All techniques
IA-0001
ST0003Initial Access

Compromise Supply Chain

Description

Adversaries achieve first execution before the spacecraft ever flies by inserting malicious code, data, or configuration during manufacturing, integration, or delivery. Targets include software sources and dependencies, build systems and compilers, firmware/bitstreams for MCUs and FPGAs, configuration tables, test vectors, and off-the-shelf avionics. Inserted artifacts are designed to appear legitimate, propagate through normal processes, and activate under routine procedures or specific modes (e.g., safing, maintenance). Common insertion points align with where trust is assumed, vendor updates, mirrors and registries, CI/CD runners, programming stations, and “golden image” repositories. The result is pre-positioned access that blends with baseline behavior, often with delayed or conditional triggers and strong deniability.

Mappings

EU regulation articles

  • craAnnex I, Part II, (1)
    addresses
    high
    derived

    Manufacturer obligation to identify and document components (including via SBOM) is the upstream visibility discipline that surfaces compromised components before they ship in the product, the reverse of the asymmetry adversary supply-chain compromise exploits.

  • craAnnex I, Part II, (5)
    addresses
    moderate
    direct

    Compromise of supply chain (primary mappings: Part II, (1) + Art. 13(5) + Art. 13(6)) requires CVD policy under (5) to coordinate disclosure with upstream component manufacturers (Art. 13(6) presumes a CVD-grade discipline).

  • craArt. 13(5)
    addresses
    high
    direct

    Manufacturer due-diligence on third-party component integration is the primary obligation that bounds supply-chain compromise; CRA Art. 13(5) explicitly requires manufacturers to exercise due diligence when integrating components, including verification that components do not compromise the product's cybersecurity.

  • craArt. 13(6)
    addresses
    high
    derived

    Manufacturer obligation to act on identified vulnerabilities in contained components (including open-source) is the procedural lever that converts compromised-component discovery into product-level remediation.

  • eu-space-actArt. 76(4)
    addresses
    moderate
    direct

    76(4)(b)'s coverage of manufacturing, assembly, integration, verification, validation, and qualification phases — the manufacturing and test lifecycle — is exactly the phase IA-0001 attacks pre-flight.

  • eu-space-actArt. 76(5)
    addresses
    moderate
    direct

    Supply-chain compromise (primary: Art. 76(4) lifecycle + Art. 92(1) supply chain) is an ISMS-managed risk class; 76(5) is the management framework that integrates supply-chain risk into overall risk treatment.

  • eu-space-actArt. 92(1)
    addresses
    high
    direct

    Pre-flight insertion of malicious code/data/configuration into manufacturing and integration is the canonical case 92(1)'s supply chain risk management framework addresses — operator contracts with supplier manufacturers must include information-security requirements that govern these touchpoints.

  • eu-space-actArt. 92(2)
    addresses
    high
    direct

    92(2)'s strategy-to-reduce-risks-in-the-supply-chain (with Annex VII point 6 measures) directly targets the supply-chain insertion paths IA-0001 enumerates.

  • nis2Art. 21(2)(d)
    addresses
    moderate
    inferred

    IA-0001 inserts malicious code through the product supply chain (vendor updates, dependencies, build and integration pipelines); NIS2 21(2)(d) supply chain security governs the supplier and provider relationships this technique abuses.

  • nis2Art. 21(2)(e)
    addresses
    high
    direct

    The technique targets sources, dependencies, build systems and CI/CD runners — the precise pipeline Art. 21(2)(e)'s network-and-information-systems acquisition/development/maintenance obligation governs, including handling of disclosed weaknesses in those mechanisms.

  • nis2Art. 21(3)
    addresses
    high
    direct

    The technique exploits trust assumed at where each supplier hands off to the next; Art. 21(3) is the obligation that requires the entity to consider supplier-specific vulnerabilities and the overall quality of supplier cybersecurity practices when sizing that trust.

  • nis2-implAnnex 5.1.1
    addresses
    high
    direct

    Compromise Supply Chain is exactly the threat the supply-chain security policy is established to govern; the policy defines who the entity contracts with, the security obligations imposed on those suppliers, and the verification and audit regime applied to each tier of the parts and software pipeline.

  • nis2-implAnnex 5.1.4
    addresses
    high
    derived

    Direct-supplier security requirements (vulnerability assessment, secure-development practices, disclosure obligations) are the procedural lever the entity uses to constrain which suppliers it accepts and to push security expectations down through the chain that supply-chain compromise traverses.

  • nis2-implAnnex 5.1.5
    addresses
    moderate
    derived

    Supplier selection criteria from the supply-chain policy gate which suppliers can ever ship code, hardware or services into the entity's environment; weak selection is the precondition for chain compromise.

  • nis2-implAnnex 5.1.6
    addresses
    high
    derived

    Primary mapping to Annex 5.1.1 (supply-chain policy) for supply-chain compromise implies Annex 5.1.6 ongoing monitoring: the entity must monitor and act on supplier-conduct, vulnerability-disclosure and policy-deviation signals across the chain.

  • nis2-implAnnex 5.1.7
    addresses
    moderate
    derived

    Continuous monitoring of supplier conduct, vulnerability disclosures and contractual compliance is the procedural mechanism that surfaces a supplier becoming compromised before delivered artefacts reach flight or ground systems.

ENISA controls

  • Cyber supply chain risk management explicitly covers third-party suppliers whose compromise enables IA-0001.

  • Supplier security management is the umbrella supply-chain control governing the manufacturing, integration, and delivery contexts where IA-0001 inserts code or hardware.

  • Software supply-chain integrity through hash sums and supplier audits is the explicit control against insertion at distribution edges and update channels.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0001 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.