Lab 191 assessments go beyond what automated tools can produce. We understand binary hardening, supply chain risks, and the formal methods required to verify that code is actually safe — and how to document that for regulators.
Every assertion is reviewed and signed by a qualified expert, providing the professional judgment that distinguishes our reports from raw tool output.
The EU Cyber Resilience Act requires manufacturers to document security due diligence for every third-party component they ship. Most products depend on thousands of open-source packages, and few organizations have a process to assess them at that scale.
Existing options don't fit: raw scanner output won't satisfy an auditor, and full-service consulting engagements aren't practical at the component level. We built Lab 191 to deliver expert-signed, audit-ready reports at a predictable per-component price.
EU CRA
Regulation 2024/2847
OpenSSF
Scorecard & Best Practices
NIST SSDF
Secure Software Framework
SLSA
Supply Chain Levels for Software Artifacts
In addition to industry-standard data sources (OpenSSF Scorecard, OSV.dev, NVD), we use proprietary tooling including: