DOSS links security data across Europe’s IoT supply chain.

The recently completed Horizon project DOSS (Design and Operation of Secure IoT Supply Chain) lays the foundation for resilient IoT communications.

Eleven EU research partners unveil IoT cybersecurity passport

Stuttgart, September 2026 – Cybersecurity provider asvin has developed an integrated Supply Trust Chain architecture as part of a consortium of industry, research and higher-education partners from six European countries.

The architecture was continuously tested in practical test environments throughout the project. The platform enables operators to significantly improve the resilience of their IoT supply chains.

“The DOSS project provides a purpose-built reference architecture for cybersecurity, implementation tools and technical guidelines.
These enable small and medium-sized enterprises to systematically assess, implement and demonstrate compliance with new cybersecurity regulations- including the Cyber Resilience Act (CRA),” emphasises asvin CTO Rohit Bohara, highlighting the relevance of the solution.

“In addition, the Supply Trust Chain developed within the research programme establishes effective feedback loops through which operators, as well as manufacturers and developers, can exchange information on identified vulnerabilities and attacks while systems are in operation.”

According to Bohara, this also ensures the vigilance – meaning proactive risk analysis – that cybersecurity experts are increasingly calling for in response to agentic AI attacks, including in IoT systems.

  • The Component Tester identifies vulnerabilities in IoT components.

  • The Digital Cybersecurity Twin models target systems and simulates potential attacks.

  • The Architecture Security Validator assesses the security and compliance of systems against structured requirements.

  • The Secure Onboarding Platform enables the trusted integration of devices into operational environments.

Doss Project - Device Security Passport

The Device Security Passport consolidates security information throughout an IoT device’s lifecycle.

The integrated DOSS approach was demonstrated and validated through three practical pilot projects. These included a smart home environment, a prosumer energy cell featuring a rooftop photovoltaic system, battery storage, a wallbox and intelligent energy management, as well as two pilots involving connected vehicles. Together, they represent different IoT environments and supply-chain relationships.

Last but not least, the standardisation work carried out as part of the project is now bearing fruit. Three ETSI documents based on DOSS results have been published: ETSI TR 104 285 on the Device Security Passport, ETSI TS 104 286 on the digital translation of security standards into requirements, and ETSI TR 104 287 on the methodology for security validation of IoT components.

asvin CTO Rohit Bohara concludes:

“By bringing together numerous relevant parameters – including IoT security requirements, testing, evidence, system-level assessments and secure commissioning – DOSS has created sound foundations for a more transparent and continuously secured IoT ecosystem.”

The results provide practical building blocks for manufacturers, technology providers, integrators and operators facing growing cybersecurity and regulatory requirements.

Should you require additional information, we would be happy to arrange an interview with asvin CTO Rohit Bohara (technology and project progress) or asvin CEO Mirko Ross (market relevance, cyber and AI risks).

Project data

Name DOSS, Design and Operation of Secure IoT Supply Chain
Grant agreement number       HE-101120270
Project start 1 September 2023
Duration 36 months
EU funding €5 million
Coordinator Atos Hungary Ltd.

About asvin

asvin is a Stuttgart-based cybersecurity company specialising in cyber threat and risk intelligence for connected products, industrial infrastructure and complex supply chains. Using AI-powered analysis, context-based risk assessment and automated CTI reports, asvin helps companies identify threats early, prioritise risks and implement regulatory requirements efficiently. asvin.io

Konrad Buck

Leiter der Presse- und Öffentlichkeitsarbeit

Hintergrund & Expertenzugang für Medien

Ich biete Journalist:innen Zugang zu vertieften Hintergrundinformationen über unsere öffentlichen Materialien hinaus, einschließlich:
  • Produkt- & Technologieeinblicke – Technischer Kontext, Lösungsarchitektur und praxisnahe Anwendungsbeispiele für Fach- und Wirtschaftspresse.
  • Expertenkommentare & Hintergrundgespräche – Unser CEO steht als Expert:innenquelle zu aktuellen Entwicklungen in der Cybersicherheit, Bedrohungslandschaften sowie den Auswirkungen von KI auf Sicherheit und Regulierung zur Verfügung.
Pressekontakt
Ich spreche offen, faktenbasiert und ohne PR-Floskeln. Als ehemaliger IT-Journalist mit jahrzehntelanger Erfahrung in der IT- und Cybersicherheitsbranche kenne ich die Höhen und Tiefen der Industrie. Hintergrundgespräche off the record sind auf Anfrage möglich.