DAIO, LAES: EU Cyber Resilience Act Makes Chip Key Injection Mandatory
Data I/O (DAIO) and SEALSQ (LAES) say the EU Cyber Resilience Act's 11 September 2026 and 11 December 2027 deadlines turn per-device key injection into a condition of selling into the EU.
Data I/O Corporation (DAIO) and SEALSQ Corp (LAES) both told investors, on earnings calls held between April and August 2026, that the EU Cyber Resilience Act has given connected products a dated, penalty-backed security obligation, and that it is already changing what customers ask for [1][2].
What the EU Cyber Resilience Act adds to chip programming
Before a chip is soldered onto a circuit board, firmware and data are written into it one part at a time. The industry calls that step programming, and Data I/O sells the machines that do it; customers pay a few cents per part. The Cyber Resilience Act adds a second job at the same station: writing a key or certificate unique to each device, so the finished product can later prove which device it is. That step is called security provisioning.
Provisioning used to be optional, common in automotive electronics and payment products and skipped almost everywhere else. The Act applies to every product with digital elements sold into the EU rather than to a few categories, so an electronics maker cannot avoid it by staying out of one segment. The station where it happens may belong to the brand's own line, or to a distributor's or contract manufacturer's programming centre, which puts the same obligation on several kinds of company at once.
The deadlines are fixed; the per-part pricing is still management arithmetic
Data I/O's CEO treated the Act as a scheduling problem on the 12 August 2026 call: vulnerability monitoring starts next month, full compliance is required by the end of next year, and a product that misses it cannot be sold into that market. He said medical customers are moving fastest because they also have to clear FDA approval [1]. The European Commission's own guidance matches the timing. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents; substantive conformity and certification obligations apply from 11 December 2027 [3], with penalties capped at EUR 15 million or 2.5% of worldwide turnover [5]. SEALSQ's CEO named the same September date on 1 April 2026 and said the rules were already shaping customer purchasing decisions [2].
The pricing side rests on much less. On the 14 May 2026 call, the same CEO said a large contract runs five to ten million parts a year, that programming bills between 9 and 15 cents a part, that security provisioning bills roughly twice that, and that each token written into a part will carry its own charge [4][1]. Those are his own figures on hypothetical contract sizes, not prices already signed. The only listed company that reports this kind of revenue separately is SEALSQ, whose Trust Services line grew nearly 600% year over year and still accounts for just 2% of total revenue [2].
The charge point moves from the machine sale to each part that runs through it
If provisioning becomes a condition of shipping, the revenue point in this business moves from selling equipment to what the installed machines produce. Whoever controls the programming station is the party that can collect a per-part fee, and Data I/O says the new charges run on its existing platform with no further build-out required [1].
The limit on that reading is that the model is not new. Pay-per-part security deployment is described as a product in the company's FY2024 Form 10-K [6] and has never reached a size worth breaking out, and SEALSQ's 2% is the closest available benchmark [2]. Management's own grip on the timetable is loose: on the May call the CEO put the mandatory date at September 2027 [4], which matches neither 11 September 2026 nor 11 December 2027 [3]. Two things can be checked from here: whether per-token or per-part revenue starts appearing as its own line in disclosure, and whether SEALSQ's Trust Services moves off 2%.
Companies exposed to the same change
- Avnet (AVT): A major electronic component distributor whose own programming centres load chips before shipping them to customers, and a Data I/O customer [7]; key and certificate injection lands on exactly that step.
- Flex (FLEX): A large contract manufacturer whose lines already write firmware into customers' products [7]; meeting the obligation means adding a certified key-writing path to the same line.
- NXP Semiconductors (NXPI): An automotive and industrial chip supplier whose parts are the ones receiving the keys and identity tokens, and whose customers will ask it how those parts can be made compliant.
Sources
[1] Drillr · Data I/O (DAIO) · 2026-08-12 · FY2026 Q2 earnings call
[2] Drillr · SEALSQ (LAES) · 2026-04-01 · FY2025 results call
[3] European Commission · Cyber Resilience Act reporting obligations · 2026-08-14 · Official policy page · https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
[4] Drillr · Data I/O (DAIO) · 2026-05-14 · FY2026 Q1 earnings call
"But it's important for everybody because security provisioning can be kind of 2X the programming charge."
[5] Jones Day · EU Cyber Resilience Act: 24-Hour Reporting Duties Start September 11, 2026 · 2026-07 · Law firm analysis · https://www.jonesday.com/en/insights/2026/07/eu-cyber-resilience-act-24hour-reporting-duties-start-september-11-2026
[6] Drillr · Data I/O (DAIO) · 2025-04-01 · Form 10-K (FY2024)
[7] Drillr · Data I/O (DAIO) · 2026-08-14 · Company customer-relationship record
This is only meant to surface industry changes and companies you may have overlooked - not a stock recommendation.
Want deeper analysis?
Ask drillr anything about AVT, DAIO, FLEX, LAES, NXPI — powered by SEC filings, earnings calls, and real-time data.
Try drillr.ai for freeRelated Research
Drillr can make mistakes. Information only — not investment advice. Learn more