All techniques
IA-0001.03
ST0003Initial Access
sub-technique

Hardware Supply Chain

Parent: IA-0001

Description

Adversaries alter boards, modules, or programmable logic prior to delivery to create latent access or reliability sabotage. Tactics include inserting hardware Trojans in ASIC/FPGA designs, modifying bitstreams or disabling security fuses, leaving debug interfaces (JTAG/SWD/UART) active, substituting near-spec counterfeits, or embedding parts that fail after specific environmental or temporal conditions (“time-bomb” components). Other avenues target programming stations and “golden” images so entire lots inherit the same weakness. Microcontroller boot configurations, peripheral EEPROMs, and supervisory controllers are common leverage points because small changes there can reshape trust boundaries across the bus. The effect is a platform that behaves nominally through acceptance test yet enables covert control, targeted degradation, or delayed failure once on orbit.

Mappings

EU regulation articles

  • craAnnex I, Part II, (1)
    addresses
    moderate
    derived

    Component identification at hardware granularity (lot, configuration, test history) underpins the lifecycle traceability and tamper-detection workflows that resist hardware-supply-chain compromise.

  • craAnnex I, Part II, (5)
    addresses
    high
    direct

    Hardware supply-chain compromise (primary mappings: Part II, (1) + Art. 13(5)) requires CVD policy under (5) for receiving hardware-related vulnerability reports.

  • craArt. 13(5)
    addresses
    high
    derived

    Hardware-supplier due-diligence under Art. 13(5) covers foundries, board houses and IC integrators where ASIC/FPGA Trojans, modified bootloaders and pre-delivery board manipulation are introduced.

  • eu-space-actArt. 92(1)
    addresses
    high
    direct

    Hardware Trojans, modified bitstreams, and counterfeit substitutions are the canonical hardware-supply-chain compromise 92(1)'s contracts must address.

  • eu-space-actArt. 92(3)
    addresses
    moderate
    direct

    92(3)'s inventory of critical assets of non-Union origin captures dependency on hardware suppliers whose supply-chain compromise IA-0001.03 represents.

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    Hardware Trojans, modified bitstreams, and counterfeit substitutions enter via direct hardware suppliers (board fabs, FPGA IP vendors, peripheral ICs); Art. 21(2)(d) governs those supplier relationships as supply-chain security.

  • nis2Art. 21(3)
    addresses
    high
    direct

    Counterfeit-screening posture, fuse-policy maturity, and golden-image custody differ by supplier; Art. 21(3) requires the entity to consider those supplier-specific vulnerabilities when sizing hardware-supply-chain risk.

  • nis2-implAnnex 12.4.1
    addresses
    moderate
    derived

    Asset inventories at component granularity (lot, serial, configuration state) are the data on which lifecycle traceability and tamper-detection workflows depend; without that inventory the entity cannot reason about what was modified pre-delivery.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    ASIC/FPGA Trojans, modified bootloaders and pre-delivery board manipulation are the canonical hardware-supply-chain threats the supply-chain security policy is established to govern.

  • nis2-implAnnex 5.1.4
    addresses
    moderate
    derived

    Direct-supplier security requirements (secure-handling practices, anti-counterfeit screening, tamper-evident packaging) are the contractual mechanism that constrains how hardware moves from foundry to final integration.

  • nis2-implAnnex 5.1.6
    addresses
    high
    derived

    Hardware suppliers (foundries, board houses, IC integrators) require Annex 5.1.6 ongoing monitoring across lots, lifecycle changes and supplier-disclosed errata to surface tampering and counterfeit risk over time.

  • nis2-implAnnex 5.1.7
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures convert hardware-supplier monitoring signals into supplier audits, lot-screening reinforcement or supply replacement.

ENISA controls

  • Tamper-proof shipping/receiving with physical inspection of hardware detects substitution and physical insertion before integration.

  • Anti-counterfeit hardware policies and procedures explicitly target hardware Trojans, counterfeits, and tampered ASICs/FPGAs that IA-0001.03 inserts.

  • ASIC/FPGA development through accredited trusted foundries directly limits hardware-Trojan injection, the core IA-0001.03 vector.

  • Supplier security management requires evidence of security posture from board, module, and programmable-logic suppliers, the route IA-0001.03 exploits.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0001.03 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.