Many manufacturers invest substantial budgets in securing their application software. But the actual programming process — the moment firmware and keys are physically flashed onto the microcontroller — remains the weak point in many production chains.

If plaintext firmware or private keys end up in the wrong hands at this stage, the trust model for an entire device generation collapses: not a quality issue, but a security and liability risk — and, with the CRA, NIS2, the Data Act and, for automotive suppliers, UN ECE R155/R156, increasingly a regulatory one too. btv SEEL® closes the gap exactly where it opens.

Want to know how to get your components programmed in a future-proof, auditable way? Talk to us.

Christian Schoregge
Key Account Manager
CHOOSE A TIME
Sebastian Gersmann
Key Account Manager
CHOOSE A TIME
Thomas Hase
Key Account Manager
CHOOSE A TIME

Security by design can't end in the code editor. The programming process is the interface between software and hardware. Whatever gets overlooked here is almost impossible to correct or prove later, out in the field.

Maximilian Krane, CEO btv technologies

The problem isn't the code. It's the handover.

In supply chain attacks, most target the code of suppliers. And most of those affected can't say afterwards how it happened.

The second point is the more uncomfortable one. An incident nobody can reconstruct can't be explained in an audit and can't be contained if things go wrong.

Trust block: The risk – 66% of attacks targeted supplier code, 66% of affected suppliers could not reconstruct how they were compromised. The expectation – 63% of companies require suppliers to meet security standards, 54% conduct audits.

At the same time, pressure is building from the other direction: customers increasingly require their suppliers to meet security standards — and actively verify that, for example through their own audits and risk assessments.

So anyone who has components programmed gets asked how that process is secured. And needs to be able to answer.

Linking to the video streaming service is disabled to protect your privacy. Click here to activate it. By loading the video, you accept the privacy policy of the video streaming service. Further information about the privacy policy can be found here: Google - Privacy & Terms

btv SEEL® CORE – RAM-only principle, no persistent data traces

The technological foundation of the btv SEEL® ecosystem. The patent-pending process processes encrypted firmware exclusively in the volatile memory of the programming environment. At no point are unencrypted temporary files or persistent copies written to storage.

Once programming is complete, an automated, irreversible memory wipe follows. Asymmetric 4K encryption, public-private key procedures and signature-based authentication protect the flashing process against tampering and unauthorized readout. During the critical decryption step, the programming environment has no direct external connection.

On top of that comes a property that can't be configured away: RAM is volatile. No power, no stored data.

  • Individual key pair per chip
  • Certificate signing through your own CA
  • No root key handover, no hidden backdoors
  • Complete documentation and auditability

btv SEEL® INTERCONNECT – Your PKI stays your PKI

As soon as you outsource programming, the question becomes how a service provider is supposed to issue device certificates without gaining access to your root certificates.

btv SEEL® INTERCONNECT connects to your own PKI infrastructure. Root certificates remain 100 percent under your control.

  • Certificate-based trust network across your supply chain
  • Data exchange in controlled, protected data rooms
  • Standardized protocols: HTTPS (SSL/TLS), SSH, PGP (Pretty Good Privacy)
  • Automatable workflows, integration into existing systems
  • Cloud and on-premise solutions available

btv SEEL® UNLIMITED – Device identities at scale, audit trail included

Modern IoT, industrial, medical and automotive devices need individual certificates to identify themselves to cloud platforms, apps or manufacturer networks. In series production, that means a very large number of certificates — each unique, each traceably assigned.

btv SEEL® UNLIMITED scales this approach to the assignment of individual device identities. Every single process step is automatically documented and cryptographically signed.

That gives you a complete audit trail — and, if something does go wrong, the ability to pinpoint the affected component batches instead of having to recall an entire device generation.

  • Certificate issuance with no volume limit, individual per device
  • Unambiguous mapping: which certificate sits on which microcontroller
  • Automated, cryptographically signed documentation for every process step
  • For global series production and complex supply chains

What we actually deliver is the evidence

For actively exploited vulnerabilities and serious incidents, the Cyber Resilience Act requires an early warning within 24 hours, followed by a report within 72 hours and a final report within 14 days.

24 hours isn't enough time to reconstruct a batch assignment after the fact. Either the data already exists — or you report without being able to narrow anything down.

That's exactly what the btv SEEL® audit trail is built for: programming, certificate issuance and chip-level traceability, documented and uniquely assigned to each component. Audit-proof evidence for your customers, for auditors, and for regulatory requirements such as the CRA, UN ECE R155/R156 or ISO/SAE 21434.

The practical difference: the evidence already exists by the time of the audit. It doesn't get reconstructed afterwards.

Source: Cyber Resilience Act, Article 14

The CRA reporting obligations become mandatory in September 2026. Let's talk about your roadmap.

CHOOSE A TIME

For security-critical industries

btv SEEL® is built for engineering, quality and operations leaders in sectors where a compromised component gets expensive:

  • Mobility and transport (automotive, aerospace, rail, maritime)
  • Healthcare (medical technology, digital health)
  • Industrial production and mechanical engineering (incl. IoT/Industry 4.0)
  • Security and defense (defense industry, infrastructure)
  • Building technology and cities (smart home, smart city)
  • Connectivity and communication (telecommunications, IT)

That means you meet regulatory requirements already at the component level — and keep the choice of how and where you produce.

Application scenario

What a typical project looks like

For automotive suppliers, the starting point is usually the same: regulatory pressure from multiple directions — the CRA deadline, CSMS obligations under UN R155/R156, requirements from ISO/SAE 21434 — and limited internal capacity to build a dedicated security infrastructure for it.

Here's what the path looks like with btv SEEL®:

  1. Assessment. Which components are affected, which standards apply, which evidence is missing.
  2. Integration. Your PKI is connected via btv SEEL® INTERCONNECT. Your root certificates stay with you.
  3. Programming. Firmware is provided encrypted and processed RAM-only.
  4. Documentation from go-live. The audit trail and cryptographic logs are available from the very first programmed component — not just once the audit happens.
  5. Audit preparation. The evidence package is ready when the auditor arrives.

You meet the requirements without building a security infrastructure internally.

At a glance

  • Patent-pending high-security process: for microcontroller programming.
  • Protection of sensitive firmware: right from the production stage.
  • RAM-only programming: without permanent storage in plain text.
  • Integration of the customer’s own PKI: root certificates remain with the manufacturer.
  • Unique device identities: in mass production.
  • Complete audit trail: with traceability at chip level.
  • Support for CRA, NIS 2 and Data Act requirements: documented and auditable.

Revamp your device security and compliance now

Chain of Trust

FAQ – direct, honest, to the point

The firmware you provide, encrypted, is processed exclusively in volatile memory. Once programming is complete, an automated, irreversible memory wipe follows. No unencrypted temporary files and no persistent copies on storage media are ever created. If power is cut, the stored content is lost.

btv SEEL® INTERCONNECT connects your own PKI. Your root certificates remain 100 percent under your control. During the critical decryption step, the programming environment also has no direct external connection.

btv SEEL® CORE secures the flashing process itself through the RAM-only principle. btv SEEL® INTERCONNECT connects your own PKI, so root certificates never leave your organization. btv SEEL® UNLIMITED scales that to individual device identities in series production — with an automatically documented, cryptographically signed audit trail for every process step.

We use asymmetric 4K encryption, public-private key procedures and signature-based authentication mechanisms. Sensitive firmware is processed only temporarily in RAM and fully deleted after programming. Data exchange takes place in controlled, protected data rooms.

The mechanism is the same regardless of industry: individual keys per device, RAM-only processing, a complete audit trail. Whether automotive, aerospace, medical technology, Industry 4.0 or critical infrastructure — you generate the compliance evidence out of production itself, instead of reconstructing it afterwards.

btv technologies is certified to ISO 9001 and IATF 16949. In addition, btv technologies has completed the TISAX® standardization process and has been listed on the ENX portal.

Yes. btv SEEL® delivers the evidence that the Cyber Resilience Act, NIS2 and the Data Act require at the component level — traceability down to the individual chip, documented key sovereignty, and a signed audit trail for every process step. Conformity of your end product remains your responsibility; we make sure you can prove it from the point of programming onward.

Secure full control – now.

What if you could meet tomorrow's security and compliance standards today?

The btv SEEL® Ecosystem consistently meets the requirements of: CyberResilience Act, NIS2, Data Act, and other international standards.

Watch the webinar now (GERMAN ONLY) 

Watch the explanatory video

Trusted by market leaders

With btv SEEL®, we meet the highest security requirements in the automotive sector –
 in an uncomplicated, flexible, and transparent manner.

Interested?

Contact us for a personal consultation on the CRA-compliant implementation of btv SEEL® in your company.

Experience the difference now – schedule a demo

IC, flash, EEPROM and microcontroller programming for samples, small batches and series production – documented, traceable and delivered on schedule.

What btv SEEL® Really Contributes to CRA Compliance

CRA reporting obligations apply from September 2026. What that means for your programming process — and where btv SEEL® fits in.

NIS2 or the CRA — or Both?

Two frameworks, two different goals. We break down NIS2 and the CRA, connect them to BSI TR-03183 and EN 18031 — and explain what this means for your components.

EN 18031: The Deadline That's Already Here

While everyone talks about the 2027 CRA deadline, EN 18031 has been mandatory since 1 August 2025 — no transition period. Here's who's affected and what needs to be provable now.

Electronics industry 2025: Between crisis and reorientation

Chip crisis, cost pressure and shifting alliances shaped the German electronics industry in 2025. What changed in the supply chain — and why resilience now depends on earlier decisions.

Testing, taping, PCB analysis and reconditioning for electronic components – modular, auditable, IATF 16949 certified.

What Really Happened to Your Component?

A component passes through many stations — from goods receipt to handover. Why the link between component, process step, and outcome often gets lost, and how a Chain of Trust fixes that.

CRA Compliance in the Supply Chain: Who Is Already Ready – and What That Means in Practice

From December 2027, firmware traceability, auditability and recall readiness are mandatory – for manufacturers and their entire supply chain. What the Cyber Resilience Act specifically demands and how companies can prepare now.

Cyber Resilience Act: Are You CRA-Ready?

Reporting obligations from September 2026, full applicability from December 2027. What this means for automotive and electronics manufacturers.

Customized supply chain, value-added services, and long-term storage for automotive, industrial, semiconductor, medical technology, and more—all from a single source.

Experience component logistics, programming, testing, storage, and technical services in a whole new way: modularly combinable, transparent, and precisely tailored to your requirements.

btv technologies at electronica 2024: Innovation leader in component logistics

Discover how btv technologies redefined the future of component logistics at electronica 2024. From revolutionary solutions to exciting encounters - experience our successful trade fair appearance in retrospect.

Security in detail: the btv SEEL® process

Imagine you have the latest technology in your hands - a car full of IoT innovations, a smart home. But what good is all that high-tech if the most critical point is a security vulnerability? What good are all your innovative encryption techniques if cybercriminals get hold of your confidential keys?

The invisible danger: cyber security in the digital age

Data is the gold of the 21st century. Cyber criminals are aware of this and try to steal as much of their victims' electronic data as possible in their attacks. The threat of cyber attacks is constantly increasing.