Cybersecurity for embedded systems

The growing number of connected embedded devices — in industrial, IoT, medical, automotive and energy applications — has turned cybersecurity from an optional feature into a binding requirement, for both market and regulatory reasons. The Cyber Resilience Act, the RED Delegated Act and the NIS2 directive already impose specific security requirements today for products placed on the European market. At Protech we support our customers through the entire product lifecycle: from requirements gathering to design, from implementation to validation, up to maintenance in the field.

Our many years of experience with embedded systems based on ARM SoCs and microcontrollers, on embedded Linux and on real-time operating systems, allows us to approach cybersecurity in an integrated way: not as a layer bolted on afterwards, but as a design element present from the concept stage.

We provide the know-how needed to interpret the regulations applicable to your product, translate them into concrete technical requirements, and implement them with the technologies best suited to the chosen platform.

Consulting & threat modeling

CRA / RED / NIS2 compliance

Secure Boot & chain of trust

ARM TrustZone & OP-TEE

Secure firmware update

System hardening

We support our customers through every stage needed to develop a secure product

Consulting & compliance

Security assessment of existing products, definition of requirements at the concept stage, threat modeling (STRIDE) and risk analysis. Interpretation and application of the Cyber Resilience Act (EU Reg. 2024/2847), the RED Delegated Act (art. 3.3 d/e/f), NIS2, and the relevant technical standards: ETSI EN 303 645, IEC 62443. We support the customer in drafting the technical security file, generating the SBOM, and defining the vulnerability handling process.

Secure Boot & Trusted Execution

Design and implementation of the secure boot process on ARM SoCs (NXP i.MX, ST STM32MPx, etc.): signed images, HAB, signed FIT images, U-Boot with verified boot, dm-verity and filesystem encryption. Development of Trusted Applications with OP-TEE, integration of Trusted Firmware-A (Cortex-A) and Trusted Firmware-M (Cortex-M), use of ARM TrustZone for secure/non-secure world separation and protection of keys and secrets.

Secure update & hardening

Implementation of secure firmware update mechanisms: signed and verified packages, A/B partitioning, anti-rollback, lifecycle management of certificates and cryptographic keys. Hardening of embedded Linux (kernel lockdown, MAC with SELinux or AppArmor, attack surface reduction, privilege management) and of bare-metal or FreeRTOS-based firmware.

Advantages

  • Integrated hardware and software approach: the same partner who designs the board also implements security.
  • Direct knowledge of the toolchains, SoCs and architectures used by the customer.
  • Well-established experience with embedded Linux, RTOS and bare-metal firmware.
  • Ability to work both on new projects and on products already in production that need to comply with new regulations.

Benefits

  • Reduced time-to-compliance, thanks to a well-established working method and in-depth knowledge of the regulatory framework.
  • Minimized risk of non-compliance already at the design stage.
  • Security by design, not bolt-on: countermeasures designed consistently with the product's architecture.
  • Technical dossier ready for certification and marking processes.

Want to know more?

Call us right away or send an email to 
info@protechgroup.it

Contact

Protech s.a.s. di Girardi A. & c. 
Registered Office: Via dei Pini 21, 31033 - CASTELFRANCO VENETO (TV) - Italy 
VAT/Tax ID 03510960267 - SDI Code WP7SE2Q
info@protechgroup.it

© 2000-2026 Protech Engineering. All rights reserved · Privacy Policy