Skip to content
Preflight Audit

Preflight Audit Laboratories

Standards & Validation Programmes

We separate commercial capability, validation readiness, laboratory accreditation, programme recognition and product validation. They are not interchangeable claims.

Programme

ISO/IEC 17025

Authority

Accreditation body

Accreditation target

Method-specific laboratory competence and QMS scope; never treated as a blanket cybersecurity certification.

Programme

NVLAP CST 17ACVT / CAVP / ACVTS

Authority

NIST / NVLAP

Programme-gated

ACVTS Demo proficiency is developed now; production validation requires the applicable accreditation and access.

Programme

NVLAP CST 17CM / FIPS 140-3 / CMVP

Authority

NIST / NVLAP

Programme-gated

Cryptographic-module testing readiness is developed now; official testing depends on the applicable laboratory accreditation.

Programme

NVLAP CST 17CM-NI

Authority

NIST / NVLAP

Programme-gated

Non-invasive/side-channel testing requires programme-specific competence and scope.

Programme

NVLAP CST 17ESV / ESVTS

Authority

NIST / NVLAP

Programme-gated

Entropy-source validation eligibility and third-party restrictions are evaluated per current programme rules.

Programme

NVLAP CST 17PIV / NPIVP

Authority

NIST / NVLAP

Programme-gated

PIV validation readiness follows current FIPS 201/SP 800-73 programme requirements.

Programme

Common Criteria Testing Laboratory

Authority

NVLAP / NIAP or applicable scheme

Accreditation target

A separate programme/business line from CST accreditation.

Programme

FIDO Security / Biometric / Document Authentication

Authority

FIDO Alliance

Accreditation target

Scheme recognition is pursued only under current FIDO laboratory requirements.

Programme

PCI Recognized Laboratory pathways

Authority

PCI Security Standards Council

Accreditation target

Targets are selected from current active payment-device/software programmes.

Programme

EMVCo Security Evaluation pathways

Authority

EMVCo

Accreditation target

Laboratory recognition and product categories are scheme-specific.

Programme

Cyber Resilience Test Facility pathway

Authority

UK NCSC / UKAS

Accreditation target

UK pathway evaluated independently of the NVLAP CST application pause.

Programme

U.S. Cyber Trust Mark CyberLAB

Authority

U.S. FCC

Accreditation target

Consumer-IoT CyberLAB recognition requires ISO/IEC 17025 accreditation covering the FCC programme scope plus programme recognition.

Programme

NFC Forum Authorized Test Laboratory

Authority

NFC Forum

Accreditation target

Official NFC certification test results require an authorized lab, approved test tools and current certification-release controls.

Programme

Bluetooth Qualification Test Facility

Authority

Bluetooth SIG

Accreditation target

BQTF recognition is facility and test-scope specific and must be renewed under current Bluetooth SIG rules.

Programme

Matter / Zigbee / Product Security Authorized Testing

Authority

Connectivity Standards Alliance

Accreditation target

Official certification testing uses authorized test houses; target scope is selected from current Alliance programmes.

Programme

SESIP Evaluation Laboratory

Authority

GlobalPlatform / approved scheme

Accreditation target

SESIP governance defines evaluation-laboratory competence and accreditation requirements for IoT platform security evaluation.

Programme

PSA Certified Evaluation Laboratory

Authority

PSA Certified

Accreditation target

Platform/Root-of-Trust evaluation is pursued only under the current approved-laboratory scheme requirements.

Programme

ISA/IEC 62443 / ISASecure laboratory pathway

Authority

ISASecure / accreditation bodies

Accreditation target

Industrial product/security testing and certification use scheme-specific ISO/IEC 17025 and ISO/IEC 17065 structures.

Terminology matters.

A Preflight commercial audit or readiness assessment is not an external government or industry validation. An accredited laboratory result will be described as such only after the exact legal entity, laboratory location, method and programme scope have been formally approved.