SciTransfer
CYRENE · Project

Supply Chain Cybersecurity Certification Tool That Finds Threats Before They Hit

digitalTestedTRL 6

Imagine your company depends on dozens of suppliers, each with their own computer systems — and any one of them could be the weak link that lets hackers in. CYRENE built a security check-up system that scans your entire supply chain, finds the vulnerabilities, and tells you exactly where you're exposed. Think of it like a building inspector, but for the digital connections between you and every company you work with. It also helps you prove compliance with EU cybersecurity rules, so you're not scrambling when auditors come knocking.

By the numbers
EUR 4,992,750
EU funding for development
14
consortium partners
10
countries represented
7
SMEs in the consortium
13
total project deliverables
64%
industry partner ratio
The business problem

What needed solving

Companies running complex supply chains have no simple way to check whether their partners' IT systems are secure. A single weak link — one supplier with poor cybersecurity — can expose the entire chain to data breaches, ransomware, and regulatory penalties. Current security audits are manual, slow, and don't cover the connections between companies.

The solution

What was built

CYRENE delivered a conformity assessment platform with both an early integrated prototype and a system final release. The platform includes dynamic risk and privacy assessment tools, threat modeling for supply chain networks, and certification-readiness evaluation aligned with ISO 27001, ISO 28001, and the EU Cybersecurity Act.

Audience

Who needs this

Supply chain security managers at logistics and freight companiesChief Information Security Officers at manufacturing enterprises with multi-tier supplier networksCompliance officers at critical infrastructure operators (energy, water, telecom)IT risk managers at pharmaceutical companies with regulated supply chainsCybersecurity consultants advising mid-size companies on NIS directive compliance
Business applications

Who can put this to work

Logistics & Freight
mid-size
Target: Logistics operators managing multi-partner supply chains

If you are a logistics company coordinating shipments across multiple carriers and warehouse operators — this project developed a conformity assessment platform that maps cyber risks across your entire partner network. It identifies which connections are vulnerable and helps you meet ISO 28001 and NIS compliance requirements without hiring a dedicated security audit team for each partner.

Pharmaceutical Manufacturing
enterprise
Target: Pharma companies with regulated, multi-tier supply chains

If you are a pharmaceutical manufacturer dealing with strict supply chain integrity requirements — this project developed a multi-level risk assessment tool that continuously monitors your supplier network for cybersecurity gaps. With 14 partners across 10 countries contributing to its development, it was designed for exactly the kind of complex, cross-border supply chains pharma companies manage daily.

Critical Infrastructure & Utilities
enterprise
Target: Energy or water utilities with interconnected operational technology

If you are a utility operator whose critical infrastructure depends on digital systems from multiple vendors — this project developed a dynamic threat analysis and certification process that evaluates security at the device, system, and service level. It helps you detect advanced persistent threats across interconnected IT systems before they cascade into operational failures.

Frequently asked

Quick answers

What would it cost to implement this in our organization?

The project itself received EUR 4,992,750 in EU funding across 14 partners to develop the platform. Pricing for commercial deployment is not specified in the project data. Contact the coordinator MAGGIOLI SPA for licensing or service pricing details.

Can this handle industrial-scale supply chains with hundreds of suppliers?

CYRENE was designed for multi-level supply chain assessment — from individual devices up to entire service networks. It was validated using real-life supply chain infrastructures, suggesting it can handle complex, multi-partner environments. Exact scale limits are not specified in the available data.

What is the IP situation — can we license this technology?

The coordinator is MAGGIOLI SPA, an Italian technology company. With 9 industry partners and 7 SMEs in the consortium, IP is likely shared among partners. Contact the coordinator directly to discuss licensing options for the conformity assessment platform.

Does this help us comply with EU cybersecurity regulations?

Yes — CYRENE was explicitly built around the EU Cybersecurity Act and targets compliance with ISO 27001, ISO 28001, ISPS, and NIS directive requirements. The conformity assessment process was designed to generate the evidence needed for security certification schemes.

How long does it take to assess our supply chain?

The project developed a dynamic, continuous assessment process rather than a one-time audit. Based on available project data, the system provides ongoing risk monitoring, but specific assessment timelines depend on supply chain complexity. The final system release is available as a prototype.

Can this integrate with our existing security tools?

CYRENE was built to work with interconnected IT infrastructures and cyber systems across supply chains. The system evolved from an early integrated prototype to a final release, suggesting integration capabilities were a design priority. Specific API or platform compatibility details should be confirmed with the consortium.

Consortium

Who built it

The CYRENE consortium is heavily industry-driven with 9 out of 14 partners from the private sector (64% industry ratio), including 7 SMEs. This signals strong commercial intent — these are companies that need this technology for their own business, not just academic interest. The coordinator MAGGIOLI SPA is an established Italian IT company, which adds credibility for enterprise buyers. With partners across 10 countries (Belgium, Switzerland, Cyprus, Greece, Spain, France, Italy, Netherlands, Serbia, Sweden), the platform was built to handle the cross-border reality of European supply chains. The 3 universities and 2 research organizations provide the scientific backbone without dominating the project direction.

How to reach the team

MAGGIOLI SPA (Italy) — established IT services company, likely to engage on licensing or partnership discussions

Next steps

Talk to the team behind this work.

Want a tailored briefing on how CYRENE's supply chain security certification can fit your operations? SciTransfer can arrange a direct introduction to the development team.