# Embedded Systems Security Assessment

> From $22K · Offensive Security · https://cisomarketplace.services/services/embedded-systems-security-assessment

Deep-dive security evaluation of embedded systems, focusing on firmware security, hardware interfaces, and communication protocols specific to embedded devices.

## In scope

- Hardware interface testing
- Firmware reverse engineering
- Debug port analysis
- Boot sequence security review
- Memory protection assessment
- Secure boot verification
- Side-channel attack testing

## Deliverables

- Technical findings report
- Hardware security analysis
- Firmware vulnerability assessment
- Debug protection recommendations
- Secure boot implementation guide
- Memory protection strategy
- 60-day retest window

## Tiers

### Core Embedded Systems Assessment: $22K

One device model and 1 firmware image: hardware interface and debug port testing, firmware extraction and reverse engineering, boot sequence and protocol review. Includes a retest.

Limits: devices 1

Includes:
- Hardware interface and debug port analysis (UART, JTAG, SWD)
- Firmware extraction and reverse engineering
- Boot sequence security review
- Communication protocol review
- 60-day retest window

Excludes:
- Side-channel attack testing
- Secure boot bypass attempts
- Memory protection deep dive
- Companion app or cloud backend testing

### Advanced Embedded Security Program: $38K

Up to 2 device models: everything in the basic tier, side-channel testing (power and timing), secure boot verification with bypass attempts, and memory protection assessment.

Limits: devices 2

Includes:
- Everything in the basic tier
- Side-channel attack testing
- Secure boot verification and bypass attempts
- Memory protection assessment
- Secure boot implementation guide

Excludes:
- Fault injection campaigns
- Custom test fixtures and tooling
- Secure development guidance for the product team

### Enterprise Embedded Security Solution: $65K

Full-scope embedded security including custom testing tools, hardware security modules, and secure development guidance

Limits: devices 4

Excludes:
- Companion mobile app and cloud backend testing
- Product certification lab testing
- Firmware remediation

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=embedded-systems-security-assessment
