We are proud to announce an important achievement for the DOSS project: three ETSI documents – two Technical Reports and one Technical Specification – based on research and technical results developed within the DOSS project have been published, bringing key project concepts and methodologies into the European standardisation landscape.
The three publications address complementary aspects of the DOSS approach to securing IoT products and their supply chains: managing security information throughout the device lifecycle, transforming security standards into actionable requirements, and systematically validating the security of IoT components.
Together, they represent an important step towards transferring DOSS research results into approaches that can be applied beyond the project and contribute to the wider European cybersecurity ecosystem.
ETSI TR 104 285 – Device Security Passport
ETSI TR 104 285, “Device Security Passport”, introduces the Device Security Passport (DSP) as a mechanism for aggregating and referencing security-related information associated with connected devices.
Today, relevant information about a device may be distributed across Software Bills of Materials (SBOMs), Hardware Bills of Materials (HBOMs), vulnerability information, security assessment results and other documents and repositories. The DSP provides a common logical entry point through which this information can be connected and managed throughout the device lifecycle.
The report specifically describes the implementation of the DSP within the DOSS Supply Trust Chain, where the passport supports the exchange and reuse of security information between the different actors involved in an IoT product’s lifecycle.
This can improve transparency, traceability and automation across device supply chains and support continuous security management as products, vulnerabilities and their operating environments evolve.
Importantly, the report also examines the DSP in the context of European cybersecurity regulation, including the Cyber Resilience Act (CRA), NIS2 Directive and EU Cybersecurity Act.
ETSI TS 104 286 – Digital Transformation of Security Standards into Requirements
A second major challenge addressed by DOSS is turning complex security standards and regulatory documents into requirements that can actually be used in engineering and security assessment processes.
ETSI TS 104 286, “Digital Transformation of Security Standards into Requirements”, specifies an AI-driven methodology for the semi-automated transformation of security standards into structured security requirements.
The methodology uses Large Language Models to support the identification, extraction and classification of security requirements from standards and regulations. The resulting requirements can be represented in a structured, human- and machine-readable form and traced back to their source clauses.
This is particularly relevant as European legislation such as the CRA significantly increases the number of organisations that need to understand, implement and demonstrate compliance with cybersecurity requirements.
By making the transformation of standards into actionable requirements more systematic and automatable, the methodology can support security engineers, auditors, conformity assessment bodies, tool developers and other stakeholders involved in compliance and certification activities.
ETSI TR 104 287 – Security Validation Methodology for IoT Components
Security information and requirements ultimately need to be supported by evidence demonstrating that components have actually been tested.
ETSI TR 104 287, “Security Validation Methodology for IoT components”, describes a unified methodology for automated security testing of IoT components. The methodology was influenced by research and implementation results from DOSS and brings together different testing techniques within a coherent validation process.
These include Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), firmware fuzzing and security patch validation.
A particularly important connection with the wider DOSS concept is the integration of testing evidence with the Device Security Passport. Findings, coverage information and evidence from patch validation can become part of the security information associated with a component, helping manufacturers, integrators and operators assess its security posture and maintain an auditable security history throughout its lifecycle.
The methodology therefore connects security testing with supply-chain transparency and lifecycle security assurance, while also supporting emerging regulatory and certification requirements such as those introduced by the CRA.
From DOSS research to European standardisation
The publication of these three ETSI documents is an important milestone for DOSS. It demonstrates how project results can move beyond research prototypes and individual use cases and contribute to reusable methodologies and standardisation activities with relevance for the wider IoT ecosystem.
The three publications also reflect the integrated philosophy behind DOSS: security requirements need to be understood and made actionable; components need to be systematically tested against security expectations; and the resulting security information and evidence need to remain accessible and traceable throughout the supply chain and product lifecycle.
By bringing these concepts into ETSI, DOSS contributes to the longer-term goal of making secure-by-design, supply-chain-aware and lifecycle-oriented cybersecurity more systematic, interoperable and automatable.
This achievement also demonstrates the importance of European research projects as a bridge between innovative cybersecurity research, practical implementation, regulation and standardisation.
These documents are available for download from the ETSI website:
ETSI TR 104 285: Device Security Passport
ETSI TS 104 286: Digital Transformation of Security Standards into Requirements
ETSI TR 104 287: Security Validation Methodology for IoT components
