Typical documentation and evidence
The work is not limited to running tests. The evaluation needs enough documentation to make scope, configuration and security functionality assessable without ambiguity or over-reliance on verbal context from the team.
When that documentary baseline is weak, the process becomes slower.
What happens if vulnerabilities are found
This is a normal part of the process. Identified vulnerabilities are reported as non-conformities so the manufacturer can resolve them. We then verify against the corrected version that the issues have been resolved.