Security by Design

Protect Industrial Products
Against Cyber Attacks

CodeX automates threat analysis and risk assessment — replacing insecure, manual Excel processes with a patented, AI-powered platform that cuts time-to-market by 90% and costs by 80%.

CodeX Performance — Radar System TARA
3d
Turnaround
40–60 days
1×
Employee needed
4 specialists
€5k
Total cost
€75,000
80%
Coverage
ISO/SAE 21434
Compliant with: ISO 21434 EU CRA NIS2 NIST OWASP

Why Manual TARA Processes Are No Longer Viable

Cybersecurity regulations are expanding across every industrial vertical. The existing approach — Excel spreadsheets, scattered data, and scarce security experts — cannot scale to meet today's demands.

  • ⚠️
    Legislation kills products Since July 2024, vehicles without a completed Threat Analysis cannot be registered in Germany. The EU CRA mandates full compliance by December 2027.
  • 💸
    Fines up to €15M or 2.5% turnover Non-compliance with CRA brings mandatory penalties, product recalls, and loss of market access.
  • 🔍
    Expert shortage is critical Security specialists are expensive and scarce. a leading Tier-1 supplier alone employs 15 experts just to review Excel-based TARAs — and still has hundreds of employees creating them.
  • 📂
    Insecure, unscalable processes Decentralised data, no access controls, no versioning, and error-prone manual work — the current state is a liability, not a process.

CodeX vs. The Market

No other solution delivers the automation depth, compliance coverage, and process security of our solution.

Capability Solution Others
ISO/SAE 21434 Coverage80%10–15%
Threat DB (10,000+ entries)120 max
Full AutomationPartial
Workflow Management
Versioning & Change Tracking
Combat Field Simulation
Security by Design
Encrypted Storage + HSM

CS Solution — Automated Cybersecurity for Industrial Products

The solution is a browser-based SaaS platform, delivered on a secure blade server with HSM. It integrates into your existing toolchain and replaces error-prone manual TARA processes with a patented, automated workflow. It can also be installed on a sovereign cloud, such as Stackit or Telekom.

🔍

Automated Threat Analysis

Automatically identifies attack vectors across all software and hardware components using a database of 10,000+ threats. Eliminates the need for scarce security experts on routine assessments.

📊

Risk Assessment & Visualisation

Calculates residual risk and visualises the security impact of vulnerabilities across the entire system architecture — giving decision-makers a clear, fact-based picture.

🛡️

Automated Countermeasures

Based on identified threats, the platform recommends targeted countermeasures tailored to your system's configuration and risk profile — no guesswork required.

🔐

Secure Development Workflow

Enforces access rights, encrypted data storage, change management, and process tracking — making your development process itself a security asset.

🔗

Tool Chain Integration

Browser-based and API-ready. Integrates with your existing engineering, PLM, and security tooling. Import architecture diagrams and electronic signal maps directly.

♻️

TARA Reuse & Scaling

Component-level TARAs are reusable across projects and customers — at a cost up to 10× less than creating new ones. Perfect for supplier networks and platform architectures.

Platform — Screenshots
TARA Diagram overview
TARA process diagram overview
CodeX Operational Assets
Operational assets & data flow mapping
CodeX Threat Scenario
Threat scenario analysis view
Attack Tree
Attack tree visualisation
European Patent Granted

Patent PT4483EP covers the platforms method for automated threat identification and countermeasure selection — a unique, legally protected competitive advantage.

Your Industry. Your Compliance. Our Platform.

The platform's database-driven architecture adapts to any industrial vertical within weeks. Select your market below.

Automotive & Driver Assistance / Autonomous Vehicles

The primary vertical for the platform. German law (July 2024) requires completed Threat Analyses for vehicle registration. OEMs including major OEMs are mandating TARA compliance across their entire supply chain.

  • ISO/SAE 21434 and UN Regulation 155 compliance
  • OEMs mandate TARA in supplier acceptance contracts
  • 50M+ lines of code and 60+ processors per modern vehicle

Challenges

100%
of EU new vehicles must comply with UN R155 by 2024
60+
ECUs per modern vehicle requiring TARA coverage

Defense Industry

Military platforms — from armoured vehicles to drones and command systems — face cyber threats of unprecedented sophistication. The platform's combat field simulation capability is unique in the market.

  • Combat zone and battlefield simulation module
  • Cooperation with international military device manufacturer, supplier and governments
  • Database extension to military threat vectors underway
  • Supports NIST, NATO STANAG cybersecurity frameworks

Challenges

Tier-1
LOI with a leading defense manufacturer — first reference customer
Unique
Only TARA tool with combat field simulation

Medical Device Manufacturers

The EU MDR and FDA cybersecurity guidance are reshaping how medical devices are designed and approved. Surgical robots, infusion pumps, and diagnostic equipment all require demonstrable cyber resilience.

  • EU MDR and FDA cybersecurity framework compliance
  • IEC 62443 industrial cybersecurity standard support
  • Surgical robots, imaging systems, connected devices
  • Rapid adaptation from automotive DB — weeks, not months
  • Bolzano R&D centre adapting the platform for health sector in 2025

Challenges

2025
Vertical launch year with local Italian expertise
FDA
New mandatory cybersecurity requirements for submissions

Aviation & Aerospace

Autopilot systems and avionics are high-profile targets. DO-326A and EASA cybersecurity regulations demand systematic threat analysis from aircraft type certification onwards.

  • DO-326A, AMC 20-42, EASA cyber regulation compliance
  • Existing relationships with leading suppliers and manufacturers
  • From commercial aviation to UAVs and space systems
  • Integrated avionics architecture import capability
  • Planned expansion 2026 with vertical-specific DB

Challenges

DO-326A
Mandatory airworthiness cybersecurity process
UAV
Rapidly expanding drone regulatory landscape

Marine & Electric Vessel Market

Maritime cyber incidents are rising. IMO Resolution MSC-FAL.1/Circ.3 requires cybersecurity risk management in ship safety management systems — and electric vessels add new attack surfaces.

  • IMO 2021 cybersecurity requirements for vessels
  • IEC 62443 for maritime industrial control systems
  • Electric propulsion and battery management system security
  • Port infrastructure and SCADA security assessment
  • Expansion roadmap 2026 — seafaring segment

Challenges

2021
IMO mandatory cyber risk management baseline year
EV
Fast-growing electric vessel segment adds new risk vectors

The Numbers Speak for Themselves

The platform delivers measurable cost and time savings from the very first TARA. Based on real project data with OEMs and Tier-1 suppliers.

−90%
Faster New TARAs
From 40–60 days to 3 days for a full radar system TARA
−80%
Change Cycle Reduction
Update existing TARAs at a fraction of previous effort
−75%
Staff Reduction
1 employee replaces 4 specialists for standard TARAs
€5k
vs. €75k Manual Cost
Total project cost including software and personnel — a 93% saving

Compliance Deadlines Are Approaching Fast

Regulations are tightening across all industrial sectors. The solution ensures you're ready — today and for future updates to the regulatory framework.

EU Cyber Resilience Act (CRA)

Applies to all products with digital elements sold in the EU. Mandatory vulnerability reporting from September 2026. Full compliance by December 2027. Fines of up to €15M or 2.5% of global annual turnover.

⏰ Sept 2026 — Dec 2027

ISO/SAE 21434 & UN R155

The automotive cybersecurity standard now enforced by law in Germany and across the EU. OEMs mandate compliance throughout their supply chain. Vehicle registration requires a completed TARA.

⏰ In Effect — July 2024

NIS2 Directive

Expanded scope of critical infrastructure cybersecurity across the EU. Covers automotive, energy, health, transport, and manufacturing sectors. Requires risk management measures and incident reporting.

⏰ In Effect — Oct 2024

Medical Device Regulation (MDR)

EU MDR and FDA guidance require medical device manufacturers to demonstrate systematic cybersecurity risk management throughout the device lifecycle, from design to post-market surveillance.

⏰ In Effect

IEC 62443

The primary standard for industrial automation and control system security, applicable to maritime, energy, manufacturing, and building automation. The solution supports IEC 62443 risk assessment methodology.

⏰ Industry Standard

DO-326A & EASA

Aviation cybersecurity airworthiness process standard. Required for new type certifications and major modifications to aircraft and avionics. EASA and FAA alignment underway.

⏰ Certification Requirement

Award-Winning Cybersecurity Technology

Recognised by leading institutions for innovation in industrial cybersecurity.

🏆Best Cybersecurity Technology — Handelsblatt Group, Fraunhofer ISI & Capgemini, 2023
🥈E-Mobility Startup Award — Porsche & Baden-Württemberg, 2023
🏅German Startup Pokal — 2nd Place, Society for Research Transfer, 2024

News, Events & Background

Stay up to date with the latest developments at Primary Target — from company background and news to upcoming events and official press releases.

About Primary Target

Primary Target GmbH has started developing a threat analysis platform with patented, AI-powered algorithms for the automated assessment of threats and risk analysis (TARA) of industrial products. Based on the Security by Design principle, the solution replaces insecure, manual, Excel-based processes with a fully automated, auditable workflow.

Our solutions serve the Automotive, Defense, Medical, Aviation, and Marine markets, and support compliance with ISO/SAE 21434, the EU Cyber Resilience Act (CRA), NIS2, NIST, and OWASP standards.

Primary Target Joins the Defense Management Network Platform

Primary Target has joined the Defense Management Network Platform https://defence.management/ to systematically promote and accelerate collaboration between industry, research, and defense organizations.

The European defense landscape is undergoing a period of profound transformation, which we are supporting through cybersecurity initiatives.

  • Hybrid threats and cyberattacks on critical infrastructure are increasing in frequency and complexity.
  • Interoperability between national systems and multinational task forces remains one of the greatest technical hurdles.
  • Innovation cycles in areas such as AI, sensor technology, software-defined capabilities, and unmanned systems are shortening dramatically.
  • Supply chains and industrial capacities are under pressure. The reasons: both geopolitical tensions and a shortage of skilled workers.
  • Regulatory requirements (such as certifications, norms, and safety standards) are becoming more extensive and complex.
October 27–29, 2026 · Nuremberg

it-sa 2026

Primary Target GmbH will be represented at the Defence Management Network booth at It-Sa in Nürnberg from 27. to 29. of October 2026.

Press Releases

Official press releases from Primary Target GmbH will be published here. For press enquiries, please contact us at contact@primary-target.com.

Request a Demo

See the platform in action. Select your market segment and we'll tailor the demo to your specific use case.

Primary Target GmbH

👤
Sabine Lutz Marketing & Sales Associate
📞
🌐
🏢
Registered Office Germany (HRB 272881)
R&D expansion: Bolzano, Italy (2025)
⚡ Quick Start Options
  • 📋 Request White Paper on TARA Automation
  • 🎯 Schedule 30-min Discovery Call
  • 🔬 Proof of Concept with your real TARA data