ASEC
Closing the Exposure Window00
Research 19.03.2026 13 min read

What the assessors actually check.

ComplianceUASSupply Chain

A manufacturer-facing read of defence supply-chain drone assessment: hardware integrity, software security, provenance, and the controls behind each.

Getting a platform onto a trusted-drone list is no longer a boutique exercise. Third-party assessment against a published standard covers hardware integrity, software security, supply-chain provenance, and cybersecurity controls — and the assessment is now run as an acquisition function, at scale.

This is a read of what that means in engineering terms, written for the people who have to pass it.

Component provenance

The critical systems are named: flight controllers, radio transmitters, data links, cameras, gimbals, and core electronics. Provenance has to be demonstrable for each, down the supply chain, not asserted in a spreadsheet.

Software security

  • A software bill of materials that matches what actually ships.
  • Signed, verified boot on every path — see our secure boot work.
  • Encrypted command and telemetry links with per-device keys.
  • A documented, exercised process for shipping a security fix.

Where manufacturers lose time

Not on the paperwork. On discovering, two weeks before assessment, that a verification routine never ran, or that a supplier substituted a radio module without telling anyone. Both are findings we produce routinely, months earlier, for a fraction of the cost of a failed assessment.

The Canadian angle

Canadian manufacturers face the same technical bar plus a domestic one: Transport Canada requires a safety assurance declaration for advanced and complex operations, and the technical standard behind it treats the command-and-control link as a safety system. Security work done for one requirement is largely reusable for the other. We scope engagements so that it is.

Same stack. Different aircraft.

If this reads like something in your programme, it probably is. Send us the architecture and we'll come back with a scope.

Talk to us

Research
08.10.2026

Infected Drones: when the aircraft attacks the ground station.

Six ground-control and middleware projects, fifteen findings, one broken trust boundary. A compromised drone does not have to stay on the vehicle — it can reach up the command chain and own the operator.

9 minRead →
Research
02.09.2026

Damn Vulnerable Drone: a whole aircraft you are allowed to break.

The training range we build and maintain in the open — a simulated airframe, ground station, and radio link, free for anyone learning to attack autonomous systems.

4 minRead →
Research
19.08.2026

MAVLink without a seatbelt.

A field study of telemetry links across eleven commercial aircraft, and what it takes to fly one from the ground.

12 minRead →