What the assessors actually check.
A manufacturer-facing read of defence supply-chain drone assessment: hardware integrity, software security, provenance, and the controls behind each.
Getting a platform onto a trusted-drone list is no longer a boutique exercise. Third-party assessment against a published standard covers hardware integrity, software security, supply-chain provenance, and cybersecurity controls — and the assessment is now run as an acquisition function, at scale.
This is a read of what that means in engineering terms, written for the people who have to pass it.
Component provenance
The critical systems are named: flight controllers, radio transmitters, data links, cameras, gimbals, and core electronics. Provenance has to be demonstrable for each, down the supply chain, not asserted in a spreadsheet.
Software security
- A software bill of materials that matches what actually ships.
- Signed, verified boot on every path — see our secure boot work.
- Encrypted command and telemetry links with per-device keys.
- A documented, exercised process for shipping a security fix.
Where manufacturers lose time
Not on the paperwork. On discovering, two weeks before assessment, that a verification routine never ran, or that a supplier substituted a radio module without telling anyone. Both are findings we produce routinely, months earlier, for a fraction of the cost of a failed assessment.
The Canadian angle
Canadian manufacturers face the same technical bar plus a domestic one: Transport Canada requires a safety assurance declaration for advanced and complex operations, and the technical standard behind it treats the command-and-control link as a safety system. Security work done for one requirement is largely reusable for the other. We scope engagements so that it is.
ASEC