By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Arxan TechnologiesPublished May 13, 2026

TL;DR: Air-gapped and network-restricted enterprises can run full-stack, automated device testing entirely on-premises while preserving compliance, observability, and scale, according to Arxan Technologies. The practical shift is to treat the lab as part of the controlled environment, not a compromise, because governance, auditability, and toolchain integration matter more than remote convenience.


At a glance

What this is: The article argues that regulated organisations can modernise device testing in air-gapped environments without sending test data outside their own network.

Why it matters: This matters to IAM and security practitioners because controlled testing environments increasingly intersect with identity-bound workflows, audit evidence, and access governance for regulated systems.

👉 Read Arxan Technologies' analysis of air-gapped testing without tradeoffs


Context

Air-gapped testing is really a governance problem disguised as an engineering one. When regulated data, operational devices, or validation evidence must stay inside the enterprise boundary, remote device clouds and external SaaS testing models become structurally incompatible with the control requirements.

For identity and access teams, the intersection is not the test tooling itself but the surrounding control plane: who can trigger tests, who can access device labs, how artifacts are retained, and how validation evidence is protected. That makes the topic relevant to IAM, PAM, and audit-ready operational workflows rather than just application testing architecture.


Key questions

Q: How should regulated teams govern access to on-premise device labs?

A: Treat device labs like any other privileged environment. Restrict administration to named roles, separate pipeline triggers from artifact access, and review permissions on a defined lifecycle so test infrastructure does not become an informal back door into regulated systems.

Q: Why do remote testing platforms struggle in air-gapped environments?

A: They depend on external infrastructure and data paths that conflict with requirements to keep regulated data, device telemetry, and validation records inside the enterprise boundary. In practice, that makes them structurally misaligned with restricted networks.

Q: What breaks when test artefacts are not preserved as audit evidence?

A: You lose the ability to prove what was tested, what failed, and what conditions existed at the time. Without durable artefacts such as logs, video, and captures, validation becomes harder to defend and incident analysis becomes less reliable.

Q: What is the difference between a device lab and a controlled validation environment?

A: A device lab is the physical and software setup used to run tests. A controlled validation environment adds governance, access restrictions, retention rules, and evidence handling so the lab can support compliance and audit expectations, not just engineering convenience.


Technical breakdown

Why remote device clouds break in restricted environments

Remote testing platforms depend on external infrastructure, shared tenancy, and data paths that leave the enterprise boundary. In air-gapped or highly regulated environments, that architecture conflicts with requirements to keep protected data, validation evidence, and operational telemetry on-premises. The practical result is not just a network restriction, but a loss of architectural fit between the testing model and the compliance boundary.

Practical implication: treat external device clouds as incompatible by design where regulated data or controlled hardware must remain inside the network.

How on-premise device labs extend the full interaction stack

An on-premise device lab is more than a rack of phones. It can connect via Bluetooth, USB, NFC, and local Wi-Fi to the actual hardware used in production workflows, such as clinical devices, payment readers, or access-control peripherals. That enables tests to validate the complete interaction chain rather than a synthetic app-only path, which is essential when device behaviour affects operational or regulated outcomes.

Practical implication: map test coverage to the real hardware and protocols your production systems use, not just the mobile application layer.

Why observability becomes a compliance control

In regulated testing, logs, screenshots, video, crash data, and network captures are not just diagnostics. They are evidence. When those artifacts are generated centrally, retained locally, and tied to repeatable execution, they can support validation records, audit trails, and root-cause analysis. That shifts the device lab from a convenience layer into part of the assurance model.

Practical implication: preserve test artifacts with the same retention and integrity expectations you apply to other audit evidence.


NHI Mgmt Group analysis

Air-gapped testing should be treated as a control-boundary design problem, not a tooling limitation. The article shows that the real issue is whether testing infrastructure can operate inside the same governance perimeter as the regulated system under test. That makes the boundary itself part of the assurance model, with implications for access control, auditability, and evidence retention. For identity and security teams, the lesson is that control placement matters as much as test automation coverage.

Identity governance extends into the test environment once devices and validation evidence become regulated assets. If a device lab can trigger release pipelines, access clinical peripherals, or validate payment workflows, then privileged access to the lab is itself high-risk access. The same governance discipline used for production systems should apply to lab administration, session control, and artifact handling. Practitioners should think in terms of lifecycle-managed access to the test estate, not informal engineering convenience.

Audit-ready testing is becoming a cross-functional requirement, not a niche compliance feature. The article makes clear that regulated enterprises need test artefacts that can survive scrutiny from compliance, engineering, and operations teams. That aligns with broader control frameworks that emphasise logging, access restriction, and evidence integrity. The practical conclusion is straightforward: if the lab cannot produce trustworthy records, it is not fully serving the regulated environment it was built for.

On-premise device labs create a named governance pattern we can call regulated test estate containment. This means keeping test execution, device connectivity, access control, and artifact storage inside the same trust boundary as the business process being validated. That pattern matters because it reduces the gap between operational control and validation control, which is where regulated testing often fails. Practitioners should design the lab as a governed estate, not a disconnected utility.

What this signals

Air-gapped testing is increasingly a governance conversation about boundary control rather than a debate about tooling preference. As regulated engineering and security teams converge, the lab will need the same access discipline, logging expectations, and evidence retention practices as production support environments.

Regulated test estate containment: the useful design pattern here is to keep execution, access, connectivity, and artifact storage inside one governed boundary. That pattern will matter wherever validation evidence and operational hardware must remain inseparable from the environment being tested.


For practitioners

  • Define the test estate as a controlled environment Classify device labs, test artifacts, and execution infrastructure as governed assets, with explicit ownership, access review, and retention rules aligned to the regulated workload.
  • Restrict privileged lab administration Limit lab administration to named roles, require step-up approval for broad device or pipeline access, and separate build-trigger permissions from artifact access.
  • Integrate evidence handling into validation workflows Store logs, screenshots, video, and network captures in systems that support integrity, retention, and traceability so they can be used for audit and root-cause analysis.
  • Map lab connectivity to production hardware Document which Bluetooth, USB, NFC, and local Wi-Fi interactions must be exercised in the lab so test coverage matches the real operational stack.

Key takeaways

  • Air-gapped device testing is a control-boundary issue, not a speed-versus-security trade-off.
  • The strongest on-premise labs validate real hardware interactions and preserve audit-grade evidence inside the enterprise boundary.
  • Teams should govern test infrastructure like privileged production-adjacent access, because the lab can become part of the assurance chain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Access control is central to governing restricted testing environments.
NIST SP 800-53 Rev 5AU-2Audit logs and evidence capture are core to the article's compliance angle.
CIS Controls v8CIS-5 , Account ManagementLab and pipeline accounts need governed lifecycle management.
ISO/IEC 27001:2022A.8.15Logging and monitoring support the article's audit-ready testing theme.

Use AU-2 to define which test events, artefacts, and administrative actions must be logged.


Key terms

  • Air-Gapped Environment: An air-gapped environment is a system separated from external networks, either physically or by strict logical controls. In identity terms, it changes how authentication, callbacks, and updates can function because the system cannot assume routine Internet reachability.
  • Validated Environment: A validated environment is a regulated system where changes must preserve documented operational and compliance requirements. In pharma, that means security controls like segmentation must be introduced carefully so they do not invalidate production processes, lab workflows, or regulated configurations.
  • Audit-Ready Evidence: Audit-ready evidence is access proof that can be retrieved directly from the control system without manual reconstruction. It should show who approved access, what policy they used, when the decision occurred, and whether any exceptions or compensating controls were applied.
  • Regulated Test Estate: The collection of devices, pipelines, artifacts, and administration used to validate software in a regulated setting. Treating it as an estate means applying governance, access review, and evidence controls to the test environment the same way they would be applied to production-adjacent assets.

What's in the full article

Arxan Technologies' full article covers the operational detail this post intentionally leaves for the source:

  • Deployment patterns for standing up an on-premise device lab inside restricted networks
  • Examples of parallel execution and scheduler design across mixed device estates
  • Integration details for CI/CD, test management, and observability platforms
  • Artifact handling approaches for audit trails, crash reports, and network captures

👉 The full Arxan Technologies article covers deployment patterns, observability details, and regulated testing workflows.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management in the contexts that most affect regulated operations. It helps practitioners connect access control and lifecycle discipline to the broader security programmes they already run.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org