.

CRA Art. 14 · PSIRT

European ICS vendor

IEC 62443-4-2 pre-evaluation scoping. Defining the exact test requirements upfront at a fixed price reduced the final certification budget substantially.

IEC 62443 · Scoping

Services

From the first gap assessment to the accredited test report.

Fixed price, not hourly.

Every service on this page is quoted as a fixed price with a binding delivery date, or as a monthly subscription. You get budget certainty; we are paid for the result rather than for hours on the clock. That is only possible because we automate heavily — and it is the reason we can support manufacturers for whom this level of help would otherwise be out of reach.

Advisory & preparation — not accredited10

Impartiality

Where we have provided advisory or preparation services for a product, accredited testing of that same product is performed by an independent laboratory. This safeguards the impartiality required under ISO/IEC 17025 clause 4.1.

How we work

A 360° approach, in three recurring waves.

We come from ethical hacking, and we replicate the methods real attackers use — so the picture you get of your security maturity is the real one. The plan is built on what that finds.

  1. Wave 1

    Assess

    We assess and evaluate the security of your systems, and simulate cyber-attacks to identify weaknesses and strengths alike. You get a complete risk assessment, a cyber health check, and the reports behind both.

    Penetration testingRisk assessmentCyber health check

  2. Wave 2

    Protect, educate and implement

    The implementation plan follows from what Wave 1 found: recommendations, a security plan, and the countermeasures actually put in place. Most breaches still come down to human error, so the programme also equips your people to recognise an attack aimed at them.

    Security planCountermeasuresAwareness programme

  3. Wave 3

    Monitor

    Security does not end at implementation. We support the whole lifecycle afterwards — monitoring, incident management, and SOC and SIEM services — because the threat model keeps moving after the project closes.

    MonitoringIncident managementSOC · SIEM

    The third wave feeds the first. Threat models move after a project closes.

Long-term collaboration

We work alongside leading IT companies towards a safer international IT landscape. We work transparently, we respect the confidentiality of your data and information, and we are measured on the result rather than on hours.

Capabilities

The disciplines behind the three waves, and the standards we work against.

Attack & analysis
  • Penetration testing
  • Offensive security
  • Risk management
Governance & compliance
  • Security governance
  • Compliance, audits and assessments
  • Data protection / GDPR
Build & operate
  • Architecture and system design
  • Incident management
  • SOC
  • SIEM
Standards
  • ISO 27001
  • IEC 62443
  • BSI C5

Industries

Every sector has its own regulation. We know which one applies to you.

The Cyber Resilience Act applies across all of them — but it never applies alone.

Robotic arms on a linear rail in an automation cell.Accredited

Industrial automation & OT

PLCs, drives, controllers and industrial gateways. Component- and system-level assessment against IEC 62443, including secure development evidence for your customers' supplier audits.

IEC 62443-4-1 · 4-2 · 3-3 · CRA

Electrical substation gantries silhouetted against a dusk sky.Accredited

Energy & storage

Battery storage, power conversion systems, energy management systems and EV charging infrastructure. Connected energy assets fall under both the CRA and NIS2.

IEC 62443 · CRA · NIS2

Vehicle centre console: head unit, illuminated display and climate dials.Accredited

Automotive & mobility

ECUs, telematics units and connected vehicle components. TARA and ISO/SAE 21434 evidence in the form your OEM expects it.

ISO/SAE 21434 · UNECE R155 · TARA

Macro photograph of a surface-mount chip beside a pin header.Accredited

Consumer IoT & wireless

Smart home devices, wearables and wireless modules. RED Article 3.3 and CRA conformity for market access in the EU and the UK.

EN 18031 · ETSI EN 303 645 · UK PSTI

A ship's bridge, its console and forward windows.Advisory

Vessel systems & marine electronics

Cybersecurity for core shipboard systems — navigation, propulsion, control. Excluding cargo and material handling systems. Equipment suppliers must produce the evidence.

IACS UR E26 / E27 · IEC 62443

Data centre aisle lined with perforated rack doors.Advisory

Critical infrastructure & NIS2

Essential and important entities under NIS2: gap assessment, risk management measures, reporting readiness, supply chain security, and attack detection readiness under Section 31 BSIG.

NIS2 · § 31 BSIG · ISO 27001

Accredited Testing under our ISO/IEC 17025 accreditation — TUNAC 2-0155, recognised internationally through the ILAC Mutual Recognition Arrangement. Advisory Consulting and assessment outside the accredited scope. Where accredited testing is required for a product we have advised on, it is performed by an independent laboratory.

Accredited testing scope

ISO/IEC 17025 · TUNAC 2-0155 · ILAC MRA

Test reports issued by Teligencia Labs SARL are recognised internationally under the ILAC Mutual Recognition Arrangement. Accreditation valid until 2029.

Consumer & IoT
EN 18031-1 / -2 / -3ETSI EN 303 645UK PSTI
Industrial & OT
IEC 62443-4-1IEC 62443-4-2IEC 62443-3-3
Automotive
ISO/SAE 21434TARAUNECE R155 support
Testing services
Penetration testingVulnerability assessment

Where we work

Accredited testing in Tunis. Contact in Germany. Regional office in South Africa.

Our laboratory works from Tunis — the same time zone as central Europe. All accredited test reports are issued by Teligencia Labs SARL.

Tunis — accredited laboratory

Teligencia Labs SARL, Immeuble Golden Tower, Bloc A, Centre Urbain Nord, 1082 Tunis. ISO/IEC 17025 accredited by TUNAC (2-0155, valid until 2029, ILAC MRA recognised). All accredited test reports are issued here.

ISO/IEC 17025AR · FR · EN

Germany — client contact

Safin Ilyas, Chief Sales Officer. Point of contact for European clients: project scoping, commercial terms and delivery coordination. Works in German and English, in the Central European time zone. safin.ilyas@teligencia.com

DE · ENDACH · EU

South Africa — regional office

Teligencia South Africa (Pty) Ltd, 425B Olive Bee Eater Crescent, Heron Hill Garden Estate, Pretoria, Gauteng 0181. Regional office extending our cybersecurity services to clients across Southern Africa. Makibinyane Mohapeloa, Managing Director.

ENSouthern Africa

Market access

EU market access, from the continent.

EU regulation is becoming the global standard. Every manufacturer in Africa and the MENA region selling into Europe will need conformity evidence — for the CRA, for the product passport, and for what comes after. The testing infrastructure to produce that evidence barely exists on the continent.

Ours does. Teligencia Labs SARL is accredited to ISO/IEC 17025 by TUNAC and recognised internationally through the ILAC Mutual Recognition Arrangement. A report issued in Tunis is accepted in Europe.

Accredited on the continent

Testing in Tunis, recognised in Europe under the ILAC MRA. No shipping products to a European laboratory and waiting in its queue.

The same regulation, explained locally

In Arabic, French and English, in your time zone, by people who work against European requirements every week.

One route, not two

We assess against the EU requirement and produce the evidence in the form your European buyer or the authority expects — not a local report that then has to be redone.

Leadership

Scientific rigour, industrial execution.

Our leadership is supported by a network of analysts, engineers and compliance specialists working to ISO/IEC 17025 procedures.

Prof. Dr. Aymen Gatri, Chairman of the Scientific Board.

Prof. Dr. Aymen Gatri

Chairman of the Scientific Board

Professor of IT Security, DBU Berlin · PhD, Northumbria University Newcastle · MBA

Provides scientific oversight for our cybersecurity laboratory — accredited by TUNAC (2-0155), recognised internationally through the ILAC Mutual Recognition Arrangement. Over two decades in senior technical and commercial roles at global industrial OEMs. Expert in standards-aligned security assurance for industry and government.

DBU BerlinNorthumbria UniversityTUNAC 2-0155ILAC MRA

Safin Ilyas, Chief Sales Officer.

Safin Ilyas

Chief Sales Officer

Strategic partnerships & compliance advisory

Translates complex regulatory requirements into structured delivery models — from ongoing compliance programmes to public-sector framework agreements. Holds three Master's degrees. Currently completing CISM (ISACA) and AI Officer ISO/IEC 42001 certifications.

ISACA CISMCompTIA Security+ISO/IEC 42001

Makibinyane Mohapeloa, Managing Director.

Makibinyane Mohapeloa

Managing Director

BCom · Postgraduate Diploma in Corporate Governance · Global Executive MBA (IESE)

Founder of Tshokoma Training and Consulting and Chief Operating Officer of MzansiSat. Serves on South Africa's B-BBEE ICT Council and as a non-executive director at Liselo Labs, bringing a background in investment, corporate governance and public-sector engagement across the continent.

MzansiSatB-BBEE ICT CouncilIESE

Applied research

Testing tomorrow's requirements today.

Our work is grounded in academic research. Prof. Dr. Aymen Gatri holds a professorship in IT Security at DBU Berlin, and our research feeds into how we assess emerging technologies — before the standards catch up.

Post-quantum cryptography

Cryptographic agility in constrained industrial devices. How do embedded systems with 10- to 20-year lifecycles migrate to post-quantum algorithms — and what does "harvest now, decrypt later" mean for products shipping today?

AI security & the AI Act

Security assessment of AI-enabled components: adversarial robustness, model integrity, and the intersection of the EU AI Act with existing product security requirements.

Supply chain integrity & SBOM

Machine-readable software bills of materials across multi-tier supply chains: what the CRA requires, what current tooling delivers, and where the gap between the two lies.

DBU Cyber Month

Click to load — YouTube sets cookies

Publication

Digitalized Quality Management for Cybersecurity Conformity Assessment

ISO/IEC 17025-based automated workflows, evidence analytics, and EN 18031 readiness for the Radio Equipment Directive.

Follow on LinkedIn

Tell us your product. We'll tell you which module applies.

Eight questions, an indicative result, no cost. Fixed price and a binding delivery date if you take it further.