Publications
Everything we publish, dated: technical articles, the freely accessible CRA & Dev wiki, open-source code, contributions to Zephyr and probe-rs, LinkedIn posts. Written by Florian Mahon, over 20 years of software and firmware engineering.
We would rather show the method than promise it. This page gathers what we have published: technical articles, an open wiki that turns the Cyber Resilience Act into development techniques, and code under open licences. Each wiki episode is tested on real hardware or in a real CI pipeline, with its companion code.
The author is Florian Mahon, founder of ADNT: over 20 years of IT, software, real-time firmware and R&D, from EtherCAT and FPGA to heading an eight-person software R&D department.
CRA & Dev wiki
CRA & Dev is our freely accessible knowledge base (CC BY-SA 4.0 licence, FR/EN, open to contributions). One episode per requirement of Annex I of Regulation (EU) 2024/2847: a concrete need, a technique with code, a threat model.
| # | Episode | Published | Technique |
|---|---|---|---|
| 1 | You can’t fix what you don’t know you’re running: SBOM and VEX | July 2026 | CycloneDX inventory, VEX exploitability |
| 2 | An unsigned .exe is a parcel with no sender | July 2026 | Authenticode signing |
| 3 | Never store a secret in plaintext again: Windows DPAPI | July 2026 | Encryption at rest, with an in-depth article |
| 4 | Trust, but verify: sign your data | July 2026 | Data integrity, cross-platform |
| 5 | Generating an SBOM is not enough: monitor it with Dependency-Track | September 2026 | Grype in CI, Dependency-Track |
| 6 | A thousand fragments, one signature: updating firmware over LoRaWAN | October 2026 | FUOTA, Zephyr, MCUboot, ESP32 bench |
Articles
- · Updating firmware over LoRaWAN without trusting the network
- · Does the CRA apply to Swiss companies?
- · CRA & Dev: our freely accessible technical wiki to secure your software
- · The Cyber Resilience Act is won in your delivery chain, not in a binder
- · Integrating CVE Auditing and SBOM Generation into CI/CD for Baremetal Embedded Systems (C++ / Rust)
- · When AI Becomes a Reliable Ally in Firmware Development
Open source
-
crispy-bootloader-rp2040-rs: A/B bootloader in Rust for the RP2040, dual bank, runs from RAM (overview).
-
cra-dev-wiki: the wiki sources and the code for each episode (Zephyr firmware, CI scripts, Rust, Python and .NET examples).
-
adnt-net-edge: SSH and Traefik tunnel on a small VPS to expose a local service over HTTPS (overview).
-
Rust crates published on crates.io: crispy-upload (USB update tool) and crispy-common (shared protocol).
All our public repositories: github.com/ADNTIO.
Upstream contributions
When a tool we use has a defect, we fix it upstream rather than working around it on our side. Contributions accepted by the maintainers, under the fmahon account:
| Project | Contribution | Merged |
|---|---|---|
| Zephyr RTOS | Raspberry Pi Pico 2: Wi-Fi firmware blob setup instructions | January 2026 |
| probe-rs | Fix: invalidate the hardware breakpoint cache after a chip reset, found while building Crispy (the story) | January 2026 |
| Raspberry Pi pico-examples | Fix: function pointer prototype and build issues | February 2025 |
| awesome-embedded-rust | Added Crispy Bootloader to the reference list of the embedded Rust ecosystem | February 2026 |
On LinkedIn
Florian Mahon has been posting on LinkedIn since July 2026, in French and English: CRA roles and obligations (manufacturer, importer, distributor), the 11 September 2026 reporting deadline, SBOM and VEX, security.txt and coordinated disclosure (RFC 9116), the CRA decisions that belong to leadership, and every new wiki episode.
Identifiers
- Commercial register: ADNT Sàrl, UID CHE-152.405.190, Le Locle.
- IANA: Private Enterprise Number 35440, OID arc
1.3.6.1.4.1.35440. - Vulnerability disclosure: policy and security.txt.