COMPLIANCE · IoT SECURITY · AUTOMATED EVIDENCE
CERTIFIoT
Monitor connected-device behaviour and
verify cybersecurity compliance continuously.
From One-Off Checks
to Continuous Assurance
Connected products continue to communicate, update and change after deployment. A one-time assessment cannot explain how a device behaves tomorrow, which destinations it contacts or whether a new configuration introduces risk.
CertifIoT transforms certification from a periodic snapshot into a continuous, evidence-driven process. It observes network activity, evaluates device behaviour and makes compliance findings understandable to technical, security and governance teams.
What CertifIoT Delivers
- Automatic device discovery Identify connected devices and establish visibility across the monitored environment.
- Continuous security and compliance analysis Analyse network traffic and device behaviour to detect vulnerabilities, anomalous activity, privacy risks and non-compliant configurations.
- Actionable evidence Translate technical findings into clear compliance insight, detailed reports and practical remediation priorities.


How CERTIFIoT Works
- Connect. Place the target devices within the monitored network or test environment.
- Discover. Identify devices and build a behavioural picture from their network activity.
- Assess. Combine passive monitoring with active security testing to evaluate vulnerabilities, anomalous behaviour, privacy exposure and resilience to realistic threats.
- Map. Associate observed technical evidence with relevant requirements and security guidance, including the EU Cyber Resilience Act, ETSI EN 303 645 and applicable NIST guidance.
- Report. Present findings, causes and recommended actions through clear compliance views and exportable evidence.
Core Capabilities
- Continuous monitoring Observe device and network behaviour beyond a single test window.
- Automated assessment Use AI-supported analysis to convert regulations and security requirements into technical checks.
- Passive and active testing Combine traffic observation with controlled testing techniques for a more robust assessment.
- Anomaly and vulnerability detection Identify suspicious behaviour, known weaknesses and configurations that increase exposure.
- Privacy risk analysis Surface data flows and behaviours that may create unnecessary privacy risk.
- Explainable reporting Show what failed, why it matters and which intervention should be prioritised.
Regulation and
Device-Agnostic by Design
CertifIoT is designed to adapt to different device categories and evolving requirements. Rather than locking assessment to a single manufacturer, device class or compliance framework, it maps observable technical evidence to the controls that matter for each deployment.
CERTIoT-6G: Continuous Trust for Next-Generation Networks


Mulini was selected for the second open call of the 6G-PATH project and is developing CERTIoT-6G, extending the CertifIoT framework into 5G and future 6G environments.
The solution integrates Mulini’s AI-driven assessment approach with the CARL-W wireless testbed at Karlstad University to deliver Security as a Service capabilities. Devices operating in critical domains such as healthcare and smart cities can be monitored in real time, while passive analysis and active testing evaluate their behaviour, security posture and resilience.
- Continuous monitoring of network traffic and device behaviour.
- Compliance verification embedded into the network environment.
- Assessment of vulnerabilities, anomalous behaviour, privacy risks and non-compliant configurations.
- Testing against realistic conditions, including denial-of-service attempts, unauthorised access and network-performance manipulation.
Frequently Asked Questions
Does CertifIoT require software on every device?
CertifIoT is designed to assess devices through their network behaviour, reducing the need to install an agent on each protected product. The final deployment model depends on the environment and assessment scope.
Which requirements can CertifIoT support?
The supplied materials identify the EU Cyber Resilience Act, ETSI EN 303 645 and relevant NIST guidance as reference points. Additional requirements can be mapped according to the deployment and agreed assessment scope.
Does CertifIoT issue a legal certification?
CertifIoT supports continuous verification, evidence generation and audit preparation. Formal certification or legal conformity decisions remain with the relevant manufacturer, assessor or competent body.
What is CERTIoT-6G?
CERTIoT-6G is the 5G and 6G application of Mulini’s CertifIoT framework developed in the context of the 6G-PATH project.
Turn Device Behaviour into Continuous Trust
Understand how your connected products behave,
where risk is emerging and what evidence is needed to move towards compliance.
