All techniques
REC-0008.01
ST0001Reconnaissance
sub-technique

Hardware Recon

Parent: REC-0008

Description

Adversaries seek insight into component sources, screening levels, test histories, and configuration states to prepare pre-delivery manipulation of boards and modules. High-value details include ASIC/FPGA part numbers and stepping, security fuses and life-cycle states, JTAG/SWD access policies, secure-boot and anti-rollback configuration, golden bitstream handling, board layouts and test points, conformal coat practices, and acceptance test procedures with allowable tolerances. Knowledge of substitute/alternate parts, counterfeit screening thresholds, and waiver histories reveals where counterfeit insertion or parametric “near-miss” parts might evade detection. For programmable logic, attackers target synthesis/place-and-route toolchains, IP core versions, and bitstream encryption keys to enable hardware Trojans or debug backdoors that survive functional test. Logistics artifacts (packing lists, RMA workflows, depot addresses) expose moments when custody is thin and tamper opportunities expand.

Mappings

EU regulation articles

  • craAnnex I, Part II, (1)
    addresses
    high
    derived

    Hardware reconnaissance enumerates components, screening, test history and configuration state; manufacturers under Annex I, Part II, (1) must identify and document those same components in an SBOM-style inventory, which is the procedural lever that makes lifecycle traceability and tamper-detection workflows operationally viable.

  • craAnnex I, Part II, (5)
    addresses
    moderate
    direct

    Hardware-supply-chain reconnaissance (primary mappings: Part II, (1) + Art. 13(5)) requires CVD policy under (5) to handle inbound third-party hardware-related vulnerability reports.

  • craArt. 13(5)
    addresses
    moderate
    derived

    Manufacturer due-diligence on hardware-component integration includes verification of supplier provenance, anti-counterfeit screening and tamper-evident packaging — the operational mechanisms that constrain how hardware moves from foundry to final integration.

  • eu-space-actArt. 92(1)
    addresses
    high
    direct

    Hardware-component reconnaissance (ASIC/FPGA part numbers, security fuses, JTAG policies) is supply-chain attack surface that 92(1)'s contracts must include security clauses for.

  • eu-space-actArt. 92(2)
    addresses
    moderate
    inferred

    Art. 92(2)'s supply-chain risk-reduction strategy is domain-relevant to hardware-supplier reconnaissance, but names no mechanism interdicting the information-gathering.

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    Hardware-supplier relationships (component sources, screening houses, FPGA IP vendors, depot repair) are exactly the supplier-relationship security obligation Art. 21(2)(d) covers, including counterfeit screening and waiver-driven trust gaps.

  • nis2Art. 21(3)
    addresses
    high
    direct

    Counterfeit screening thresholds, golden-bitstream handling, and stepping/lot-specific weaknesses are the kind of supplier-specific vulnerability profile Art. 21(3) requires the entity to consider when relying on a hardware supplier.

  • nis2-implAnnex 12.4.1
    addresses
    moderate
    derived

    Asset inventories at component granularity contain exactly the lot, serial and configuration data hardware reconnaissance targets; inventory protection determines whether that data is reachable.

  • nis2-implAnnex 5.1.1
    addresses
    moderate
    derived

    Hardware-supply-chain reconnaissance focuses on components, screening, test history and configuration state; the supply-chain security policy is the procedural mechanism that scopes what the entity exposes about its parts pipeline.

ENISA controls

  • Third-party risk management explicitly covers component and equipment suppliers — the targets of hardware-supply-chain reconnaissance.

  • Developing and maintaining a hardware and software asset inventory governs asset knowledge in the domain REC-0008.01 targets, but maintaining an inventory does not actively defend against external hardware reconnaissance, so addresses rather than mitigates.

  • Supplier security management governs the hardware vendor ecosystem whose security practices REC-0008.01 reconnoitres.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0008.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.