IoT supply chain cybersecurity: From manufacturer to deployment

For B2B buyers of IoT devices, minimizing cyber risks is critical. This requires implementing a structured vendor assessment system, verifying component provenance, and ensuring secure onboarding that aligns with regulatory requirements.

In today's world, with the rapid growth of connected Internet of Things (IoT) devices, supply chain cybersecurity has become a paramount concern for every enterprise. Balancing cost, device availability, and the imperative to minimize risks from compromised components—from hardware to firmware and software—is a key challenge for CISOs, procurement heads, IoT solution architects, and compliance specialists.

Understanding IoT supply chain risks: From chip to cloud

IoT device supply chains are incredibly complex and globally distributed, making them attractive targets for cyberattacks. Risks can emerge at any stage: from chip manufacturing to the deployment of the end device. Common threats include malicious functionality embedded in hardware or software, the use of counterfeit components, or vulnerabilities passed from suppliers to end-users.

The scale of the problem is striking: as of 2024, there are over 21 billion connected devices worldwide, with approximately 820,000 cyberattacks recorded daily. More than 50% of all IoT devices contain critical vulnerabilities that can be immediately exploited by attackers, and 60% of data breaches are linked to unpatched firmware. This underscores the critical need for robust cybersecurity practices throughout the entire device lifecycle.

Assessing and qualifying IoT device suppliers: Cybersecurity criteria

Building a resilient supply chain begins with thorough supplier assessment and qualification. It's crucial to move beyond traditional criteria and focus on their cybersecurity practices. Recognized standards and recommendations exist for this purpose:

  • ETSI EN 303 645: This global standard sets baseline cybersecurity requirements for consumer IoT devices, covering secure communication, software updates, password protection, and vulnerability handling. While not a harmonized standard under the EU Cyber Resilience Act as of May 2026, it serves as a strong foundation for evaluation.
  • NIST SP 800-161: Provides guidance on Cyber Supply Chain Risk Management (C-SCRM) for systems and organizations. It helps identify, assess, and mitigate risks originating from suppliers, including hardware, software, and services.
  • ISO 27036: This standard offers guidance on information security risk management when acquiring goods and services from third parties, particularly for ICT supply chains (Part 3).

When auditing suppliers, attention should be paid to the presence of security certifications (e.g., ISO 27001), vulnerability response policies, and transparency regarding their own component supply chain.

Ensuring component integrity: From manufacturing to warehouse

To minimize risks from compromised components, their integrity must be ensured at all stages. Key tools here include:

  • Software Bill of Materials (SBOM) and Hardware Bill of Materials (HBOM): An SBOM is a complete inventory of all software components running on a device, including version, programming language, and libraries. It provides transparency in the software supply chain, allowing for quick identification of vulnerabilities and application of patches. An HBOM, in turn, lists all physical components used to build the device.

Manufacturers should provide SBOMs containing author name, supplier, component name, version string, cryptographic hash, and a unique identifier. This enables end-users to understand and mitigate risks. Secure packaging and transportation of devices are also crucial to prevent unauthorized access and modification. Hardware Security Modules (HSMs) and Trusted Platform Modules (TPMs) play a vital role by providing hardware-based cryptographic functions and secure storage for sensitive data, enhancing device integrity.

Secure onboarding and deployment of IoT devices: First steps into the ecosystem

IoT device onboarding is the process of securely connecting a new device to a network and bringing it into an operational, trusted state. It involves establishing the device's identity, authenticating it, provisioning credentials and configuration, applying firmware updates, and enforcing security policies before the device is authorized to communicate.

Key aspects of secure onboarding:

  • Device Identity Management: Each IoT device should be assigned a unique cryptographic identity early in its lifecycle, ideally during manufacturing or initial boot-up. This can be a digital certificate that enables secure, authenticated communication.
  • Secure Over-the-Air (OTA) Firmware Updates: OTA update systems must be designed so that each update is signed with a private key and verified on the device using the corresponding public key. This ensures that only trusted updates are installed, prevents tampering during transmission, and includes rollback protection against vulnerable versions.
  • Initial Security Configuration: After onboarding, devices are typically in a default mode. It's crucial to change default passwords, configure access restrictions, and ensure network segmentation to minimize potential attack vectors.
  • Automated Provisioning (Zero-touch provisioning): For large-scale IoT deployments, automating registration, broker assignment, and network connection processes is critical for scalability and reducing human error.

Compliance and regulatory requirements: Navigating the IoT security landscape

Adhering to regulatory requirements is an integral part of managing IoT supply chain cyber risks. The global IoT security landscape is rapidly evolving, and B2B buyers must stay informed about key standards:

  • EU Cyber Resilience Act (CRA): Adopted in October 2024, the CRA introduces stringent cybersecurity requirements for all products with digital elements sold in the EU market. It mandates manufacturers to integrate security-by-design principles, provide SBOMs, ensure vulnerability handling, secure updates, and cryptographic flexibility throughout the product lifecycle. Obligations for vulnerability reporting begin in September 2026, with full regulation enforcement expected in December 2027.
  • ETSI EN 303 645: As mentioned, this standard is an important foundation for baseline IoT device security, helping manufacturers ensure cybersecurity at the design stage.
  • ISO 27036: This standard, particularly Part 3, provides guidance on information security risk management in the supply chain for hardware, software, and services.

Understanding and integrating these standards into procurement and deployment processes is critical for ensuring compliance and mitigating legal and operational risks.

IoT device supplier assessment matrix

To make informed decisions regarding IoT device procurement, it is recommended to use a structured assessment matrix that considers key aspects of supply chain cybersecurity:

Assessment Criterion Description Importance for B2B Buyer
Compliance with ETSI EN 303 645 Confirmation of adherence to baseline cybersecurity requirements for IoT devices. High: Ensures a minimum level of security and compliance with European recommendations.
Availability of SBOM (Software Bill of Materials) Detailed list of all software components and their versions. Critical: Allows identification of vulnerabilities and management of software risks.
Secure firmware update mechanisms Use of cryptographic signatures, integrity verification, rollback protection. Critical: Prevents installation of malicious updates and ensures long-term security.
Support for Hardware Security Modules (TPM/HSM) Presence of hardware for key storage and integrity assurance. High: Increases trust in hardware and protection against physical attacks.
Device Identity Management processes Ensuring a unique cryptographic identity for each device. Critical: Foundation for device authentication and authorization on the network.
Manufacturer security certifications (ISO 27001, SOC 2 Type II) Confirmation of the manufacturer's mature information security management processes. High: Indicates a systematic approach to security at the organizational level.
Vulnerability response policy Presence of clear procedures for detecting, reporting, and remediating vulnerabilities. High: Guarantees timely response to new threats.
Transparency of component supply chain Supplier's ability to provide information about component origin and security. High: Allows assessment of third-party risks.

For B2B buyers aiming to minimize cyber risks and ensure regulatory compliance, AZIOT offers expertise in designing and implementing comprehensive IoT solutions that consider supply chain security from device selection to integration and ongoing management. Intecracy solutions and inbase.com.ua solutions provide robust platforms for secure IoT deployments.

Building a reliable IoT device procurement and deployment process is not a one-time action but a continuous process that requires vigilance and adaptation to the evolving threat landscape. Integrating security principles at all stages, from supplier selection to onboarding, is the only way to create a resilient and protected IoT ecosystem. This not only ensures compliance with regulatory requirements but also safeguards critical operations and data from growing cyber threats.

Source list

  1. goleadingit.comNIST SP 800-161 Explained: Cybersecurity Supply Chain Risk Management (C-SCRM) - LeadingIT
  2. complianceforge.comNIST 800-161 Compliance Resource Center | ComplianceForge
  3. ordr.netIoT Security Statistics 2024: 21B Devices, 820K Daily A… | ORDR
  4. intertek.comETSI EN 303 645 Cybersecurity Standard for Consumer IoT DevicesIntertekFlag for ArgentinaFlag for BrazilFlag for BulgariaFlag for CanadaFlag for the Czech RepublicFlag for ChileFlag for ChinaFlag for ColombiaFlag for DenmarkFlag for Dominican RepublicFlag for EcuadorFlag for FinlandFlag for FranceFlag for GermanyFlag for BulgariaFlag for GuatemalaFlag for Hong Kong SAR, ChinaFlag for ItalyFlag for MexicoFlag for The NetherlandsFlag for NorwayFlag for PeruFlag for PolandFlag for PortugalFlag for RomaniaFlag for SpainFlag for SwedenFlag for SwitzerlandFlag for ThailandFlag for United Arab EmiratesFlag for VietnamFlag for Intertek GobalLinkedInX (Twitter)FacebookYouTubeIntertekIntertekTotal Quality. Assured
  5. ul.comGuide to ETSI EN 303 645 Compliance Services | UL SolutionsUL Logo
  6. tuvsud.com
  7. craevidence.comCRA for Consumer IoT: EN 303 645 and Smart Home Security | CRA Evidence
  8. learn.microsoft.comNational Institute of Standards and Technology (NIST) SP 800-161 - Azure Compliance | Microsoft Learn