I would be great if an independent lab would certify equipment and software as spyware free. And it would be great if one could buy insurance to that effect on equipment and software. The NSA has done great economic damage to US exports of software and IT equipment. I suppose that US government oversight of the NSA takes that into account.
That's just not possible. Devices are way too complex nowadays. Too much can be hidden.
A product will have multiple ASICs, SOCs, etc. Those in themselves are too complex for any single individual to really understand them. How much effort could an independent lab put into certifying them? It would literally take man-years.
How do you certify an SOC? Start with a gate level Verilog netlist? Good luck figuring out anything useful from that. You think a vendor will give an outside lab a higher level Verilog RTL to review for a design? Not likely. That's highly valuable intellectual property.
About all that could be done is monitoring the software or equipment to see if there is any unexpected network activity flowing in or out. That in itself would be a difficult thing to to.