New Technical Guide: Securing the JTAG/SWD Interface for Embedded Systems

We are pleased to share the publication of a new technical guide (STIG) dedicated to securing JTAG/SWD debug interfaces in critical embedded systems.

This document provides an implementation framework that is technically actionable, operable in an industrial OT context, and auditable, covering the full lifecycle of debug security: design, integration, production, deployment, and maintenance. It explicitly addresses the tension between maintainability and cyber robustness, following a defense-in-depth and operational traceability approach.

The central defensive assumption of the guide is that partial physical access is plausible during maintenance operations, and must therefore be controlled rather than assumed impossible.

Threat Model

The guide considers a range of attacker profiles relevant to debug interface abuse:

Guide Objectives

The guide aims to:

The guide is designed for a two-level reading, aligning strategic architecture and risk governance decisions with concrete implementation-level settings and audit evidence, so that hardware, firmware, cybersecurity, and OT operations teams can work from the same reference.

Download the Guide

English version: Download Technical Guide (PDF)

French version: Télécharger le guide technique (PDF)

The document is published under a Free License.