Skip to main content

The Horizon Europe DOSS Project completes three years of research, bringing continuous security and trust across the entire IoT Supply Chain

The consortium of industrial actors, research institutes, and academia from 6 European countries has developed and validated an integrated Supply Trust Chain Architecture that improves the resilience of IoT Supply Chains.

.

Budapest, 31. August 2026 – The DOSS research and innovation project has concluded after three years of collaboration of its 11 European partners. The project developed an integrated Supply Trust Chain designed to improve the security, transparency and resilience of IoT products and systems – from design and testing to deployment and operation.

At the centre of the DOSS Supply Trust Chain is the Device Security Passport Platform, which provides controlled access to machine-readable security information, including software and hardware bills of materials, vulnerability information, security assessment results and test reports.

This information is used and enriched by four interconnected security modules:

  • the Component Tester, which identifies vulnerabilities in IoT components;
  • the Digital Cybersecurity Twin, which models systems and simulates potential attacks;
  • the Architecture Security Validator, which assesses security and compliance against structured requirements; and
  • the Secure Onboarding Platform, which supports the trusted deployment of devices into operational environments.

Together, these modules enable security information and evidence to be shared and updated throughout the IoT lifecycle. The Supply Trust Chain also establishes feedback loops through which vulnerabilities and attacks identified during operation can be communicated to manufacturers and developers.

The integrated DOSS approach was demonstrated and validated through three pilots covering a smart home, a prosumer energy cell and connected cars, representing different IoT environments and supply-chain relationships.

The project’s standardisation efforts have also borne fruit. Three ETSI documents based on DOSS results have been published: ETSI TR 104 285 on the Device Security Passport, ETSI TS 104 286 on the digital transformation of security standards into requirements, and ETSI TR 104 287 on security validation methodology for IoT components.

By connecting security requirements, testing, evidence, system-level assessment and secure deployment, DOSS has laid the foundations for a more transparent and continuously secured IoT ecosystem. Its results provide practical building blocks for manufacturers, technology providers, integrators and operators facing increasing cybersecurity and regulatory requirements.

The DOSS consortium brought together service operators, manufacturers, technology providers, software developers, research institutes and academic partners, ensuring that the project’s results reflected the needs of the wider European IoT ecosystem. The project was coordinated by Atos Hungary.

 

Project Key Facts

Full Name: DOSS: SECURE-BY-DESIGN IOT OPERATION WITH SUPPLY CHAIN CONTROL
Contract No.: HE – 101120270
Start date: 01 September 2023
Duration: 36 months
EU Contribution: € 5 million
Coordinator: Atos Hungary Ltd.

 

Project Partners

France
Thales SIX GTS France SAS
Red Alert Labs SAS

Germany
Fraunhofer FOKUS
asvin GmbH

Greece
Centre for Research and Technology-Hellas

Hungary
Atos Hungary Ltd.
Budapest University of Technology and Economics
SafePay Systems Ltd.

Poland
Institute of Theoretical and Applied Informatics, Polish Academy of Sciences

Spain
Fundacion Tecnalia Research & Innovation
University of Murcia

 

Contact
Tamás Nagy
Atos Hungary Ltd.
Email: ta********@**os.net

Leave a Reply