Summary
- Fime has acquired Red Alert Labs, adding accredited cybersecurity evaluation and product-security compliance capabilities.
- The deal includes Red Alert Labs’ CyberPass platform for managing and automating certification and compliance work.
- The acquisition comes days after Cyber Resilience Act vulnerability and incident reporting duties began applying to manufacturers.
Testing and certification company Fime has acquired French cybersecurity specialist Red Alert Labs, extending its assurance business into product security as European manufacturers begin operating under the first live reporting requirements of the Cyber Resilience Act.
Financial terms have not been disclosed. Fime says the acquisition adds accredited cybersecurity evaluation, certification expertise, specialist Cyber Resilience Act and EU Cybersecurity Certification Scheme capabilities, and Red Alert Labs’ CyberPass compliance-automation platform.
Fime has built much of its business around testing and certification in payments, later expanding into digital identity and smart mobility. Red Alert Labs adds another part of the assurance chain, focused on connected-product security and the evidence organisations use to support certification and regulatory compliance.
The Red Alert Labs business will continue operating as an independent entity, retaining its accreditations and autonomy, according to current reporting on the deal. Founder and managing director Roland Atoui is expected to continue leading the laboratory.
CyberPass is intended to help manufacturers assess and manage compliance readiness and to support certification schemes handling assessment processes at scale. That sits alongside Red Alert Labs’ accredited evaluation work rather than replacing independent technical assessment.
The acquisition arrives at an important point in the European product-security timetable. Cyber Resilience Act Article 14 reporting requirements began applying on 11 September 2026. In-scope manufacturers must now report actively exploited vulnerabilities and severe product-security incidents through the required European process, while the Act’s main requirements apply from December 2027.
That timetable increases the operational burden attached to products after they reach the market. The CRA combines security requirements with vulnerability handling, reporting, software maintenance, and evidence covering how manufacturers manage security throughout supported product lifecycles.
Certification and conformity work therefore sits alongside ongoing operational processes rather than functioning solely as a pre-launch exercise.
The deal also reflects increasing overlap between payments, digital identity, connected devices, and cybersecurity assurance. A single product or service can combine identity credentials, communications components, cloud dependencies, embedded software, and payment functionality while being assessed against several technical or regulatory frameworks.
That creates scope for assurance providers to bring together capabilities that customers previously bought separately. Fime says the combined operation will support work from security by design and implementation through testing, evaluation, certification, and continuing assurance.
There is also a commercial incentive as European regulation makes evidence of secure development and vulnerability management more important in procurement and market access. Manufacturers that rely on external laboratories and certification bodies may increasingly look for ways to reduce duplicated work across different schemes.
Automating compliance administration does not remove the need for specialist assessment. Whether a product satisfies a security requirement depends on its architecture, software, vulnerability processes, evidence, and the particular standard or regulation involved.
Red Alert Labs nevertheless gives Fime a larger position in a European assurance market being reshaped by product-security rules. The acquisition comes only days after the CRA’s first direct reporting obligation took effect, at a point when manufacturers are moving from preparation towards running those processes in production.





