Blog Post
From Innovation to Standard: How RESCALE Is Building a…
A secure supply chain cannot depend on trust alone. It needs evidence, and that evidence must be understandable, verifiable, and reusable across organisations, industries, and national borders. This is where standardisation becomes essential. RESCALE is developing a holistic cybersecurity assessment framework for software and hardware supply chains, centred on the Trusted Bill of Materials, or TBOM. However, creating effective technical solutions is only part of the challenge. For these solutions to achieve long-term impact, their terminology, processes, outputs, and trust mechanisms must connect with recognised standards, certification frameworks, and European cybersecurity requirements. The RESCALE Contribution to Standardisation White Paper 2025 explains how the project intends to establish this connection and identifies the results that could contribute to future standards in supply chain security, certification, and trust management.
1. Creating a Common Language for Supply Chain Security
Before organisations can exchange security evidence, they must agree on what that evidence means. Software and hardware supply chain cybersecurity currently brings together a wide range of overlapping terms, assurance models, regulatory requirements, and technical processes. Different stakeholders may use different expressions for similar concepts, which can make interoperability, certification, and conformity assessment more difficult. RESCALE addresses this challenge through its Reference Architecture and Glossary, which define the project’s main architectural elements and establish a shared vocabulary for trusted supply chains. These concepts include the Trusted Bill of Materials, the Static Supply Chain Guarantee, the Dynamic Supply Chain Guarantee, and the Bill of Vulnerabilities. By consolidating this terminology, RESCALE provides a common foundation that can be understood by developers, manufacturers, security professionals, auditors, regulators, and end users. The Reference Architecture therefore functions not only as a technical design for the RESCALE platform, but also as a potential blueprint for wider European and international discussions on supply chain assurance.
2. Moving from a Bill of Materials to a Trusted Bill of Materials
A traditional Bill of Materials can identify the components included in a digital product, but an inventory alone does not demonstrate that those components have been securely developed, tested, or continuously monitored. RESCALE extends this concept through the Trusted Bill of Materials. The TBOM combines information about hardware and software components with evidence produced by static and dynamic security testing. It can incorporate the Static Supply Chain Guarantee, the Dynamic Supply Chain Guarantee, known vulnerability information, and proof that relevant testing activities have taken place. In this way, the TBOM becomes more than a list of dependencies. It becomes a structured, traceable, and reproducible assurance artefact that can support security evaluation throughout the lifecycle of a product. The approach is designed to build upon established machine-readable BOM formats such as CycloneDX and SPDX while adding the evidence needed to support security certification and continuous assurance. For manufacturers, integrators, auditors, and users, this creates a clearer view of what a product contains, how its components were assessed, and what security findings must still be addressed.
3. Transforming Security Testing into Reusable Assurance Evidence
Security testing is most valuable when its results can be preserved, interpreted, and reused beyond a single assessment. RESCALE therefore develops a modular toolbox that converts different security evaluation activities into structured supply chain guarantees. The Static Code Analysis Module examines source code without executing it, helping developers detect coding errors, vulnerabilities, and security weaknesses early in the development process. Its results are captured in the Static Supply Chain Guarantee and are designed to reflect assurance principles associated with frameworks such as Common Criteria. The Dynamic Testing Module evaluates applications, binaries, and hardware components during execution. It combines dynamic analysis, runtime monitoring, fuzzing, and hardware side-channel leakage assessment to produce the Dynamic Supply Chain Guarantee. RESCALE also develops RAISE, the REST API Intelligent Security Explorer, which extends automated API testing through machine learning enhanced fuzzing. RAISE generates sequences of API requests to identify security weaknesses in cloud and microservice-based environments. Through the RESCALE Platform and its Advanced Visualisation Toolkit, these results can be integrated into role-based views that support monitoring, decision-making, incident management, and auditing. The key contribution is that assessment findings do not remain isolated inside individual testing tools. They become part of a structured evidence chain that can support future reassessment, certification, vulnerability management, and regulatory compliance.
4. Making Trust Evidence Verifiable Without Exposing Sensitive Information
Security evidence must be protected from manipulation, but publishing complete technical reports could expose sensitive information about products, components, vulnerabilities, or testing environments. RESCALE addresses this balance through its Trust Storage Platform. Instead of placing complete TBOMs and assessment reports directly on a public blockchain, the platform records cryptographic hashes that act as verifiable references to the original evidence. These hashes make unauthorised changes detectable while allowing the underlying reports to remain protected. This approach supports integrity, traceability, transparency, and immutability without requiring the public disclosure of confidential security information. The Trust Storage Platform can also connect with existing standards and mechanisms for identity, digital signatures, secure key storage, and signed supply chain statements. Relevant technologies include X.509 certificates, PKCS#7 or Cryptographic Message Syntax, PKCS#11, CycloneDX, and the registration and verification mechanisms being developed by the IETF Supply Chain Integrity, Transparency, and Trust working group. Together, these elements could support a Trusted Certification Evidence Repository model in which assurance evidence is securely linked, cryptographically verifiable, and usable across different organisations and certification environments.
5. Connecting RESCALE with International Standards and European Regulation
RESCALE does not develop its approach in isolation. The project maps its results to a broad ecosystem of standards, standardisation bodies, certification initiatives, and European regulatory requirements. ISO/IEC 27001 and the wider ISO/IEC 27000 series provide controls related to supplier relationships, supply chain security, configuration management, monitoring, and information security governance. ISO/IEC 20243 addresses trusted technology providers and ICT supply chain risk mitigation, while ISO/IEC 15408 and ISO/IEC 18045 provide internationally recognised methods for security evaluation. NIST SP 800-115 offers guidance for technical security testing, and NIST SP 800-161 provides a structured approach to cybersecurity supply chain risk management. ETSI standards and technical reports are relevant to IoT security, threat and vulnerability assessment, secure updates, and supply chain risk management. CycloneDX and SPDX provide established foundations for machine-readable Bills of Materials, while IETF SCITT focuses on interoperable mechanisms for registering and verifying trustworthy supply chain statements. CEN-CENELEC JTC 13, IEC, ISO committees, and ENISA certification initiatives provide further pathways for aligning RESCALE results with European and international conformity assessment practices.
This alignment also connects RESCALE with the NIS2 Directive and the Cyber Resilience Act. RESCALE’s TBOM, continuous security validation mechanisms, security assessment reports, and cryptographically verifiable evidence can support organisations addressing supply chain risk management requirements under NIS2 Article 21. The same capabilities can help manufacturers and other stakeholders organise evidence related to the secure development, vulnerability management, lifecycle assurance, and transparency requirements associated with Annex I of the Cyber Resilience Act. RESCALE does not replace formal certification or conformity assessment. Instead, it provides practical tools, structured outputs, and traceable evidence that can make these processes more effective and easier to demonstrate.
6. Turning Research Results into a Standardisation Journey
Standardisation is not simply a final step that takes place after technical development has been completed. It is a continuous process that helps ensure that research results can be understood, adopted, integrated, and trusted outside the environment in which they were created. RESCALE is therefore engaging with key communities including ETSI TC CYBER, IETF SCITT, CEN-CENELEC JTC 13, ISO, IEC, and ENISA. As part of this effort, Athena Research Centre presented the RESCALE project to the SCITT working group during IETF 123 in Madrid. The presentation introduced the project’s concepts and opened discussions on how RESCALE could use SCITT mechanisms and contribute practical supply chain security use cases to the working group. These interactions provide an opportunity to test interoperability, refine the project’s approach, and ensure that RESCALE’s results remain compatible with developing international practices.
Building a Shared Foundation for Trusted Supply Chains
The RESCALE White Paper shows that the project is building more than a collection of cybersecurity tools. It is developing a structured approach to supply chain assurance that combines shared terminology, static and dynamic testing, continuous monitoring, structured security evidence, and cryptographic verification. The Reference Architecture creates a common language, the TBOM transforms component inventories into assurance artefacts, the testing modules generate reusable guarantees, and the Trust Storage Platform protects the integrity of the resulting evidence. By connecting these results with established standards and European regulatory frameworks, RESCALE is working to ensure that its innovations can support a wider community of manufacturers, developers, auditors, regulators, and end users.
The next generation of secure software and hardware supply chains will not be built by a single platform or organisation. It will depend on collaboration, interoperability, and a common language of trust. RESCALE’s contribution to standardisation is an important step toward making that shared foundation practical, transparent, and verifiable.
Read the whole whitepaper here.