Skip to main content
Secure Connected Device badge

Getting SCD accreditation

To enquire about gaining the Secure Connected Device accreditation and becoming an SBD member company, contact your local SBD Development Officer.

What is the process?

Our SCD device assessment identifies the level of risk associated with a connected device and/or mobile app and its ecosystem. Based on the results of the assessment we can advise companies of the appropriate level of certification they need to achieve with one of our SBD approved certification bodies.

Once independent third party testing and certification have been completed, the company can then apply to become SBD members with the product or service receiving the SBD 'Secured Connected Device' accreditation.

1. Enquiry

Enquiry into SCD accreditation and SBD membership for your IoT product or app.

2. Scoping

If product is in scope for the SCD scheme, an SCD device assessment is conducted to determine the appropriate certification route for an IoT product and/or mobile app.

3. Results

Based on the results, you will be given a recommended certification route that you need to achieve with one of our SBD approved certifying bodies.

4. Certification

Complete and achieve third party testing and independent certification with one of our SBD approved certifying bodies.

5. Accreditation

Apply for SBD membership and gain SCD accreditation for your product.

What does the app accreditation test?

Authentication mechanisms and session management

Ensures users are securely verified and that their logged-in sessions are protected from hijacking, misuse or unauthorised access

Secure default configurations and deployment standards

Ensures applications are safely configured and deployed, so they are not exposed to avoidable risks from misconfigurations

Use of cryptography to protect sensitive data

Checks that sensitive information is properly encrypted using strong, modern algorithms and securely managed keys

Safe error handling and logging

Ensures apps do not leak sensitive information through errors while maintaining secure, useful logs for investigating security incidents

Input validation and output encoding

Checks that all user-supplied data is handled safely throughout an application

Protection against common threats

Checks the app consistently validates input, encodes output, and enforces server-side authorisation to prevent attackers from accessing unauthorised data