Skip to main content
FDIE
Assessment coverage

See what the checks cover.

This inventory records the technical mappings configured in FDIE. A mapped check is not a complete assessment of a standard, legal applicability or conformity. Missing evidence remains unassessed.

Inventory dated 16 September 2026 · 60 technical checks across the suite.

A framework may map only some categories or use broad mechanism-family references. These mappings need specialist review against the applicable edition and product. NIST IR 8259A device identification, hardware validation and organisational lifecycle processes cannot be established from firmware bytes alone. CRA disclosure review is separate and has no conformity grade.

Scores weight assessed controls by severity. Unassessed and not-applicable controls are excluded from that score and remain visible in coverage counts. A raw pass rate is a different metric. Each assessment should be reviewed with its own mapping and profile version.

Source inventory identity

SHA-256: a13128efb566020e8eef43058129008ea1dde9ffbee947c81dc88b451ec791b7

Identifies the source mapping inventory used for this page, not an independently certified mapping or a particular deployed assessment.

OWASP Firmware Security Testing Methodology · 1.0 · 47 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for OWASP Firmware Security Testing Methodology
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityStage 5
TC-CRED-03 · Password hash strength assessmentCredential SecurityStage 5
TC-CRED-04 · API key and token detectionCredential SecurityStage 5
TC-CRED-05 · Embedded private key detectionCredential SecurityStage 5
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecurityStage 5
TC-CRED-07 · Account with no password setCredential SecurityStage 5
TC-CRYPTO-01 · MD5 usage in security contextCryptographyStage 5
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographyStage 5
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographyStage 5
TC-CRYPTO-04 · RSA key length validationCryptographyStage 5
TC-CRYPTO-05 · TLS version enforcementCryptographyStage 5
TC-CRYPTO-06 · Certificate validationCryptographyStage 5
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographyStage 5
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyStage 5
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographyStage 5
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographyStage 5
TC-CRYPTO-11 · ECB block-cipher modeCryptographyStage 5
TC-BIN-01 · Stack canary detectionBinary HardeningStage 5
TC-BIN-02 · NX/DEP bit verificationBinary HardeningStage 5
TC-BIN-03 · PIE/ASLR verificationBinary HardeningStage 5
TC-BIN-04 · RELRO configurationBinary HardeningStage 5
TC-BIN-05 · Debug symbol strippingBinary HardeningStage 5
TC-BIN-06 · Insecure RPATH/RUNPATHBinary HardeningStage 5
TC-ATK-01 · Telnet service detectionAttack SurfaceStage 5
TC-ATK-02 · FTP service detectionAttack SurfaceStage 5
TC-ATK-03 · Debug tool presenceAttack SurfaceStage 5
TC-ATK-04 · UART debug shell detectionAttack SurfaceStage 5
TC-ATK-06 · Web interface privilege checkAttack SurfaceStage 5
TC-CVE-01 · OS and kernel CVE scanKnown VulnerabilitiesStage 5
TC-CVE-02 · BusyBox CVE scanKnown VulnerabilitiesStage 5
TC-CVE-03 · TLS library CVE checkKnown VulnerabilitiesStage 5
TC-CVE-05 · Known vulnerable binary hash matchKnown VulnerabilitiesStage 5
TC-CVE-06 · Firmware-wide critical CVE presenceKnown VulnerabilitiesStage 5
TC-CVE-07 · CVE regression from prior firmware versionKnown VulnerabilitiesStage 5
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown VulnerabilitiesStage 5
TC-CVE-09 · End-of-life component in the SBOMKnown VulnerabilitiesStage 5
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime BehaviourStage 7
TC-RUN-02 · Network-reachable command execution surfaceRuntime BehaviourStage 7
TC-ATK-08 · Brute-force protection on network authenticationAttack SurfaceStage 5
TC-ATK-09 · Pre-authentication information disclosureAttack SurfaceStage 5
TC-ATK-10 · Redundant root-privileged accountAttack SurfaceStage 5
TC-ATK-11 · Security event logging presentAttack SurfaceStage 5
TC-ATK-12 · Management interface served over cleartext HTTPAttack SurfaceStage 5
TC-CODE-01 · Command or code injection in shipped scriptsCode SecurityStage 5
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode SecurityStage 5
TC-CODE-03 · Untrusted input selects a file pathCode SecurityStage 5
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode SecurityStage 5
NIST SP 800-193 · Final · 9 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for NIST SP 800-193
CheckCategoryConfigured reference
TC-UPD-01 · Update signature verification presenceFirmware Update4.1.2
TC-UPD-03 · Rollback protectionFirmware Update4.1.3
TC-UPD-04 · Pre-installation integrity checkFirmware Update4.1.2
TC-UPD-05 · Unsigned update rejectionFirmware Update4.1.1
TC-ATK-11 · Security event logging presentAttack Surface4.1.4
TC-BOOT-01 · Bootloader signature verificationSecure Boot4.1.1
TC-BOOT-02 · Boot measurement capabilitySecure Boot4.2.3
TC-BOOT-03 · Recovery partition presenceSecure Boot4.3.1
TC-BOOT-04 · Runtime integrity verificationSecure Boot4.2.1
ETSI EN 303 645 · v2.1.1 · 44 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for ETSI EN 303 645
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential Security5.1-1
TC-CRED-02 · Default credential database matchCredential Security5.1-1, 5.1-2
TC-CRED-03 · Password hash strength assessmentCredential Security5.4
TC-CRED-05 · Embedded private key detectionCredential Security5.4
TC-CRED-06 · Credentials stored in clear text on the deviceCredential Security5.4-1
TC-CRED-07 · Account with no password setCredential Security5.1-1
TC-UPD-01 · Update signature verification presenceFirmware Update5.3-3
TC-UPD-02 · Update channel encryptionFirmware Update5.3-2
TC-UPD-04 · Pre-installation integrity checkFirmware Update5.3-3
TC-CRYPTO-01 · MD5 usage in security contextCryptography5.5
TC-CRYPTO-02 · SHA-1 usage in security contextCryptography5.5
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)Cryptography5.5
TC-CRYPTO-05 · TLS version enforcementCryptography5.5
TC-CRYPTO-06 · Certificate validationCryptography5.5
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)Cryptography5.5
TC-CRYPTO-09 · Broken hash algorithm (MD4)Cryptography5.5
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)Cryptography5.5
TC-CRYPTO-11 · ECB block-cipher modeCryptography5.5
TC-ATK-01 · Telnet service detectionAttack Surface5.6-1
TC-ATK-02 · FTP service detectionAttack Surface5.6
TC-ATK-03 · Debug tool presenceAttack Surface5.6-2
TC-ATK-04 · UART debug shell detectionAttack Surface5.6
TC-ATK-05 · Unnecessary network servicesAttack Surface5.6-1
TC-ATK-06 · Web interface privilege checkAttack Surface5.6-3
TC-ATK-07 · Vulnerability disclosure policy presenceAttack Surface5.2
TC-CVE-01 · OS and kernel CVE scanKnown Vulnerabilities5.3
TC-CVE-02 · BusyBox CVE scanKnown Vulnerabilities5.3
TC-CVE-03 · TLS library CVE checkKnown Vulnerabilities5.3
TC-CVE-04 · SBOM generationKnown Vulnerabilities5.3
TC-CVE-06 · Firmware-wide critical CVE presenceKnown Vulnerabilities5.3
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown Vulnerabilities5.3
TC-CVE-09 · End-of-life component in the SBOMKnown Vulnerabilities5.3
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime Behaviour5.13-1
TC-RUN-02 · Network-reachable command execution surfaceRuntime Behaviour5.13-1
TC-ATK-08 · Brute-force protection on network authenticationAttack Surface5.1-5
TC-ATK-09 · Pre-authentication information disclosureAttack Surface5.6-2
TC-ATK-10 · Redundant root-privileged accountAttack Surface5.6-3
TC-ATK-12 · Management interface served over cleartext HTTPAttack Surface5.5-1
TC-CODE-01 · Command or code injection in shipped scriptsCode Security5.13-1
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode Security5.13-1
TC-CODE-03 · Untrusted input selects a file pathCode Security5.13-1
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode Security5.13-1
TC-BOOT-01 · Bootloader signature verificationSecure Boot5.7
TC-BOOT-04 · Runtime integrity verificationSecure Boot5.7
NIST IR 8259A · Final · 17 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for NIST IR 8259A
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityCapability 4
TC-CRED-02 · Default credential database matchCredential SecurityCapability 2
TC-CRED-07 · Account with no password setCredential SecurityCapability 4
TC-UPD-01 · Update signature verification presenceFirmware UpdateCapability 5
TC-UPD-02 · Update channel encryptionFirmware UpdateCapability 5
TC-CRYPTO-05 · TLS version enforcementCryptographyCapability 3
TC-CRYPTO-06 · Certificate validationCryptographyCapability 3
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyCapability 3
TC-ATK-01 · Telnet service detectionAttack SurfaceCapability 4
TC-ATK-05 · Unnecessary network servicesAttack SurfaceCapability 4
TC-CVE-01 · OS and kernel CVE scanKnown VulnerabilitiesCapability 5
TC-CVE-04 · SBOM generationKnown VulnerabilitiesCapability 6
TC-CVE-06 · Firmware-wide critical CVE presenceKnown VulnerabilitiesCapability 5
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown VulnerabilitiesCapability 5
TC-CVE-09 · End-of-life component in the SBOMKnown VulnerabilitiesCapability 5
TC-ATK-08 · Brute-force protection on network authenticationAttack SurfaceCapability 4
TC-ATK-12 · Management interface served over cleartext HTTPAttack SurfaceCapability 3
IEC 62443-4-2 · 2019 · 36 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for IEC 62443-4-2
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityCR 1.5
TC-CRED-02 · Default credential database matchCredential SecurityCR 1.1
TC-CRED-03 · Password hash strength assessmentCredential SecurityCR 1.5
TC-CRED-04 · API key and token detectionCredential SecurityCR 1.5
TC-CRED-05 · Embedded private key detectionCredential SecurityCR 1.5
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecurityCR 4.1
TC-CRED-07 · Account with no password setCredential SecurityCR 1.5
TC-UPD-01 · Update signature verification presenceFirmware UpdateCR 3.4
TC-CRYPTO-01 · MD5 usage in security contextCryptographyCR 4.1
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographyCR 4.1
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographyCR 4.1
TC-CRYPTO-04 · RSA key length validationCryptographyCR 4.1
TC-CRYPTO-05 · TLS version enforcementCryptographyCR 4.1
TC-CRYPTO-06 · Certificate validationCryptographyCR 4.1
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographyCR 4.1
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyCR 4.1
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographyCR 4.1
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographyCR 4.1
TC-CRYPTO-11 · ECB block-cipher modeCryptographyCR 4.1
TC-ATK-01 · Telnet service detectionAttack SurfaceCR 2.1
TC-ATK-02 · FTP service detectionAttack SurfaceCR 2.1
TC-ATK-03 · Debug tool presenceAttack SurfaceCR 2.1
TC-ATK-04 · UART debug shell detectionAttack SurfaceCR 2.1
TC-ATK-05 · Unnecessary network servicesAttack SurfaceCR 2.1
TC-ATK-06 · Web interface privilege checkAttack SurfaceCR 2.1
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime BehaviourCR 3.5
TC-RUN-02 · Network-reachable command execution surfaceRuntime BehaviourCR 3.5
TC-ATK-08 · Brute-force protection on network authenticationAttack SurfaceCR 1.11
TC-ATK-10 · Redundant root-privileged accountAttack SurfaceCR 2.1
TC-ATK-11 · Security event logging presentAttack SurfaceCR 6.1
TC-ATK-12 · Management interface served over cleartext HTTPAttack SurfaceCR 4.1
TC-CODE-01 · Command or code injection in shipped scriptsCode SecurityCR 3.5
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode SecurityCR 3.5
TC-CODE-03 · Untrusted input selects a file pathCode SecurityCR 3.5
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode SecurityCR 3.5
TC-BOOT-01 · Bootloader signature verificationSecure BootCR 3.4
EN 18031-1 · 2024 · 45 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for EN 18031-1
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityAUM-1
TC-CRED-02 · Default credential database matchCredential SecurityAUM-1
TC-CRED-03 · Password hash strength assessmentCredential SecurityAUM-1
TC-CRED-04 · API key and token detectionCredential SecurityAUM-1
TC-CRED-05 · Embedded private key detectionCredential SecurityAUM-1
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecurityAUM-1
TC-CRED-07 · Account with no password setCredential SecurityAUM-1
TC-UPD-01 · Update signature verification presenceFirmware UpdateSUM-1
TC-UPD-02 · Update channel encryptionFirmware UpdateSUM-1
TC-UPD-03 · Rollback protectionFirmware UpdateSUM-1
TC-UPD-04 · Pre-installation integrity checkFirmware UpdateSUM-1
TC-UPD-05 · Unsigned update rejectionFirmware UpdateSUM-1
TC-CRYPTO-01 · MD5 usage in security contextCryptographyCRY-1
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographyCRY-1
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographyCRY-1
TC-CRYPTO-04 · RSA key length validationCryptographyCRY-1
TC-CRYPTO-05 · TLS version enforcementCryptographyCRY-1
TC-CRYPTO-06 · Certificate validationCryptographyCRY-1
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographyCRY-1
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyCRY-1
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographyCRY-1
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographyCRY-1
TC-CRYPTO-11 · ECB block-cipher modeCryptographyCRY-1
TC-BIN-01 · Stack canary detectionBinary HardeningGEC-1
TC-BIN-02 · NX/DEP bit verificationBinary HardeningGEC-1
TC-BIN-03 · PIE/ASLR verificationBinary HardeningGEC-1
TC-BIN-04 · RELRO configurationBinary HardeningGEC-1
TC-BIN-05 · Debug symbol strippingBinary HardeningGEC-1
TC-BIN-06 · Insecure RPATH/RUNPATHBinary HardeningGEC-1
TC-ATK-01 · Telnet service detectionAttack SurfaceGEC-2
TC-ATK-02 · FTP service detectionAttack SurfaceGEC-2
TC-ATK-03 · Debug tool presenceAttack SurfaceGEC-2
TC-ATK-04 · UART debug shell detectionAttack SurfaceGEC-2
TC-ATK-05 · Unnecessary network servicesAttack SurfaceGEC-2
TC-ATK-06 · Web interface privilege checkAttack SurfaceGEC-2
TC-ATK-07 · Vulnerability disclosure policy presenceAttack SurfaceGEC-2
TC-ATK-08 · Brute-force protection on network authenticationAttack SurfaceGEC-2
TC-ATK-09 · Pre-authentication information disclosureAttack SurfaceGEC-2
TC-ATK-10 · Redundant root-privileged accountAttack SurfaceGEC-2
TC-ATK-11 · Security event logging presentAttack SurfaceGEC-2
TC-ATK-12 · Management interface served over cleartext HTTPAttack SurfaceGEC-2
TC-BOOT-01 · Bootloader signature verificationSecure BootRLM-1
TC-BOOT-02 · Boot measurement capabilitySecure BootRLM-1
TC-BOOT-03 · Recovery partition presenceSecure BootRLM-1
TC-BOOT-04 · Runtime integrity verificationSecure BootRLM-1
EN 18031-2 · 2024 · 18 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for EN 18031-2
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential SecuritySSM-1
TC-CRED-02 · Default credential database matchCredential SecuritySSM-1
TC-CRED-03 · Password hash strength assessmentCredential SecuritySSM-1
TC-CRED-04 · API key and token detectionCredential SecuritySSM-1
TC-CRED-05 · Embedded private key detectionCredential SecuritySSM-1
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecuritySSM-1
TC-CRED-07 · Account with no password setCredential SecuritySSM-1
TC-CRYPTO-01 · MD5 usage in security contextCryptographySCM-1
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographySCM-1
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographySCM-1
TC-CRYPTO-04 · RSA key length validationCryptographySCM-1
TC-CRYPTO-05 · TLS version enforcementCryptographySCM-1
TC-CRYPTO-06 · Certificate validationCryptographySCM-1
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographySCM-1
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographySCM-1
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographySCM-1
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographySCM-1
TC-CRYPTO-11 · ECB block-cipher modeCryptographySCM-1
EN 18031-3 · 2024 · 23 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for EN 18031-3
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityRED 3.3(f) - AUM
TC-CRED-02 · Default credential database matchCredential SecurityRED 3.3(f) - AUM
TC-CRED-03 · Password hash strength assessmentCredential SecurityRED 3.3(f) - AUM
TC-CRED-04 · API key and token detectionCredential SecurityRED 3.3(f) - AUM
TC-CRED-05 · Embedded private key detectionCredential SecurityRED 3.3(f) - AUM
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecurityRED 3.3(f) - AUM
TC-CRED-07 · Account with no password setCredential SecurityRED 3.3(f) - AUM
TC-UPD-01 · Update signature verification presenceFirmware UpdateRED 3.3(f) - SUM
TC-UPD-02 · Update channel encryptionFirmware UpdateRED 3.3(f) - SUM
TC-UPD-03 · Rollback protectionFirmware UpdateRED 3.3(f) - SUM
TC-UPD-04 · Pre-installation integrity checkFirmware UpdateRED 3.3(f) - SUM
TC-UPD-05 · Unsigned update rejectionFirmware UpdateRED 3.3(f) - SUM
TC-CRYPTO-01 · MD5 usage in security contextCryptographyRED 3.3(f) - CRY
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographyRED 3.3(f) - CRY
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographyRED 3.3(f) - CRY
TC-CRYPTO-04 · RSA key length validationCryptographyRED 3.3(f) - CRY
TC-CRYPTO-05 · TLS version enforcementCryptographyRED 3.3(f) - CRY
TC-CRYPTO-06 · Certificate validationCryptographyRED 3.3(f) - CRY
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographyRED 3.3(f) - CRY
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyRED 3.3(f) - CRY
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographyRED 3.3(f) - CRY
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographyRED 3.3(f) - CRY
TC-CRYPTO-11 · ECB block-cipher modeCryptographyRED 3.3(f) - CRY
IEC 81001-5-1 · 2021 · 39 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for IEC 81001-5-1
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential Security5.2.2
TC-CRED-02 · Default credential database matchCredential Security5.2.2
TC-CRED-03 · Password hash strength assessmentCredential Security5.2.2
TC-CRED-04 · API key and token detectionCredential Security5.2.2
TC-CRED-05 · Embedded private key detectionCredential Security5.2.2
TC-CRED-06 · Credentials stored in clear text on the deviceCredential Security5.2.2
TC-CRED-07 · Account with no password setCredential Security5.2.2
TC-UPD-01 · Update signature verification presenceFirmware Update7.2
TC-UPD-02 · Update channel encryptionFirmware Update7.2
TC-UPD-03 · Rollback protectionFirmware Update7.2
TC-UPD-04 · Pre-installation integrity checkFirmware Update7.2
TC-UPD-05 · Unsigned update rejectionFirmware Update7.2
TC-CRYPTO-01 · MD5 usage in security contextCryptography4.2
TC-CRYPTO-02 · SHA-1 usage in security contextCryptography4.2
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)Cryptography4.2
TC-CRYPTO-04 · RSA key length validationCryptography4.2
TC-CRYPTO-05 · TLS version enforcementCryptography4.2
TC-CRYPTO-06 · Certificate validationCryptography4.2
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptography4.2
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)Cryptography4.2
TC-CRYPTO-09 · Broken hash algorithm (MD4)Cryptography4.2
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)Cryptography4.2
TC-CRYPTO-11 · ECB block-cipher modeCryptography4.2
TC-BIN-01 · Stack canary detectionBinary Hardening5.4
TC-BIN-02 · NX/DEP bit verificationBinary Hardening5.4
TC-BIN-03 · PIE/ASLR verificationBinary Hardening5.4
TC-BIN-04 · RELRO configurationBinary Hardening5.4
TC-BIN-05 · Debug symbol strippingBinary Hardening5.4
TC-BIN-06 · Insecure RPATH/RUNPATHBinary Hardening5.4
TC-ATK-07 · Vulnerability disclosure policy presenceAttack Surface6.2
TC-CVE-01 · OS and kernel CVE scanKnown Vulnerabilities6.1
TC-CVE-02 · BusyBox CVE scanKnown Vulnerabilities6.1
TC-CVE-03 · TLS library CVE checkKnown Vulnerabilities6.1
TC-CVE-04 · SBOM generationKnown Vulnerabilities5.2.4
TC-CVE-05 · Known vulnerable binary hash matchKnown Vulnerabilities6.1
TC-CVE-06 · Firmware-wide critical CVE presenceKnown Vulnerabilities6.1
TC-CVE-07 · CVE regression from prior firmware versionKnown Vulnerabilities6.1
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown Vulnerabilities6.1
TC-CVE-09 · End-of-life component in the SBOMKnown Vulnerabilities6.1
FDA Premarket Cybersecurity (524B) · 2023 · 60 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for FDA Premarket Cybersecurity (524B)
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential Security(b)(1)
TC-CRED-02 · Default credential database matchCredential Security(b)(1)
TC-CRED-03 · Password hash strength assessmentCredential Security(b)(1)
TC-CRED-04 · API key and token detectionCredential Security(b)(1)
TC-CRED-05 · Embedded private key detectionCredential Security(b)(1)
TC-CRED-06 · Credentials stored in clear text on the deviceCredential Security(b)(1)
TC-CRED-07 · Account with no password setCredential Security(b)(1)
TC-UPD-01 · Update signature verification presenceFirmware Update(b)(1)
TC-UPD-02 · Update channel encryptionFirmware Update(b)(1)
TC-UPD-03 · Rollback protectionFirmware Update(b)(1)
TC-UPD-04 · Pre-installation integrity checkFirmware Update(b)(1)
TC-UPD-05 · Unsigned update rejectionFirmware Update(b)(1)
TC-CRYPTO-01 · MD5 usage in security contextCryptography(b)(1)
TC-CRYPTO-02 · SHA-1 usage in security contextCryptography(b)(1)
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)Cryptography(b)(1)
TC-CRYPTO-04 · RSA key length validationCryptography(b)(1)
TC-CRYPTO-05 · TLS version enforcementCryptography(b)(1)
TC-CRYPTO-06 · Certificate validationCryptography(b)(1)
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptography(b)(1)
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)Cryptography(b)(1)
TC-CRYPTO-09 · Broken hash algorithm (MD4)Cryptography(b)(1)
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)Cryptography(b)(1)
TC-CRYPTO-11 · ECB block-cipher modeCryptography(b)(1)
TC-BIN-01 · Stack canary detectionBinary Hardening(b)(2)
TC-BIN-02 · NX/DEP bit verificationBinary Hardening(b)(2)
TC-BIN-03 · PIE/ASLR verificationBinary Hardening(b)(2)
TC-BIN-04 · RELRO configurationBinary Hardening(b)(2)
TC-BIN-05 · Debug symbol strippingBinary Hardening(b)(2)
TC-BIN-06 · Insecure RPATH/RUNPATHBinary Hardening(b)(2)
TC-ATK-01 · Telnet service detectionAttack Surface(b)(2)
TC-ATK-02 · FTP service detectionAttack Surface(b)(2)
TC-ATK-03 · Debug tool presenceAttack Surface(b)(2)
TC-ATK-04 · UART debug shell detectionAttack Surface(b)(2)
TC-ATK-05 · Unnecessary network servicesAttack Surface(b)(2)
TC-ATK-06 · Web interface privilege checkAttack Surface(b)(2)
TC-ATK-07 · Vulnerability disclosure policy presenceAttack Surface(b)(2)
TC-CVE-01 · OS and kernel CVE scanKnown Vulnerabilities(b)(2)
TC-CVE-02 · BusyBox CVE scanKnown Vulnerabilities(b)(2)
TC-CVE-03 · TLS library CVE checkKnown Vulnerabilities(b)(2)
TC-CVE-04 · SBOM generationKnown Vulnerabilities(b)(3)
TC-CVE-05 · Known vulnerable binary hash matchKnown Vulnerabilities(b)(2)
TC-CVE-06 · Firmware-wide critical CVE presenceKnown Vulnerabilities(b)(2)
TC-CVE-07 · CVE regression from prior firmware versionKnown Vulnerabilities(b)(2)
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown Vulnerabilities(b)(2)
TC-CVE-09 · End-of-life component in the SBOMKnown Vulnerabilities(b)(2)
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime Behaviour(b)(2)
TC-RUN-02 · Network-reachable command execution surfaceRuntime Behaviour(b)(2)
TC-ATK-08 · Brute-force protection on network authenticationAttack Surface(b)(2)
TC-ATK-09 · Pre-authentication information disclosureAttack Surface(b)(2)
TC-ATK-10 · Redundant root-privileged accountAttack Surface(b)(2)
TC-ATK-11 · Security event logging presentAttack Surface(b)(2)
TC-ATK-12 · Management interface served over cleartext HTTPAttack Surface(b)(2)
TC-CODE-01 · Command or code injection in shipped scriptsCode Security(b)(2)
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode Security(b)(2)
TC-CODE-03 · Untrusted input selects a file pathCode Security(b)(2)
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode Security(b)(2)
TC-BOOT-01 · Bootloader signature verificationSecure Boot(b)(1)
TC-BOOT-02 · Boot measurement capabilitySecure Boot(b)(1)
TC-BOOT-03 · Recovery partition presenceSecure Boot(b)(1)
TC-BOOT-04 · Runtime integrity verificationSecure Boot(b)(1)
TEC 31318 Code of Practice for Securing Consumer IoT · TEC 31318:2025 Release 2.0 · 59 mapped technical checks

Publisher reference · References below reproduce the configured technical mapping, including category and mechanism-family mappings.

Configured checks for TEC 31318 Code of Practice for Securing Consumer IoT
CheckCategoryConfigured reference
TC-CRED-01 · Hardcoded credential detectionCredential Security3.1
TC-CRED-02 · Default credential database matchCredential Security3.1
TC-CRED-03 · Password hash strength assessmentCredential Security3.4
TC-CRED-04 · API key and token detectionCredential Security3.4
TC-CRED-05 · Embedded private key detectionCredential Security3.4
TC-CRED-06 · Credentials stored in clear text on the deviceCredential Security3.4
TC-CRED-07 · Account with no password setCredential Security3.1
TC-UPD-01 · Update signature verification presenceFirmware Update3.3
TC-UPD-02 · Update channel encryptionFirmware Update3.3
TC-UPD-04 · Pre-installation integrity checkFirmware Update3.3
TC-UPD-05 · Unsigned update rejectionFirmware Update3.3
TC-CRYPTO-01 · MD5 usage in security contextCryptography3.5
TC-CRYPTO-02 · SHA-1 usage in security contextCryptography3.5
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)Cryptography3.5
TC-CRYPTO-04 · RSA key length validationCryptography3.5
TC-CRYPTO-05 · TLS version enforcementCryptography3.5
TC-CRYPTO-06 · Certificate validationCryptography3.5
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptography3.5
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)Cryptography3.5
TC-CRYPTO-09 · Broken hash algorithm (MD4)Cryptography3.5
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)Cryptography3.5
TC-CRYPTO-11 · ECB block-cipher modeCryptography3.5
TC-BIN-01 · Stack canary detectionBinary Hardening3.6
TC-BIN-02 · NX/DEP bit verificationBinary Hardening3.6
TC-BIN-03 · PIE/ASLR verificationBinary Hardening3.6
TC-BIN-04 · RELRO configurationBinary Hardening3.6
TC-BIN-05 · Debug symbol strippingBinary Hardening3.6
TC-BIN-06 · Insecure RPATH/RUNPATHBinary Hardening3.6
TC-ATK-01 · Telnet service detectionAttack Surface3.6
TC-ATK-02 · FTP service detectionAttack Surface3.6
TC-ATK-03 · Debug tool presenceAttack Surface3.6
TC-ATK-04 · UART debug shell detectionAttack Surface3.6
TC-ATK-05 · Unnecessary network servicesAttack Surface3.6
TC-ATK-06 · Web interface privilege checkAttack Surface3.6
TC-ATK-07 · Vulnerability disclosure policy presenceAttack Surface3.2
TC-CVE-01 · OS and kernel CVE scanKnown Vulnerabilities3.3
TC-CVE-02 · BusyBox CVE scanKnown Vulnerabilities3.3
TC-CVE-03 · TLS library CVE checkKnown Vulnerabilities3.3
TC-CVE-04 · SBOM generationKnown Vulnerabilities3.3
TC-CVE-05 · Known vulnerable binary hash matchKnown Vulnerabilities3.3
TC-CVE-06 · Firmware-wide critical CVE presenceKnown Vulnerabilities3.3
TC-CVE-07 · CVE regression from prior firmware versionKnown Vulnerabilities3.3
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown Vulnerabilities3.3
TC-CVE-09 · End-of-life component in the SBOMKnown Vulnerabilities3.3
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime Behaviour3.13
TC-RUN-02 · Network-reachable command execution surfaceRuntime Behaviour3.13
TC-ATK-08 · Brute-force protection on network authenticationAttack Surface3.1
TC-ATK-09 · Pre-authentication information disclosureAttack Surface3.1, 3.6
TC-ATK-10 · Redundant root-privileged accountAttack Surface3.6
TC-ATK-11 · Security event logging presentAttack Surface3.10
TC-ATK-12 · Management interface served over cleartext HTTPAttack Surface3.5
TC-CODE-01 · Command or code injection in shipped scriptsCode Security3.13
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode Security3.13
TC-CODE-03 · Untrusted input selects a file pathCode Security3.13
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode Security3.13
TC-BOOT-01 · Bootloader signature verificationSecure Boot3.7
TC-BOOT-02 · Boot measurement capabilitySecure Boot3.7
TC-BOOT-03 · Recovery partition presenceSecure Boot3.9
TC-BOOT-04 · Runtime integrity verificationSecure Boot3.7
Next step

Start with one product and two releases.

Review a sample comparison with us. Then scope a supported image pair, hosting requirements and the evidence your team needs to evaluate.

or explore pricing

21-day free trial on the full platform. No card, no automatic conversion.