Insyde® Software Integrates Post-Quantum Cryptography and Builds EU CRA Compliance Foundation Across Full Firmware Stack
InsydeH2O®, Supervyse® OPF, and TapRUUT™ Add Quantum-Resistant Security as Insyde Prepares for EU CRA Requirements

COMPUTEX — TAIPEI, TAIWAN, June 3, 2026 — Insyde® Software, the firmware platform company behind InsydeH2O® UEFI BIOS, Supervyse® OPF OpenBMC firmware, and the TapRUUT™ Platform Root-of-Trust family, today announced ML-DSA (Dilithium) post-quantum cryptography integration across its firmware portfolio alongside expanded security lifecycle capabilities as it prepares for EU Cyber Resilience Act (CRA) requirements.
Insyde Software’s PQC implementation targets the three foundational layers where firmware trust originates. InsydeH2O integrates ML-DSA support for Secure Flash, Capsule Update, and firmware authentication. Supervyse OPF adds PQC cipher suite support via OpenSSL post-quantum extensions, securing platform management and remote infrastructure operations. TapRUUT anchors quantum-resistant firmware verification and recovery at the hardware level, aligned with NIST SP 800-193 principles for firmware protection, detection, and recovery.
The EU Cyber Resilience Act establishes cybersecurity, vulnerability management, and software lifecycle obligations for products sold in the EU. Insyde Software is building the compliance infrastructure its customers will need, with practices and tooling across the firmware portfolio, including:
- Security development processes: ISO/IEC 27001 and IEC 62443-4-1 aligned
- Supply chain visibility: machine-readable SBOM generation
- Vulnerability management: coordinated disclosure workflows, plus AdmynCVE™ for lifecycle risk visibility and accelerated remediation
PQC capabilities and components of security lifecycle tooling are available now to Insyde customers and partners. Full EU CRA compliance is in active development, with additional capabilities to follow as Insyde’s CRA preparation program progresses. Visit www.insyde.com or speak with an Insyde representative at COMPUTEX 2026 for technical details and roadmap information.
“The customers who navigate post-quantum and CRA well will be the ones whose firmware supplier got ahead of it,” said Tim Lewis, Chief Technology Officer, Insyde Software. “We’re making that investment now so ours do.”
About Insyde Software
Insyde Software (www.insyde.com) is a leading worldwide provider of UEFI firmware, OpenBMC-based systems management solutions and custom engineering services for companies in the mobile, server, desktop, embedded and edge computing industries. The company is publicly held (6231.TWO) and headquartered in Taipei, Taiwan with U.S. headquarters in Westborough, MA. The company’s customers include the world’s leading computing, communications and storage designers and manufacturers.
Insyde, InsydeH2O, Supervyse, TapRUUT, and AdmynCVE are trademarks or registered trademarks of Insyde Software in the United States and other countries. Other names and brands may be claimed as the property of others.
