Boot Security Mastery Conference 2026

Unboxing Compliance: tooling lessons learned from scaling our BenchRack score
2026-09-24 , GPN-T Main Room

Public scoring tools will cheerfully report that your firmware is "compliant with warnings", but addressing the fix priorities is another story. We closed that gap on BenchRack with two internal tools: EAP (Ecosystem Alignment Program) and SAM (Stack Alignment Manifest) which emits a business decision report with a verdict a maintainer or a manager can act on.

This talk showcases the public scorers ran against a BenchRack, and how EAP and SAM turned their warnings into addressable backlog - helping us increase our CRA scoring and automate fixing compliance gaps in discrete timeframes. It also demonstrates how, with the usage of in-house tooling, which continuously reconciles current upstream firmware component versions against the CycloneDX SBOM (Software Bill Of Materials) of the binary we actually ship, we can hack paperwork-style compliance requirements, having them be automatically generated call to action in practice.

Junior Embedded Systems Developer at 3mdeb. An enthusiast of hot coffee, reasonable security and expression through writing documents and guides. Long-time Qubes OS user and contributor who believes that security shall be guaranteed out-of-the-box and not get in the way of everyday operations. Not afraid of paperwork, though preferring to make compliance and procedures seamless and automated.

Project Manager and former Test Automation TL. More and more enthusiastic about open source family. Thrilled to learn the latest trends in the world of project management. Loves the good Sci-Fi literature and automation of the boring stuff.