Video Poster Image

QNX Cybersecurity

Cybersecurity-centered people, products, and ecosystem

In today’s interconnected world, the cybersecurity of your embedded systems is paramount. As a leader in developing safe and secure embedded systems, QNX is committed to protecting the world’s most critical systems against malicious access and attacks.

The QNX Commitment to Cybersecurity

For more than 40 years, QNX has provided safe and secure embedded software solutions for automotive, industrial controls, robotics, medical devices, and other mission-critical applications. QNX cybersecurity is built on a strong culture, product excellence, and an ecosystem that enhances the company’s security capabilities. 

Cybersecurity Culture

Cybersecurity at QNX isn't just an afterthought—it's ingrained in the company culture. As a leadership priority, cybersecurity underpins everything QNX does, from investments in security technologies and practices, to a transparent and open corporate environment where feedback is valued and contributes to continuous improvement in cybersecurity practices. 

Certifications

QNX has earned several key industry certifications, showcasing its commitment to cybersecurity, including the certification to the ISO/SAE 21434 automotive cybersecurity standard, TISAX, and ISO/IEC 27001 certifications.  These successes showcase a solid infrastructure and foundation for delivering secure solutions. This foundation can facilitate certification to other cybersecurity standards, including IEC 62443 for industrial automation, FDA guidelines for medical device manufacturers, or future harmonized standards adopted by the EU Cyber Resilience Act.

Visit our Certifications page to see the full list of certificates.

Product Excellence

While IT cybersecurity is a well-established subject with popular models like the CIA (Confidentiality, Integrity, and Availability) triad, there is no single proven formula for building robust cybersecurity into embedded devices. To protect an embedded system, security mechanisms should be considered at all levels of the system. Consider trusted hardware combined with techniques for secure booting, tamper protection, and various access control all the way to real-time intrusion detection. The operating system plays a pivotal role.

QNX strongly prioritizes security, leading the way in a world where no proven standard or formula exists for building robust cybersecurity into embedded systems. As a microkernel, the QNX® OS has a minimal attack surface. It also boosts the cybersecurity of the system by isolating critical components that manage tasks, memory, and peripheral access, ensuring system integrity and availability even if user space is compromised. This architecture also enables QNX to implement unique fine-grained access controls through security policies, providing precise control over process privileges. This approach, combined with comprehensive cybersecurity capabilities like encryption, spatial separation, and networking security mechanisms, ensures that QNX solutions offer unparalleled protection for embedded environments. QNX extends these benefits into secure virtual machine execution with the QNX® Hypervisor.

Product Excellence
Building a secure embedded device requires a layered design that integrates cybersecurity mechanisms throughout the system.

Cybersecurity Ecosystem and Professional Services

QNX collaborates with partners to offer additional cybersecurity solutions, enhancing and extending the cybersecurity of embedded systems built on a QNX foundation. For example, QNX has partnered with Bosch ETAS for their automotive firewall and host-based intrusion detection technology, allowing automakers and their suppliers to implement continuous security monitoring to meet UN-R 155. 

Beyond product offerings, QNX cybersecurity experts offer professional services to address various cybersecurity needs throughout your product lifecycle, ensuring the safety of your product and end users.

Talk to Us

Secure your critical embedded systems with QNX expertise and a robust cybersecurity framework. Contact us today to ensure protection against future cyber threats.

Related Products

Structural Dependency
The cloud-ready foundational development platform for the next generation of high-performance, mission-critical embedded systems.
Learn More
Structural Dependency
Consolidate diverse embedded systems with different reliability and security requirements onto a single SoC.
Learn More
Structural Dependency
Certified to IEC 61508 SIL3, IEC 62304 for Class C devices, ISO 26262 at ASIL D, EN 50657 SIL 4, and EN 50128 SIL 4.
Learn More
Structural Dependency
Security, manageability, and reliability solutions providing end-to-end security between devices and IoT platforms.
Learn More

FAQ

What cybersecurity certifications has QNX obtained?

QNX meets industry security standards, including ISO/SAE 21434, TISAX, and ISO/IEC 27001, ensuring adherence to best-in-class cybersecurity practices.

Is the QNX OS inherently secure?

QNX products are designed with cybersecurity at their core. The microkernel architecture of the QNX operating system limits its attack surface, making it inherently more secure. This architecture, combined with advanced security features including access control, encryption, QNX Trusted Disk, ensures that QNX software provides robust protection against cyber threats. The innovative QNX OS is an RTOS with a microkernel architecture that significantly reduces its attack surface. Its design and dedicated cybersecurity features allow it to defend and protect against a wide variety of attacks.

What about the QNX Hypervisor?

The QNX Hypervisor is built as an extension of the QNX OS microkernel. As such, it inherits the cybersecurity features of the microkernel itself as well as the secure execution environment created by the microkernel. In addition, the hypervisor has additional layers that are purpose-built for secure virtual machine operation.

Learn More

What significance does the ISO 21434 have for companies working with the automotive industry?

Essentially, ISO 21434 encompasses the entire lifecycle of automotive products, from initial concept to decommissioning. It provides guidelines on how to identify and mitigate cybersecurity risks, enabling every component and system within a vehicle is safeguarded against potential threats. By embracing the standard, QNX has enhanced all aspects of its development lifecycle for cybersecurity, from performing threat analysis, risk assessment and static code analysis, to doing cybersecurity-related testing, improving on its vulnerability handling capacities, and more.

How are safety and cybersecurity related for products built on a QNX foundation?

In automotive, for example, ISO 21434, the automotive cybersecurity standard, and ISO 26262, the functional safety standard for the development of electrical and electronic systems in road vehicles, have complementary goals, as there’s no safety without cybersecurity. The two standards emphasize the importance of integrating their respective criteria into the overall engineering process, and both cover the lifecycle of a product from concept to maintenance to decommissioning. By achieving this new cybersecurity certification, QNX adds a new layer of protection for automakers, building on existing ISO 26262 ASIL D certification for QNX OS for Safety and QNX Hypervisor for Safety, and has proven its dedication to maintaining both stringent cybersecurity and safety standards throughout the product lifecycle.