The Security Evaluation Standard for IoT Platforms (SESIP) is a security evaluation methodology for connected platforms and their components, published by GlobalPlatform and standardized by CEN/CENELEC as EN 17927. It takes the rigor of Common Criteria and reshapes it for the realities of the IoT market: shorter evaluation cycles, a reusable catalogue of security functional requirements, and assurance levels that scale to the actual threat model of your product.

What makes SESIP different is composition. A certified platform's evidence can be reused by the products built on top of it, and a single SESIP evaluation can be mapped to the requirements of other schemes and regulations — from ETSI EN 303 645 and EN 18031 to IEC 62443, ISO/SAE 21434, NIST IR 8259A, and PSA Certified. That turns certification from a series of separate projects into one asset you keep drawing on.

Keysight is a licensed evaluation lab under the TrustCB SESIP scheme. Our team has spent decades breaking and hardening embedded systems, chipsets, and secure elements — and we bring that attacker's perspective to every evaluation, from scoping and Security Target authoring through pre-certification testing and the formal Evaluation Technical Report (ETR).

sesip logo
Your Path to SESIP Certification
red icon with a certificate

Discovery and Scoping

We start with a joint workshop to map your architecture, target markets, and threat landscape. Together we define the Target of Evaluation (ToE), select the right SESIP assurance level, and identify which SESIP profile fits your product category.

red icon with a team

Training and Alignment (optional)

SESIP workshops bring your engineering, product, and security teams onto the same page: how the SESIP catalogue works, what evaluators will actually look for, and how SESIP relates to Common Criteria, PSA Certified, and the regulations on your roadmap.

red icon with a folder

Security Target and Evidence

The Security Target is where most SESIP projects succeed or stall. We help you select security functional requirements from the SESIP catalogue, write claims that are precise and testable, and assemble the architecture descriptions, threat models, and developer evidence your assurance level requires.

red icon with a shield

Pre-Certification Assessment

Before the clock starts on formal evaluation, our experts run vulnerability analysis and penetration testing against your product. You get findings and remediation guidance while there is still time to act on them.

red icon with a certificate

Formal SESIP Evaluation

As a licensed lab under the TrustCB SESIP scheme, we conduct the independent evaluation in our labs, perform the required testing for your assurance level, and deliver the Evaluation Technical Report to TrustCB for certificate issuance.

red icon with two circular arrows

Maintenance and Reuse

A TrustCB SESIP certificate is valid for five years from the issue date of the ETR. We help you plan for product updates, derivative certifications, higher assurance levels, and the reuse of your evidence in adjacent schemes and regulatory submissions.

SESIP Assurance Levels and Typical Use Cases

SESIP defines five assurance levels. Each represents a step up in evaluator effort and in the attack potential your product is expected to resist. The right level is the one that matches your product's real threat model and your customers' expectations.

SESIP 1 is based on self-assessment. Evaluators do not independently verify that the platform implements the claimed security functional requirements, so the level provides a basic degree of assurance. It suits software components and platforms entering the market for the first time, low-risk consumer products where physical attack is implausible, and teams who want to establish a documented, structured security baseline before committing to independent testing.

SESIP 2 adds independent black-box penetration testing. It is the highest level that can be applied to a closed-source platform without developer cooperation, which makes it valuable when evaluating third-party or acquired components. Typical products include connected consumer devices, home hubs, routers and gateways, and closed-source platforms that need credible independent evidence for network-facing threats.

SESIP 3 is a traditional white-box vulnerability analysis, structured around time-limited source code review combined with time-limited penetration testing. It is the level most commonly requested by commercial customers and regulators. Typical products include secure microcontrollers and wireless SoCs, smart meters and grid devices, industrial controllers, automotive ECUs and gateways, and any platform where an attacker may have extended physical access to the device.

SESIP 4 was originally designed for the reuse of SOG-IS certified platforms and parts, allowing those platforms to draw on SESIP's mappings into specific commercial domains. That reuse path remains available, including for EUCC certification. CEN/CENELEC has since added a standalone evaluation methodology to EN 17927, so a SESIP-only SESIP 4 evaluation is now possible. It suits high-value components where sophisticated logical and physical attacks are in scope.

SESIP 5 shares the same origin as SESIP 4 — reuse of SOG-IS certified platforms and parts by licensed laboratories — and, with the CEN/CENELEC standalone methodology, can now also be pursued as a SESIP-only evaluation. It targets components that must withstand attackers with high attack potential, such as secure elements, secure enclaves, and Root of Trust implementations protecting cryptographic keys and other high-value assets.

Working with Keysight

Focus on advancing your product while Keysight guides you through SESIP preparation and evaluation.

engineer with magnifying glass

Evaluate With an Attacker's Mindset

Our team has spent decades finding real weaknesses in real embedded products, using side-channel analysis, fault injection, and hardware and firmware reverse engineering. That experience shapes how we scope, test, and advise — so your certificate reflects genuine resistance to attack, not just a completed checklist.

engineer at a computer

Arrive at Evaluation Ready

Most delays in SESIP projects trace back to an imprecise Security Target or evidence that does not match the claims. Our readiness assessments, training, and documentation support surface those gaps before the formal evaluation begins, which keeps timelines and budgets predictable.

three engineers examining graphs

Certify Once, Reuse Many Times

We plan your SESIP work alongside the other schemes and regulations on your roadmap — CRA, RED, PSA Certified, IEC 62443, Common Criteria — so one body of evidence serves several obligations, and each new product or derivative costs less to certify than the last.

Frequently Asked Questions

Learn Resources

Featured Blogs

Our experts regularly share practical insights in our blog. Explore the latest developments in device security.