Cybersecurity and compliance extend beyond the finished product. They also concern component handling, programming and the protection of firmware, keys, certificates and device identities.
Whether you work in machinery and industrial equipment, telecommunications, building technology, automotive or medical technology, the starting point is the same: establish which requirements apply to your product, your organisation and the component processes involved.
This hub brings together articles on key regulatory frameworks and security concepts. It shows where documented component and programming processes can support technical evidence—and where responsibility remains with the manufacturer.
Three interconnected levels
Product cybersecurity, organisational information security and supply chain security address different responsibilities. The Cyber Resilience Act concerns products with digital elements, while NIS2 addresses cybersecurity risk management for entities within its scope.
Sector-specific frameworks add further requirements: UN R155/R156 address vehicle cybersecurity and software updates, while the MDR provides the regulatory framework for medical devices.
For the processes discussed here, the practical question is: can you establish which component passed through which processing steps, which firmware or identity was assigned to it, and how it was handed over?
Cyber Resilience Act
The Cyber Resilience Act introduces cybersecurity requirements for products with digital elements within its scope. Reporting obligations for actively exploited vulnerabilities and severe security incidents have applied since 11 September 2026; most other requirements become applicable on 11 December 2027.
EN 18031 and the RED
The EN 18031 series supports the assessment of cybersecurity requirements under the Radio Equipment Directive for certain categories of radio equipment. Manufacturers need to distinguish the applicable legal requirements from the standards used to demonstrate conformity and determine which provisions apply to their product.
Cross-sector requirements, targeted sector-specific guidance.
This hub addresses companies across the electronics supply chain. CRA, EN 18031 and NIS2 are covered in their respective sections; the following articles provide additional guidance on selected automotive and medical technology frameworks.
TISAX® and information security
TISAX® enables the standardised and controlled exchange of information-security assessment results within the automotive industry. btv technologies has completed the TISAX® standardization process and has been listed on the ENX portal.
UN ECE R155 and R156
UN R155 addresses vehicle cybersecurity and the Cyber Security Management System. UN R156 covers software updates and the Software Update Management System; manufacturers must demonstrate the required management systems within the applicable type-approval framework.
NIS2 and supply chain security
NIS2 requires entities within its scope to implement appropriate technical, operational and organisational cybersecurity measures. These include supply chain security, vulnerability handling and security-related aspects of relationships with direct suppliers and service providers.
Chain of custody
A documented chain of custody makes the physical and operational journey of a component traceable—from goods receipt and storage through processing and order picking to handover and delivery.btv-technologies
Cybersecurity starts before the finished product
Physical traceability and secure programming address different parts of the same process chain. btv TAK® documents agreed supply chain information at packaging-unit level, while btv SEEL® adds programming and identity-assignment records for individual programmed components.
Together, these records can support investigations, audits and the identification of affected components. They do not constitute a blanket conformity assurance for the finished product.
| Evidence chain | Key question | Relevant btv services |
| Chain of custody | Where was the component, which processing steps did it undergo, and how was it handed over? | btv TAK®, Storage and Component Services |
| Chain of trust | Which firmware, keys, certificates and device identity were assigned to the programmable component? | btv SEEL® and documented programming processes |
Documented Quality and Security
Industry requirements differ. Reliable processes, traceable material flows and clearly defined security standards remain relevant across all of them.
btv technologies is certified to ISO 9001 and IATF 16949. This is complemented by AEO CS status and an EcoVadis Bronze rating.
How btv technologies supports you
btv technologies combines component supply, storage, component services and secure programming within coordinated supply structures. The relevant services are selected according to the components, processes and requirements involved.
btv SEEL®
btv SEEL® supports protected firmware processing, integration with customer-owned PKI infrastructure and the assignment of individual device identities. Documented programming records link certificates and relevant process information to the programmed component.
Conformity assessment and regulatory responsibility for the finished product remain with the respective manufacturer.
Translate requirements into processes
Would you like to clarify the component, storage, processing or programming requirements within your supply chain?
Together, we review your components, interfaces and documentation needs to identify which btv services can support your operational processes and technical evidence.
Frequently asked questions – our answers
NIS2 explicitly identifies supply-chain security as part of cybersecurity risk management. Affected organisations must take appropriate and proportionate measures and consider security-related aspects of their relationships with direct suppliers and service providers. The required measures depend on the individual risk assessment and the role of the respective organisation. btv technologies can support with documented processes, clear handovers and secure programming; overall regulatory responsibility remains with the respective organisation.