SESIP Paves the Way for IoT Manufacturers to Meet New European Cybersecurity Rules
12.12.2024 09:00:00 CET | Business Wire | Press release
GlobalPlatform’s SESIP methodology (EN 17927) offers a streamlined, cost-effective security framework for connected devices and components to conform to the EU’s new Cyber Resilience Act
GlobalPlatform is calling for manufacturers of connected devices and components to adopt its “Security Evaluation Standard for IoT Platforms” (SESIP) methodology to demonstrate conformance with the European Union’s new Cyber Resilience Act (CRA), which comes into force this month. The CRA aims to strengthen and harmonize cybersecurity across the EU by creating a new legal framework for all products that connect to the internet.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20241211681976/en/

(Graphic: Business Wire)
The enactment of the CRA puts into place mandatory cybersecurity rules that span the entire lifecycle of a digital product sold in the EU. The CRA was published in the Official Journal of the European Union last month and becomes law on December 11, 2024. Product manufacturers will have 36 months to fully comply with the legislation. The Act will eventually require all relevant products to comply with the rules in order to obtain the CE marking, a mandatory market requirement for issuing products in Europe.
As an internationally recognized standard for IoT security evaluation, SESIP is key to meeting the requirements mandated by the CRA. It provides manufacturers with a proven methodology for conducting security evaluations of software and hardware components across their products and supply chains. SESIP is recognized as a standard by CENELEC, the European Standardization Organization, as EN 17927. It also aligns with many other legislation and vertical certification schemes around the world, including the Cyber Trust Mark in the US.
The methodology is being used to certify components, platforms, and modules from a range of companies and is supported by a growing ecosystem of security providers, certification bodies (CBs), security laboratories, and other stakeholders. GlobalPlatform continues to support the growth and governance of the SESIP ecosystem. SGS Brightsight has recently been accredited as a SESIP CB following approval from the Spanish national accreditation body (ENAC), becoming the second SESIP CB after TrustCB.
“Industry support for SESIP is building at this critical juncture for IoT manufacturers operating in Europe,” said Gil Bernabeu, CTO of GlobalPlatform. “The Cyber Resilience Act is vital to protecting consumers and businesses by embedding security features into the heart of the connected devices we use every day, providing a cybersecurity framework that spans the design, development, and maintenance of digital products.
“However, this landmark legislation presents a range of compliance challenges for manufacturers of connected devices and the components used in these products,” continued Bernabeu. “SESIP simplifies conformity with the new regulations by providing a unified framework for comprehensive security evaluation, reducing cost, risk, and time to market. We look forward to expanding the SESIP ecosystem to help multiple industry sectors meet the requirements of the new European regulations. It will also enable international manufacturers to reuse their security evaluation investments to demonstrate conformance to non-European regulations.”
The SESIP methodology is already mapped to other standards and regulations such as ETSI, (EN 303645 / TS 103732), ISO/IEC (62443-4-2), RED (EN 18031), UNECE WP.29 (ISO/SAE 21434) and NIST (NIST 8259 / NIST 8425). It is also being used by schemes such as PSA Certified, and standardization bodies including the Car Connectivity Consortium and the Wireless Power Consortium. In addition to Europe, SESIP is being adopted around the world in key markets such as China, where an agreement was recently reached between GlobalPlatform and China’s National Financial Technology Certification Center (NFTC).
GlobalPlatform has a number of initiatives in place to help accelerate SESIP adoption. A training program has been launched and available for any interested party. It has also launched the SESIP Adopters community to give non-members the ability to keep up to date with relevant technical documents and showcase certified SESIP products.
For more information on SESIP please visit: https://globalplatform.org/sesip/
About GlobalPlatform
GlobalPlatform is a technical standards organization that enables the efficient launch and management of innovative, secure-by-design digital services and devices, which deliver end-to-end security, privacy, simplicity, and convenience to users. It achieves this by providing standardized technologies and certifications that empower technology and service providers to develop, certify, deploy, and manage digital services and devices in line with their business, security, regulatory and data protection needs. GlobalPlatform technologies are used in billions of smart cards, smartphones, wearables and other connected and IoT devices.
GlobalPlatform standardized technologies and certifications are developed through effective industry-driven collaboration, led by multiple diverse member companies working in partnership with industry and regulatory bodies and other interested parties from around the world.
globalplatform.org | Twitter / X | LinkedIn | YouTube | GitHub | WeChat
View source version on businesswire.com: https://www.businesswire.com/news/home/20241211681976/en/

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Verimatrix: Sale of Extended Threat Defense Assets (Mobile Application Protection) to Guardsquare5.2.2026 17:45:00 CET | Press release
Completion of the sale of XTD assets (code and mobile application protection), including a portfolio of patents and a team of experts.The Group is refocusing on anti-piracy (video protection), its core business, which represents approximately 90% of its total revenue. Regulatory News: Verimatrix, (Euronext Paris: VMX), a leading provider of security solutions for a safer connected world, today announced that it has completed the sale of 100% of its Extended Threat Defense (XTD) assets to Guardsquare, a Belgian company and leader in mobile application security. This transaction follows the signing of an agreement announced in a press release on December 8, 2025, as well as regulatory approval. It is part of Verimatrix's overall strategy to refocus on its core business, reflecting the group's strategic decision to concentrate on the key growth segments of the video protection market. Commenting on the announcement, Laurent Dechaux, CEO of Verimatrix, said: “Verimatrix has a strong techno
Duna, Built by Stripe Veterans, Raises €30 Million CapitalG-led Series A to Solve Business Identity For The Internet5.2.2026 15:00:00 CET | Press release
Duna, the identity fintech founded by two Stripe alumni, today announced a €30 million Series A funding round led by CapitalG, Alphabet’s independent growth fund. Existing investors Index Ventures, Puzzle Ventures and Snowflake Chairman Frank Slootman also participated in the round. The company, based in Germany and the Netherlands, was launched in 2023 by Duco van Lanschot, who was head of Benelux and DACH at Stripe for three years, and David Schreiber, who spent six years at Stripe where he ran the company’s largest global business unit, including the core card payment platform. In May 2025, the company announced a €10.7 million seed round led by Index Ventures. The latest fundraise brings Duna’s total funding to more than €40 million. Duna’s mission is to build global trust infrastructure by providing a digital passport for every business. Over time, this will evolve into a network for shareable identity and one-click onboarding. Today Duna’s AI-native business identity platform ser
AI-Powered Experian Assistant for Model Risk Management Wins 2026 BIG Innovation Award5.2.2026 15:00:00 CET | Press release
Highlights how Experian’s AI capabilities help global financial institutions keep regulatory documentation aligned with rapid model innovations Experian today announced that its recently launched, AI‑powered Experian Assistant for Model Risk Management has been awarded the 2026 BIG Innovation Award in the Innovative Products category. Recognizing trailblazers across industries since 2014, this global award celebrates exceptional innovation and the value it brings to a recipient’s clients, stakeholders and community. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260205042051/en/ Experian's recently launched, AI-powered Experian Assistant for Model Risk Management has been awarded the 2026 BIG Innovation Award in the Innovative Products category. Fully integrated into the Experian Ascend Platform™ and powered by ValidMind technology, Experian Assistant for Model Risk Management helps accelerate model validation, improve audit
LTIMindtree Recognized as a Leader in Everest Group Payments IT Services PEAK Matrix® Assessment 20255.2.2026 14:30:00 CET | Press release
LTIMindtree [NSE: LTIM, BSE: 540005], a leading global technology consulting and digital solutions provider, has been positioned as a Leader in the Everest Group Payments IT Services PEAK Matrix® Assessment 2025. This recognition is for being a strategic transformation partner that combines modernization scale, platform alliances, and innovation across real-time, digital assets, and ensure secure, regulator-ready payment environments. Everest Group highlighted LTIMindtree’s strong market impact and vision and capability in delivering largescale payments across issuers, acquirers, payment processors, card networks, and FinTechs. The assessment comes at a time when enterprises are rapidly modernizing legacy payments platforms to support real-time, cross-border, and ISO 20022 compliant payment environments, while enhancing resiliency, interoperability, and regulatory compliance. LTIMindtree stands out for its product engineering expertise across major payment platforms like Finastra GPP/P
PubNub Achieves SOC 3 Compliance, Reinforcing Commitment to Security, Trust, and Transparency5.2.2026 14:00:00 CET | Press release
PubNub, the real-time communications platform that powers low-latency, event-driven logic across modern application architectures, is pleased to announce that it has achieved SOC 3 compliance. This latest attestation highlights PubNub’s continuous dedication to providing a secure and trusted platform for building and scaling interactive online experiences. The SOC 3 report affirms that PubNub’s systems meet the Trust Services Criteria for security, availability, and confidentiality. Unlike SOC 2 reports, which are restricted to existing customers or partners due to the level of operational detail they include, SOC 3 reports are designed for broad, public distribution. This transparency enables anyone to verify that PubNub adheres to the stringent controls required by the SOC 2 framework, providing proof of robust information security and operational integrity. This achievement adds to PubNub’s extensive compliance portfolio, which includes SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA, and G
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom