Ampyx Cyber Blog
The Intersection of Regulation & Resilience
Firmware and Bootloader: The Verification Gap in OT Infrastructure
Proving that the code running on a field device is what the vendor shipped is one of the hardest problems in industrial security. This second report in the series compares four verification mechanisms, from SHA-256 hashing to remote attestation, and maps them to the revised Network and Information Security Directive (NIS2), the Cyber Resilience Act (CRA), and Germany's BSI Act. It also looks at what US utilities learned under NERC CIP, and which compensating controls work for legacy controllers that cannot verify their own firmware.
The Execution Layer Gap: Why European Critical Infrastructure May Be Looking at the Wrong Regulatory Clock
Many European critical infrastructure operators are planning around December 2027, when the Cyber Resilience Act (CRA) fully applies. Its vulnerability reporting duty under Article 14 took effect on September 11, 2026, and it covers products already deployed in the field. This Foundation report, the first in a six-part series, looks at why regulators are turning to the firmware and bootloader layer below the operating system, how the CRA and the revised Network and Information Security Directive (NIS2) reach it, and what Germany's implementation adds.