Security

 

Security is at the core of every Sequans technology, from the first line of the architecture. Our chips are deployed in sectors — energy, utilities, healthcare, industrial automation — where data sovereignty, regulatory compliance, and long-term field reliability aren’t optional. For OEMs and carriers building on Sequans silicon, security isn’t a feature they have to ask for. It’s the foundation we build to.

Secure Development Practices
Security requirements are considered from the earliest architectural decisions, not added retroactively. Sequans employees receive regular training to identify security risks and practice cybersecure behaviors, both inside and outside the workplace. A robust suite of cybersecurity tools supports early threat blocking, risk reduction, and incident detection.

 

Independent Evaluation
Sequans works with independent labs and government cybersecurity agencies to validate security claims.

Cyber Resilience Act
The EU Cyber Resilience Act (CRA) establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market, covering both hardware and software — including components, like semiconductor chips and modules. The regulation sets expectations across the entire product lifecycle: secure design and development, ongoing vulnerability handling, security updates, and transparency with users for as long as the product remains in use. Key obligations are being phased in on a strict timeline — vulnerability and incident reporting requirements take effect September 11, 2026, with full compliance required by December 11, 2027.

As a supplier of cellular IoT chips and modules that OEMs and carriers build into their own connected products, Sequans recognizes that its customers’ CRA obligations depend directly on the security foundation we provide at the component level.

Responsible Disclosure Policy
Sequans Responsible Disclosure Policy aims to facilitate the identification of vulnerabilities or security issues affecting Sequans’ products and to ensure they are addressed promptly and effectively.

Security Disclosures and Vulnerability Reporting