Generated by All in One SEO v4.9.7.2, this is an llms.txt file, used by LLMs to index the site. # EMERALD ## Sitemaps - [XML Sitemap](https://www.emerald-he.eu/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Emerald pilot 4: turning continuous compliance into reality for the financial sector](https://www.emerald-he.eu/emerald-pilot-4-turning-continuous-compliance-into-reality-for-the-financial-sector/) - From Periodic Audits to Continuous Assurance As financial institutions continue their digital transformation journey, the challenge is no longer simply securing cloud environments. The real challenge lies in maintaining continuous compliance across increasingly complex hybrid infrastructures while keeping pace with evolving regulations and cyber threats. Traditional audits often provide a point-in-time view of an organization's - [The EMERALD Stream 2: Targets of Evaluation – Reviewing Evidence and Compliance](https://www.emerald-he.eu/the-emerald-stream-2-targets-of-evaluation-reviewing-evidence-and-compliance/) - As already introduced in a previous post on “The EMERALD Compliance-as-a-Service workflow” and further detailed in “The EMERALD Stream 1: Certification Schemes – Structuring Compliance Through Metrics Mapping”, the EMERALD user interface is structured around three complementary visualization streams: Stream 1: Certification Schemes: Allows users to upload, compare, customize, and map certification schemes and controls. - [Turning Infrastructure Events into Compliance Evidence: the OpenNebula Add-on Behind Pilot 4](https://www.emerald-he.eu/turning-infrastructure-events-into-compliance-evidence-the-opennebula-add-on-behind-pilot-4/) - EMERALD Pilot 4, "Hybrid Cloud-Edge Environments", tackles continuous certification in the complex infrastructures of the financial sector, where security, sovereignty and regulatory readiness (DORA, EUCS) are non-negotiable. The pilot is led technically by OpenNebula Systems, with CaixaBank as use-case owner, bringing together multi-cloud resources from IONOS and CloudFerro alongside CaixaBank's own infrastructure under a single - [EMERALD General Presentation 2026](https://www.emerald-he.eu/emerald-general-presentation-2026/) - [The EMERALD Consortium met in Warsaw for the 8th General Assembly](https://www.emerald-he.eu/the-emerald-consortium-met-in-warsaw-for-the-8th-general-assembly/) - On 9–10 June 2026, the EMERALD consortium met in Warsaw for the 8th General Assembly, hosted by CloudFerro. The meeting brought together project partners for two days of discussions, joint work and planning as the project is approaching its final phase. The first day was mainly dedicated to the EMERALD pilots. Partners discussed their current - [Standardizing Cloud Compliance: The Integration of SECA in the EMERALD Project](https://www.emerald-he.eu/standardizing-cloud-compliance-the-integration-of-seca-in-the-emerald-project/) - Automating compliance for cybersecurity certifications like BSI C5 or the upcoming EUCS is a critical step toward establishing sovereign European cloud solutions. EMERALD addresses this challenge by developing a continuous "Compliance-as-a-Service" (CaaS) framework. To ensure broad applicability and reduce market fragmentation, the project emphasizes the standardization of technical interfaces, particularly through the open Sovereign European - [From Security Metrics to Ontology Evolution with AIOX](https://www.emerald-he.eu/from-security-metrics-to-ontology-evolution-with-aiox/) - The EMERALD project has advanced the development of AIOX, an AI-assisted ontology extension tool designed to support the evolution of the CertGraph ontology. AIOX helps domain experts and ontology engineers identify missing concepts and properties directly from YAML-based security metric definitions and guides their integration into the ontology. By combining semantic analysis with interactive expert - [Validation Preparation](https://www.emerald-he.eu/validation-preparation/) - The EMERALD project aims at streamlining the audit process for continuous compliance. The work package 5 performs regular checks for the internal business driven requirements. The next step is the validation of the audit workflows with the EMERALD framework. In order to make sure everything is on track for the stage gate process, which tracks - [Integrating Semantic Technologies into Microservices with owl2proto](https://www.emerald-he.eu/integrating-semantic-technologies-into-microservices-with-owl2proto/) - The owl2proto tool is designed to facilitate the integration of semantic technologies within modern cloud environments, particularly focusing on the seamless exchange of semantic data. It automates the translation of OWL (Web Ontology Language) ontologies into the Protocol Buffers (protobuf) data format, which is widely utilized in cloud-native applications. By converting OWL ontologies into protobuf - [The EMERALD Consortium Met in Munich for the 7th General Assembly](https://www.emerald-he.eu/title-the-emerald-consortium-met-in-munich-for-the-7th-general-assembly/) - The EMERALD consortium gathered in Munich on 10-11 March 2026 for the project’s latest General Assembly, hosted by our partner Fraunhofer AISEC. As the project enters its final phase, the meeting provided an important opportunity for partners to review progress, align on the remaining activities, and coordinate the work that will lead EMERALD toward its - [Are We Ready for Audits?](https://www.emerald-he.eu/are-we-ready-for-audits/) - The Emerald project includes four pilots, each representing a different type of cloud infrastructure. Preparations for the actual audits are currently underway. This phase involves finalizing the audit scope, which covers the following elements: List of controls (requirements): A selected subset of controls drawn from one or more certification frameworks. These are implemented in the - [3rd Cohort of the European Blockchain Sandbox Best Practices for the EMERALD Trustworthiness System](https://www.emerald-he.eu/3rd-cohort-of-the-european-blockchain-sandbox-best-practices-for-the-emerald-trustworthiness-system/) - TECNALIA has participated during the second half of 2025 in the Third Cohort of the European Blockchain Sandbox with one of the components of the EMERALD CaaS Framework, namely the EMERALD Trustworthiness System (TWS). This cohort refers to the third group of selected blockchain and Distributed Ledger Technology (DLT) use cases participating in the European - [The EMERALD Stream 1: Certification Schemes - Structuring Compliance Through Metrics Mapping](https://www.emerald-he.eu/the-emerald-stream-1-certification-schemes-structuring-compliance-through-metrics-mapping/) - As already introduced in a previous post on "The EMERALD Compliance-as-a-Service workflow", the EMERALD user interface is structured around three complementary visualization streams: Stream 1: Certification Schemes: Allows users to upload, compare, customize, and map certification schemes and controls. Stream 2: Targets of Evaluations: Allows users to define certification targets, link evidence tools, and manage - [Strengthening Financial Resilience: Why EMERALD is Leading the Way](https://www.emerald-he.eu/strengthening-financial-resilience-why-emerald-is-leading-the-way/) - Meeting a New Era of Digital Risk European financial institutions stand at a crossroads: cyberattacks are escalating, cloud adoption is accelerating, and regulatory expectations have never been more demanding. For CaixaBank, one of Europe's largest and technologically advanced financial institutions, ensuring security, sovereignty, and resilience across hybrid cloud edge environments is both a priority and - [The Second EMERALD Annual Summary Is Now Available](https://www.emerald-he.eu/the-second-emerald-annual-summary-is-now-available/) - We are pleased to announce the publication of the Second Annual Summary of the EMERALD project. This document is intended for an informed audience with an interest in the project’s domain, while remaining accessible to readers who are not directly involved in EMERALD. The summary provides an overview of the progress achieved during the project’s - [Cybersecurity and Security Assurance in Emerging Digital Ecosystems](https://www.emerald-he.eu/cybersecurity-and-security-assurance-in-emerging-digital-ecosystems/) - The CUSTODES system will discover and translate certification information of the Building Blocks of the composite ICT products or Services under evaluation, will provide Certification information to the interested parties and will share information on newly identified vulnerabilities related to the specific blocks or composite products as needed, increasing transparency, re-usability and trust. It will - [EMERALD and CUSTODES Join Forces to Explore Synergies and Collaboration](https://www.emerald-he.eu/emerald-and-custodes-join-forces-to-explore-synergies-and-collaboration/) - On 28 November, EMERALD project and CUSTODES Project held a joint online meeting to explore potential synergies and collaboration opportunities within the EC3 cluster. The session brought together representatives from both consortia to present their projects, exchange insights, and identify overlapping objectives. Discussions focused on finding ways to work together across several key areas, including: - [EU Projects Joint Workshop on Exploitation & Technical Collaboration](https://www.emerald-he.eu/u-projects-joint-workshop-on-exploitation-technical-collaboration/) - Joint Exploitation Workshop On the 20th of November 2025, EMERALD joined a multi-project exploitation workshop hosted by Engineering Group in Rome. As the project moves forward, we are entering a critical phase: turning the tools and technologies we have developed into real-world impact. This workshop aimed to bring together consortium partners from different active EU - [Software Provenance for Cloud Services](https://www.emerald-he.eu/software-provenance-for-cloud-services/) - Software provenance provides the auditable evidence needed to meet compliance objectives across regulatory, contractual, and policy requirements. By recording and verifiably linking every step from material sourcing to final artefact, provenance enables organizations to demonstrate control, transparency, and accountability in the software supply chain. Thus, software provenance for cloud services provides important evidences for EMERALD’s - [Tecnalia presented EMERALD Blockchain-based TWS@the 3rd cohort of the European Blockchain Sandbox](https://www.emerald-he.eu/tecnalia-presented-emerald-blockchain-based-twsthe-3rd-cohort-of-the-european-blockchain-sandbox/) - [eknows-e3 Development Progress](https://www.emerald-he.eu/eknows-e3-development-progress/) - eknows-e3 (eknows evidence extractor) is part of the evidence gathering tools which are being developed in EMERALD and supports the assessment of security and compliance of a cloud application's source code. It extracts evidence required for later assessments, such as identifying used transport layer protocols and cipher suites. The static code analysis platform eknows [1] - [The EMERALD Compliance-as-a-service Workflow](https://www.emerald-he.eu/the-emerald-compliance-as-a-service-workflow/) - The EMERALD project aims to make the complex world of cybersecurity certification easier to navigate. To do this, we are designing a user interface (UI) that guides our target users through all stages of an audit, from defining high-level requirements to exploring specific technical details in policies, system documentation, as well as source code and - [EMERALD solution architecture](https://www.emerald-he.eu/emerald-solution-architecture/) - The EMERALD project reached its milestone MS5 in October 2025. This milestone, located in month 24, corresponds to the second version (V2) of the EMERALD CaaS components. EMERALD context The context diagram shown in Figure 1 presents the EMERALD process workflow. The compliance evaluation process is initiated by the Compliance Manager, who defines the Audit - [AI-SEC Tool Development Progress](https://www.emerald-he.eu/ai-sec-tool-development-progress/) - The development of the AI-SEC tool [1] is making steady progress. This tool is designed to systematically evaluate various security and trustworthiness properties of AI models in accordance with the AIC4 requirements [2]. The evaluation covers key aspects such as privacy protection, data poisoning resistance, adversarial robustness, and explainability. To ensure both comprehensive coverage and - [The EMERALD Co-Creation & Co-Design Process](https://www.emerald-he.eu/the-emerald-co-creation-co-design-process/) - In EMERALD’s Work Package 4, we adopted a co-creation and co-design approach - a way of developing technology with users rather than for them. This method brings together those who will use the system (pilot partners), those who build it (technology component owners), and external auditors to collaboratively shape the EMERALD Compliance-as-a-service. The goal is - [The Emerald consortium met in Linz for the 6th General Assembly](https://www.emerald-he.eu/the-emerald-consortium-met-in-linz-for-the-6th-general-assembly/) - All EMERALD partners came together for the 6th General Assembly on 14–15 October 2025, hosted by our partner Fabasoft in their stunning facility near the Danube in Linz, Austria. The meeting was held in a hybrid format, allowing partners who could not travel to join remotely via Microsoft Teams, ensuring full engagement across the consortium. - [Juncal Alonso presented EMERALD @Universidad de Murcia](https://www.emerald-he.eu/juncal-alonso-presented-emerald-universidad-de-murcia/) - [EMERALD metrics migration progress](https://www.emerald-he.eu/emerald-metrics-migration-progress/) - Work to integrate EMERALD metrics into the security-metrics repository is making steady, practical progress [1]. The initial content and category scaffolding have been added, and a series of targeted metric PRs have already been merged. These include transport encryption and TLS-related metrics (protocols, cipher suites, DH groups), password and rotation metrics, antimalware scan frequency, virtual - [From Auditors Desk: Why Architecture Diagrams and Documentation Are Essential in the Audit Process](https://www.emerald-he.eu/from-auditors-desk-why-architecture-diagrams-and-documentation-are-essential-in-the-audit-process/) - In the world of digital systems auditing our ability to assess systems effectively depends on one thing above all: clarity. That clarity comes from two critical sources: Architecture diagrams, which show us how systems are structured. Documentation, especially technical implementation descriptions, which explain how those systems actually work. Together, they form the foundation of a - [The 2nd EMERALD Flyer is released](https://www.emerald-he.eu/the-2nd-emerald-flyer-is-released/) - The 2nd Flyer of the EMERALD project has been finalized. The flyer contributes to raise awareness of the EMERALD project and to present key project information in a clear way. It shows key milestones at one glance focusing on the progress and on developments achieved during the first half of the project, and on the - [Secure and Sovereign Cloud](https://www.emerald-he.eu/secure-and-sovereign-cloud/) - The EU project "EMERALD" is developing a framework with new approaches for cloud security compliance with a focus on the user. As cyberattacks, data breaches, and regulatory requirements continue to intensify, European cloud providers face mounting pressure to demonstrate security and compliance. EMERALD addresses this challenge by creating a framework that strengthens digital sovereignty across - [EMERALD joins HELEN: Strengthening Legal and Ethical Foundations for CaaS](https://www.emerald-he.eu/emerald-joins-helen-strengthening-legal-and-ethical-foundations-for-caas/) - The EMERALD project is pleased to announce its official membership in HELEN, the Horizon Europe Legal and Ethics Network. HELEN’s primary mission is to foster collaboration, promote the creation and sharing of knowledge, and develop effective solutions and methodologies to ensure the legal compliance and ethical integrity of emerging technologies. By embedding the principles of - [aCtive sEcurity foR connecTed devIces liFecYcles](https://www.emerald-he.eu/active-security-for-connected-devices-lifecycles/) - CERTIFY establishes a methodological, technological, and organizational approach to IoT security lifecycle management, aiming to enhance security by effectively detecting and responding to a wide range of attacks. - [CONFormIty assessment, metRics and compliance autoMATion for the cyber resiliencE act](https://www.emerald-he.eu/conformity-assessment-metrics-and-compliance-automation-for-the-cyber-resilience-act/) - CONFIRMATE is an EU-funded project designed to simplify compliance with the Cyber Resilience Act (CRA). The initiative focuses on developing open-source tools and automation solutions to enhance cybersecurity resilience. By bringing together leading organizations, CONFIRMATE aims to standardize testing procedures, provide guidance, and support businesses in meeting CRA requirements. - [Cybersecurity via trustworthy tools and methodologies is a crucial challenge for IoT ecosystems](https://www.emerald-he.eu/cybersecurity-via-trustworthy-tools-and-methodologies-is-a-crucial-challenge-for-iot-ecosystems/) - The TELEMETRY project addresses the critical challenge of cybersecurity in IoT ecosystems by developing and validating innovative tools and methods for testing and detecting security vulnerabilities in IoT devices and systems. - [Agile conformance assessment for cybersecurity CERTIFication enhanced by Artificial Intelligence](https://www.emerald-he.eu/agile-conformance-assessment-for-cybersecurity-certification-enhanced-by-artificial-intelligence/) - CERTIFAI endeavours to create an open software framework employing AI-driven, cost-efficient continuous assessment and (re-)certification methods specifically tailored for ICT products, processes, and services. This proactive approach addresses the evolving cybersecurity landscape by ensuring robust compliance throughout the product life cycle. - [Secure-by-Design IoT operation with Supply Chain Control](https://www.emerald-he.eu/secure-by-design-iot-operation-with-supply-chain-control/) - The DOSS project focuses on enhancing the security and reliability of IoT operations. The project develops a secure-by-design approach and implements supporting technologies, including structured data exchange, component testing, and architecture modelling. - [Certification for Cybersecurity in EU ICT using Decentralized Digital Twinning](https://www.emerald-he.eu/certification-for-cybersecurity-in-eu-ict-using-decentralized-digital-twinning/) - COBALT aims to elevate the overall level of cybersecurity, contributing to a future where certifications are universally recognized and trusted. By aligning with existing initiatives such as the EU CSA, ENISA, EUCS, and the EUCC, the project becomes a catalyst for harmonizing cybersecurity practices. - [MARI: Mapping Assistant for Regulations with Intelligence](https://www.emerald-he.eu/mari-mapping-assistant-for-regulations-with-intelligence/) - MARI is an intelligent component developed in EMERALD by CNR to support compliance activities in the context of cybersecurity certification schemes. Its main goal is to automate the association between security controls and measurable metrics, reducing the manual workload for compliance managers. MARI performs two key tasks: Control-to-metric mapping: it automatically suggests relevant metrics based - [New Developments in the CertGraph Ontology](https://www.emerald-he.eu/new-developments-in-the-certgraph-ontology/) - As in one previous fragment presented, the CertGraph Ontology is proposed as an extensible approach to model evidence. The foundation of the ontology is Core, which consists of the following sub-ontologies: Evidence, which contains concepts to link resources with security features Framework, which contains common (high-level) types of software components, like HTTP servers or Logging - [The European Cluster for Cybersecurity Certification: Enhancing Cybersecurity in the European Region](https://www.emerald-he.eu/the-european-cluster-for-cybersecurity-certification-enhancing-cybersecurity-in-the-european-region/) - The EMERALD action has established the European Cluster for Cybersecurity Certification, which is slated for its kick-off gathering in April during the International Conference of Cloud Computing and Service Science (CLOSER conference) to enhance capabilities in cybersecurity within Europe. The creation of the Cluster for Cybersecurity Certification was foreseen as a way to operate a - [EMERALD general presentation has been published](https://www.emerald-he.eu/emerald-general-presentation-has-been-published/) - The EMERALD general presentation is now available on the website. This key resource offers a deep dive into the EMERALD project for anyone interested, highlighting goals, approaches, and the innovative solutions we're bringing to cybersecurity and cloud service certification.Website visitors can now easily access this presentation to learn more about what we do and why - [Multi-Cloud with OpenNebula: Working on a DORA-Ready Blueprint for Resilient Banking](https://www.emerald-he.eu/multi-cloud-with-opennebula-working-on-a-dora-ready-blueprint-for-resilient-banking/) - Our last EMERALD fragment, “The Role of OpenNebula for the Multicloud Security-Certification Challenges of EMERALD,” explained why continuous evidence and security certification are central to the project’s mission (EMERALD). This follow-up looks at how the same platform turns multi-cloud theory into day-to-day reality—and why that matters even more now that the EU Digital Operational Resilience - [EMERALD and other E3C Projects Successfully Hosted a Panel on Cybersecurity Certification at CLOSER 2025](https://www.emerald-he.eu/emerald-and-other-e3c-projects-successfully-hosted-a-panel-on-cybersecurity-certification-at-closer-2025/) - On April 1, 2025, the EMERALD project successfully co-organized a pivotal industrial panel at the CLOSER 2025 Conference titled “Cybersecurity Certification for the Computing Continuum: Future Challenges and Opportunities.” The panel was a collaborative effort with the projects COBALT, CERTIFY, CONFIRMATE, DOSS and TELEMETRY, all members of the European Cluster for Cybersecurity Certification (E3C). Context - [SEVEN NEW DELIVERABLES PUBLISHED ON 30th APRIL 2025!](https://www.emerald-he.eu/seven-new-deliverables-published-on-30th-april-2025/) - Explore the latest seven deliverables and dive into our innovative project. The deliverables cover key aspects of our work carried out during the last eighteen months of the project. Visit the EMERALD Deliverables webpage to access these insightful documents and stay informed about our latest efforts and findings: Deliverable D1.2 - Data Modelling and interaction - [EMERALD contributes to the global IoT Day 2025](https://www.emerald-he.eu/emerald-contributes-to-the-global-iot-day-2025/) - On April 9, 2025, the EMERALD project took part in one of the official events of the global IoT Day 2025, contributing to the Webinar & Roundtable on IoT Supply Chain Security and Cyber Resilience Act (CRA) compliance. Organised by the Horizon Europe project DOSS, the online event brought together seven EU-funded research projects—FLUIDOS, TaRDIS, - [From thorough preparation to the icing on the cake - audit preparation processes at IONOS](https://www.emerald-he.eu/from-thorough-preparation-to-the-icing-on-the-cake-audit-preparation-processes-at-ionos/) - As part of the EMERALD project’s efforts to understand user requirements for interaction and user experience (WP4), this article presents insights from an interview conducted by Angela Fessl and Katharina Stefan (Know Center) with a compliance manager (CM) of IONOS SE, on the topic of audit preparation processes at IONOS as part of the EMERALD - [ECCO: European Cybersecurity COmmunity](https://www.emerald-he.eu/ecco-european-cybersecurity-community/) - This project, led by the European Cyber Security Organisation (ECSO), aims to support the activities necessary to develop, promote, coordinate and organize the work of the Cybersecurity Competence Community at European Level, within the scope and operations of the ECCC and National Coordination Centres Network. The goal is to improve cooperation between cybersecurity projects and - [Launch of the Security Metrics Repository](https://www.emerald-he.eu/launch-of-the-security-metrics-repository/) - Establishing robust security measures is essential for all kinds of organizations. Security metrics play a critical role in evaluating the effectiveness of these measures, enabling organizations to gauge their compliance with various security standards and identify areas for improvement. Moreover, metrics provide a standardized approach to security assessments, facilitating communication among stakeholders. They serve as - [Pilot 2 - Workflow overview](https://www.emerald-he.eu/pilot-2-workflow-overview/) - In the previous fragments, we introduced the high-level concept of Pilot 2 (https://www.emerald-he.eu/pilot-2-description-cloudferros-role-in-emerald/) and shared an overview of our environments (https://www.emerald-he.eu/pilot-2-test-environments-preparation/). Now, we would like to take a closer look at the workflow of Pilot 2 — how different participants will interact with the selected EMERALD components throughout the pilot. So, let’s start by revisiting the high-level architecture - [The Emerald consortium met in Pisa for the 5th General Assembly](https://www.emerald-he.eu/the-emerald-consortium-met-in-pisa-for-the-5th-general-assembly/) - All EMERALD partners participated in the 5th General Assembly on 25-27 March 2025. The two days meeting were organized and hosted at CNR premises in the historic town of Pisa, Italy. For the first time since the beginning of the project, the GA was held over three days with the first afternoon dedicated to the Executive - [Compliance Managers' feedback of EMERALD UI and workflows](https://www.emerald-he.eu/compliance-managers-feedback-of-emerald-ui-and-workflows/) - A compliance manager plays a critical role in ensuring that an organization adheres to legal, regulatory, and internal policy standards. Their primary responsibility is to oversee and manage compliance programs, reducing the risk of legal, ethical and cyber security violations. In this interview Samu Nisula, a compliance manager for a global company with +50k employees, - [Emerald Kickoff Meeting](https://www.emerald-he.eu/emerald-kickoff-meeting/) - The online Emerald Kickoff Meeting took place on November 20-21, 2023. A very fruitful interaction among partners took place, discussing roles and responsibilities, establishing common project goals and timelines and building trust among the project members. - [Emerald presented at Annual CNR-IIT Conference in Pisa](https://www.emerald-he.eu/emerald-presented-at-annual-cnr-iit-conference-in-pisa/) - On December 18, 2023 the CNR partner presented the Emerald Project at the Annual CNR-IIT Conference held in Pisa (Italy) - [The first Emerald Flyer is released](https://www.emerald-he.eu/the-first-emerald-flyer-is-released/) - This flyer, the first in a series of three, is intended to raise awareness of the EMERALD project and to present key project information in a concise manner. It also aims to highlight the project's innovative approach to evidence management for Continuous Certification in Cloud Services. The downloadable version is available in the Communication section - [EMERALD Press Release 2024 (EN)](https://www.emerald-he.eu/emerald-press-release-2024-en/) - [EMERALD Press Release 2024 (IT)](https://www.emerald-he.eu/emerald-press-release-2024-it/) - [The first EMERALD Press release is now available](https://www.emerald-he.eu/the-first-emerald-press-release-is-now-available/) - The first Emerald Press release is now available offering a comprehensive overview of the project's context, its mission and objectives. It can be distributed to media, press agencies and at conferences and events. An essential communication tool for maintaining visibility and engaging with a broader audience. The downloadable version is available in the Flyers section - [The Emerald consortium met in Bilbao for the 2nd General Assembly](https://www.emerald-he.eu/the-emerald-consortium-met-in-bilbao-for-the-2nd-general-assembly/) - All EMERALD partners participated in the 2nd General Assembly on 6 and 7 March 2024. The two days meeting were hosted at Tecnalia premises in Derio (Bilbao), Spain. Participants who could not travel were able to follow the GA online, through the Teams session organized for that purpose. The main objectives of the meeting were to: - [EMERALD and COBALT Projects explore new collaborations](https://www.emerald-he.eu/charting-new-territories-in-cybersecurity-the-emerald-and-cobalt-projects-explore-future-collaborations/) - Participants: TECNALIA Bosch Demokritos FhG CNR On February 29, 2024, an important meeting occurred between representatives of two groundbreaking Horizon Europe (HE) projects, EMERALD and COBALT. This meeting aimed to explore potential avenues for collaboration, leveraging their unique strengths to enhance cybersecurity measures across Europe. The primary objective was to identify and discuss potential collaboration - [EMERALD Press Release 2024 (ES)](https://www.emerald-he.eu/emerald-press-release-2024-en-2/) - [EMERALD Press Release 2024 (DE)](https://www.emerald-he.eu/emerald-press-release-2024-de/) - [Emerald Deliverable D6.1 published in February 2024](https://www.emerald-he.eu/emerald-deliverable-d6-1-published-in-february-2024/) - EMERALD has released the Deliverable D6.1 “Project flyer and public website”in February 2024. It reports on the activities carried out within Work Package 6 in the period from M1 (01.11.2023) to M4 (29.02.2024) and represents the first piece of the EMERALD Dissemination and Communication strategies carried on in WP6. This document is published on the - [EMERALD Press Release 2024 (PL)](https://www.emerald-he.eu/emerald-press-release-2024-pl/) - [Björn Fanta@Bitkom's Expert Group on Cloud Services & Digital Ecosystems](https://www.emerald-he.eu/bjorn-fantabitkoms-expert-group-on-cloud-services-digital-ecosystems/) - [EMERALD at Bitkom's Expert Group on Cloud Services & Digital Ecosystems](https://www.emerald-he.eu/emerald-at-bitkoms-expert-group-on-cloud-services-digital-ecosystems/) - In a significant gathering of tech experts, the EMERALD project was highlighted at Bitkom's expert round on March 20, 2024, in Frankfurt at the IBM offices. This session, part of the AK Cloud Services & Digital Ecosystems series, provided a valuable opportunity to discuss cloud certification, compliance, and the integration of advanced technologies to enhance - [IPCEI Next Generation Cloud Infrastructure and Services](https://www.emerald-he.eu/ipcei-next-generation-cloud-infrastructure-and-services/) - Initiative aimed at building the next-generation cloud-edge infrastructure for Europe. The objective is to build a powerful and sustainable first-ever “Multi-Provider Cloud-Edge Continuum” that is not tied to individual providers. AI-optimised security solutions for the next-generation cloud edge in diverse cloud environments will be developed, enabling the seamless integration of a variety of different new - [AK-Graph: AI-based Software Architecture Design for the Engineering of Secure and Sustainable System](https://www.emerald-he.eu/ak-graph-ai-based-software-architecture-design-for-the-engineering-of-secure-and-sustainable-system/) - The objective of this project is to describe software architecture knowledge in a knowledge graph to lay out the foundation for automatically processing architecture knowledge with reasoning- and AI-based approaches in order to provide architecture design guidance and automate architecture evaluation. - [A Distributed Open Marketplace for Europe Cloud and Edge Services](https://www.emerald-he.eu/a-distributed-open-marketplace-for-europe-cloud-and-edge-services/) - The aim of DOME to support businesses and public organisations digital transformation making available a catalogue of cloud-to-edge offerings in Europe. - [Consolidating Research and Policy along the Cognitive Computing Continuum](https://www.emerald-he.eu/consolidating-research-and-policy-along-the-cognitive-computing-continuum/) - NexusForum.EU will boost the consolidation of the European Computing Continuum ecosystem building on the valuable activities and impact generated so far within the existing EUCloudEdgeIoT (EuCEI) initiative, as well as provide a forward-looking and bold vision in new areas and directions that have not been explored so far. - [EMERALD Press Release 2024 (FIN)](https://www.emerald-he.eu/emerald-press-release-2024-fin/) - [EMERALD and CERTIFAI projects explore possible areas of joint work](https://www.emerald-he.eu/emerald-and-certifai-projects-explore-possible-areas-of-joint-work/) - On March 22, 2024 representatives from EMERALD and CERTIFAI projects joined to set up the way of collaboration. Both projects were approved under the same topic (HORIZON-CL3-2022-CS-01-04 Development and validation of processes and tools used for agile certification of ICT products, ICT services and ICT processes), therefore they can be considered as “sister” projects. EMERALD - [EMERALD deliverables published in April 2024](https://www.emerald-he.eu/emerald-deliverables-published-in-april-2024/) - We are glad to inform that EMERALD has published four new Deliverables in April 2024. These documents are available in the Deliverables web page: https://www.emerald-he.eu/deliverables/ D1.5 DevOps methodology and CD/CI strategy for EMERALD - v1 This deliverable describes the DevOps Methodology and CI/CD (Continuous Integration/Continuous Deployment) strategies that are applied for the development of the - [EMERALD Data Diagram](https://www.emerald-he.eu/emerald-data-diagram/) - The EMERALD consortium stablished a data modelling process to enable the integration of – and data exchange between – all the components underlying EMERALD’s future UI. To achieve this milestone, the partners built on a similar architecture as in the H2020 project MEDINA. The work has been an iterative process - aided by GitLab’s versioning - [DevOps methodology and CI/CD strategy for EMERALD](https://www.emerald-he.eu/devops-methodology-and-ci-cd-strategy-for-emerald/) - The EMERALD CaaS (Certification-as-a-Service) framework will consist of several components, with different levels of maturity and developed by different teams, which makes it challenging to approach the integration of the framework. Furthermore, on the validation side, the project includes several pilots, each with its particular needs and limitations. Therefore, we have considered that the application - [Getting to know the EMERALD Pilots](https://www.emerald-he.eu/getting-to-know-the-emerald-pilots/) - The first EMERALD face-to-face consortium meeting took place at the beginning of March 2024 in Bilbao, Spain. One goal of this meeting was to get to know and to better understand our four pilot partners – IONOS, Cloudferro, Fabasoft, and CaixaBank. We have conducted an interactive interview session with the pilot partner to elicit their - [EMERALD Introduced at “Hannover Messe 2024”](https://www.emerald-he.eu/emerald-introduced-at-hannover-messe-2024/) - Hannover Messe 2024 took place from April 22nd to April 26th, 2024, at the Hannover Exhibition Grounds in Germany. The event is known as one of the world's largest trade fairs for industrial technology, innovation, and digitalization. This year, it attracted a diverse audience of over 200,000 visitors, including industry professionals, decision-makers, investors, and technology - [Pilot 2 description – CloudFerro’s role in EMERALD](https://www.emerald-he.eu/pilot-2-description-cloudferros-role-in-emerald/) - CloudFerro (CF) provides cloud computing services dedicated to specific industries. Company specializes in the storage and processing of large data sets, including Earth observation satellite data repositories. It is the largest company in the Polish space sector, a leader in the European Earth Observation sector and a prime contractor for such institutions as ESA, EUMETSAT, ECMWF - [The 3rd successful General Assembly of the EMERALD project took place in Karlsruhe](https://www.emerald-he.eu/the-3rd-successful-general-assembly-of-the-emerald-project-took-place-in-karlsruhe/) - We are pleased to report the successful conclusion of the 3rd General Assembly of the EMERALD project, held over two productive days in the beautiful city of Karlsruhe, Germany. Hosted by our partner IONOS, the meeting took place on the eleventh floor of their building, offering an excellent venue for our discussions and planning sessions. - [CertGraph Ontology](https://www.emerald-he.eu/certgraph-ontology/) - To consider a cloud system from multiple perspectives (for example, source code, runtime environment, policy documents) during certification, multiple evidence extractors are used, each specializing in a specific domain. The extracted evidence will then be linked together to obtain a holistic view on the whole system. We propose the CertGraph Ontology as an extensible approach to model - [Five EMERALD deliverables submitted in July 2024](https://www.emerald-he.eu/five-emerald-deliverables-submitted-in-july-2024/) - We are glad to inform that five new EMERALD Deliverables were submitted on 31st July 2024. These documents are available in the Deliverables web page: https://www.emerald-he.eu/deliverables/ D1.1 - Data Modelling and interaction mechanisms – v1.0 Initial version of the overview of data models and techniques used for creating and linking the data to evidence (annotation, - [EMERALD pilots and DORA](https://www.emerald-he.eu/emerald-pilots-and-dora/) - The Digital Operational Resilience Act (DORA) requires the European financial sector to take comprehensive measures to improve the security of ICT systems. This also applies to cloud services, which play a central role in the IT infrastructure of financial organizations. In the EU research project ‘EMERALD’ (https://www.emerald-he.eu/), a research team is working on a use - [EMERALD YouTube channel](https://www.emerald-he.eu/emerald-youtube-channel/) - We are happy to announce that EMERALD has launched its YouTube channel to share views, insights and knowledge on the advancements of the projects. In addition to X and LinkedIn, the Emerald Youtube channel will present, through several videos, the main features of the different EMERALD tools as well as the integrated solution on different - [CaixaBank's Role in EMERALD: Enhancing Compliance in Hybrid Cloud-Edge Environments](https://www.emerald-he.eu/caixabanks-role-in-emerald-enhancing-compliance-in-hybrid-cloud-edge-environments/) - As the financial sector embraces digital transformation, the need for robust and scalable cloud solutions becomes critical. CaixaBank (CXB), a leader in financial services in Spain and Portugal, is proud to be part of the EMERALD project, which focuses on certifying hybrid cloud-edge environments, ensuring they meet the highest standards of security and compliance whilst - [The role of OpenNebula for the Multicloud Security Certification Challenges of Emerald](https://www.emerald-he.eu/the-role-of-opennebula-for-the-multicloud-security-certification-challenges-of-emerald/) - OpenNebula is a powerful European open source platform to build and manage Enterprise Clouds, which provides unified management of IT infrastructure and applications, avoiding vendor lock-in and reducing complexity, resource consumption and operational costs. It combines virtualization and container technologies with multi-tenancy, automatic provision, and elasticity to offer on-demand applications and services. OpenNebula supports the - [The success of the 4th EMERALD HE Project General Assembly in Barcelona](https://www.emerald-he.eu/the-success-of-the-4th-emerald-he-project-general-assembly-in-barcelona/) - We recently concluded the fourth General Assembly of the EMERALD HE Project, hosted by our partner CaixaBank in the vibrant city of Barcelona. This gathering provided an exceptional opportunity to bring the team together and assess our achievements over the first year of working on the Continuous Certification as a Service (CaaS) concept. Throughout the - [Seven new EMERALD Deliverables submitted on 31st October 2024](https://www.emerald-he.eu/seven-new-emerald-deliverables-submitted-on-31st-october-2024/) - We are glad to inform that seven new EMERALD Deliverables were submitted at M12. These documents are available in the Deliverables web page: https://www.emerald-he.eu/deliverables/ D1.3 - EMERALD solution architecture - v1 Initial version of the description and design of the architecture of the EMERALD solution and underlying component integration. D2.2 - Source Evidence Extractor – - [Pilot 2 - test environments preparation](https://www.emerald-he.eu/pilot-2-test-environments-preparation/) - Pilot 2 Architecture The first step of Pilot 2 was architecture preparation and it has been achieved (details in https://www.emerald-he.eu/pilot-2-description-cloudferros-role-in-emerald/). The next step was to prepare the test environments. Pilot 2 is intended to demonstrate the operation of EMERALD for Infrastructure as a Service (IaaS) and Platfrom as a Service (PaaS) on a public cloud. All - [Discover the New Resources from the EMERALD Project: Annual Summary and 1st Year Results Poster](https://www.emerald-he.eu/discover-the-new-resources-from-the-emerald-project-annual-summary-and-1st-year-results-poster/) - The first year of EMERALD has come to a close, and we are excited to share two new materials that showcase the work accomplished and the results achieved: Annual Summary 2024 This document provides a detailed overview of the activities completed during the first year, organized by work package. It offers an in-depth perspective on - [EMERALD was present in the 12th Conference of the EU Framework Programme for R&D in Spain representing one of the Cluster 3 projects](https://www.emerald-he.eu/emerald-was-present-in-the-12th-conference-of-the-eu-framework-programme-for-rd-in-spain-representing-one-of-the-cluster-3-projects/) - In November 2024, the CDTI hosted the 12th Conference of the European Union’s Framework Programme for Research and Innovation in Spain, titled ‘Beyond Horizon’. The event was held at the Oviedo Exhibition and Conference Centre with the participation of projects coordinated by Spanish entities that have obtained funding from Horizon Europe. EMERALD was selected to - [Nixu’s Role in EMERALD: Auditors Perspective and Stage-Gate Process](https://www.emerald-he.eu/nixus-role-in-emerald-auditors-perspective-and-stage-gate-process/) - Nixu Certification Oy is an independent subsidiary of DNV Cyber, acting as an official Information Security Inspection Body approved by the Finnish Communications Regulatory Authority. Information security auditors are essential in helping organizations protect sensitive data, maintain regulatory compliance, and mitigate risks associated with cyber threats. Nixu’s role in the EMERALD project is to bring - [EMERALD’s Innovative Approach to Compliance](https://www.emerald-he.eu/emeralds-innovative-approach-to-compliance/) - As financial institutions like CaixaBank (CXB) expand their operations into public cloud environments, integrating SaaS and IaaS with existing on-premise services, they face significant regulatory and security challenges. These hybrid cloud-edge environments require continuous compliance monitoring and certification to meet the stringent standards imposed by the financial sector. In this context, the EMERALD platform plays - [Meet the EMERALD Personas](https://www.emerald-he.eu/meet-the-emerald-personas/) - The EMERALD solution and especially the EMERALD UI is designed in a way that brings together the functionalities of the individual EMERALD components in an easy-to-use and intuitive way to serve as the main access point to the cloud cybersecurity domain for our target users. Thereby, our target users are compliance managers and auditors as - [EMERALD strengthens participation in the ECCO community working groups](https://www.emerald-he.eu/emerald-strengthens-participation-in-the-ecco-community-working-groups/) - Tecnalia and OpenNebula Systems have been invited to join the European Cybersecurity Community (ECCO), led by the European Cyber Security Organization. ECCO comprises a consortium of 13 cybersecurity stakeholders from both the public and private sectors. Its mission is to enhance cooperation between cybersecurity projects across Europe, strengthen Europe's leadership in cybersecurity, support network and - [THREE NEW DELIVERABLES SUBMITTED ON 31st JANUARY 2025](https://www.emerald-he.eu/three-new-deliverables-submitted-on-31st-january-2025/) - We are pleased to announce that we have successfully completed and submitted three new deliverables as part of our project. This milestone marks a significant step forward, consolidating our progress and paving the way for the next phases. The deliverables cover key aspects of our work and provide essential contributions toward achieving the project's objectives: - [Next Generation Set of Evidence Gathering Tools and Techniques](https://www.emerald-he.eu/next-generation-set-of-evidence-gathering-tools-and-techniques/) - A key objective of the EMERALD project is to establish a unified view of the cloud service under certification by extracting and enriching knowledge from different layers of the service and providing suitable evidence for security metrics. We, therefore, are working on providing a next generation set of evidence gathering tools and techniques based on ## Pages - [HOME](https://www.emerald-he.eu/) - Evidence Management for Continuous Certification as a Service in the Cloud THE PROJECT EMERALD will foster the adoption of cloud-based services for both large enterprises and Small and Medium Enterprises (SMEs), by simplifying the process of obtaining an agile security certification. EMERALD’s mission is to provide a user-friendly framework to help stakeholders in the cybersecurity - [PUBLICATIONS](https://www.emerald-he.eu/publications/) - As the project implementation progresses, publications stemming from and acknowledging EMERALD will be available here. - [DELIVERABLES](https://www.emerald-he.eu/deliverables/) - EMERALD will produce a number of deliverables during the lifetime of the project. Deliverables marked as ‘public’ will be available here for download, as soon as they are available. WP1 - Concept and methodology of EMERALD WP2 - Methodology for knowledge extraction WP3 - Evidence assessment and certification WP4 - User interaction and user experience - [ANNUAL SUMMARIES](https://www.emerald-he.eu/annual-summaries/) - EMERALD annual summary offers stakeholders a comprehensive overview of the project's progress and future directions. FIRST YEAR SECOND YEAR - [FLYERS](https://www.emerald-he.eu/flyers/) - Flyers are designed to quickly inform and attract attention from the project's target audience, highlighting key information, events, or updates. They will be published here. 1st EMERALD Flyer 2nd EMERALD Flyer - [PARTNERS](https://www.emerald-he.eu/partners/) - Project Coordinator, WP1 Lead, WP7 LeadJuncal Alonsojuncal.alonso@tecnalia.com(Spain) TECNALIA is the largest centre of applied research and technological development in Spain, a benchmark in Europe and a member of the Basque Research and Technology Alliance. It collaborates with companies and institutions to improve their competitiveness, people’s quality of life and achieve sustainable growth, thanks to a - [OPEN RESOURCES](https://www.emerald-he.eu/open-resources/) - As EMERALD aims to provide benefits to the European society, we will encourage the adoption of Open-Source Software or the contribution to Open-Source communities. All the resources connected to the Open-Source paradigm will be available here. Public repository of the EMERALD EU project Open repository of the EMERALD EU project - [STANDARDIZATION](https://www.emerald-he.eu/standardization/) - Standardization plays a pivotal role in ensuring the consistency, interoperability, and long-term sustainability of the project’s outcomes. Through active engagement with relevant standardization bodies, collaborative initiatives, and the development of shared frameworks, our efforts aim to align project results with established industry and research standards. This section highlights our contributions to standardization processes, ongoing alignment - [PILOTS](https://www.emerald-he.eu/pilots/) - To validate the EMERALD framework, two main categories of pilots have been identified. The goal of these pilots is to illustrate how EMERALD will enable regulated industries to move to cloud-first/native environments while deriving individual compliance level as per industry or customer requirement and provide services fulfilling business needs. Category I: Certification of public Cloud - [KEY RESULTS](https://www.emerald-he.eu/key-results/) - KR1: EXTRACT Evidence extraction from cloud service: A framework to continuously extract knowledge on various layers of the cloud service (infrastructure, code, business processes) and prepare suitable evidence based on them. This result covers the improvements on existing evidence extraction tools and concepts of MEDINA, such as AMOE (Assessment and Management of Organisational Evidence). The - [POSTERS](https://www.emerald-he.eu/posters/) - Posters visually communicate the project's goals, results, or specific aspects in a succinct and engaging manner. Posters published in conferences, workshops, or public spaces will be reported here. - [VIDEOS](https://www.emerald-he.eu/videos/) - Videos offer a dynamic and accessible way to showcase the project's activities, results, and impact. EMERALD videos will be available here. - [APPROACH](https://www.emerald-he.eu/approach/) - The EMERALD approach can be summarized as follows: Different controls from one or more certification schemes are selected, which are a comprehensive set of rules, technical requirements, standards and procedures with which to demonstrate compliance. An intelligent system selects an optimized set of metrics that can be measured to demonstrate compliance to the controls. One - [OBJECTIVES](https://www.emerald-he.eu/objectives/) - The EMERALD project will pursue the following objectives. For each objective, the KeyResults (KRs) to be achieved are also listed. 1 Provide next generation evidence gathering tools based on knowledge graph approach KR1 EXTRACT: A framework to continuously extract knowledge on various layers of the cloud service (infrastructure, code, business processes) and prepare suitable evidence - [LEGAL NOTICE](https://www.emerald-he.eu/legal-notice/) - Use of the website IIT-CNR takes the utmost care in the quality and updating of published information. Nevertheless, with respect to the wide variety of sources used, internal and external to the Institute, and to the large number of pages available, it should be noted that over time the information may lose its validity and - [COOKIE POLICY](https://www.emerald-he.eu/cookie-policy/) - Cookies consist of portions of code installed in the browser that assist the Owner in providing the service according to the purposes described. Some of the purposes of installing cookies may also require the User’s consent. This Site uses technical cookies to save the User’s session and to carry out other activities strictly necessary to - [PRIVACY POLICY](https://www.emerald-he.eu/privacy-policy/) - In accordance to article 13 of the EU Regulation No. 2016/679 on the protection of personal data (hereinafter referred to as “GDPR”), of the Recommendation No. 2/2001 of the Working Party ex art. 29 and of the general Provision of the Italian Authority Control on cookies of 8 May 2014, n. 229 laying down provisions - [NETWORKING](https://www.emerald-he.eu/networking/) - [PRESENTATIONS](https://www.emerald-he.eu/presentations/) - [EMERALD FRAGMENTS](https://www.emerald-he.eu/emerald-fragments/) - If you want to stay up-to-date on the progress of the project, this is the right place. New EMERALD ‘fragments’ will be published on a regular basis to answer stakeholders’ questions and to raise awareness about EMERALD milestones and outcomes. AllfragmentsEmerald pilot 4: turning continuous compliance into reality for the financial sectorFrom Periodic Audits to - [PRESS RELEASES](https://www.emerald-he.eu/press-release/) - [MISSION](https://www.emerald-he.eu/mission/) - The EMERALD project is dedicated to transforming the landscape of cloud-based services, focusing on developing a new framework to enhance security and efficiency for both large and Small and Medium Enterprises. With a commitment to developing an agile certification process, EMERALD will support Service Providers, Customers and Auditors in the certification process, fostering the adoption - [CONTACT](https://www.emerald-he.eu/contact/) - TECNALIA Address: Parque Tecnológico de Bizkaia, C/ Geldo. Edificio 700. E-48160 Derio (Bizkaia) Phone: +(34) 946.430.850 E-mail: juncal.alonso@tecnalia.com - [Category II: Certification of hybrid cloud-edge environments for the financial sector](https://www.emerald-he.eu/uc-2/) - The second category aims at the certification of hybrid cloud-edge environments for the financial sector. Main driver of this category definition is CaixaBank, which currently holds a large number of on-premise services and is trying to expand this into the field of public clouds, i.e. using SaaS or IaaS providers. However, due to regulation, there - [Category I: Certification of public Cloud Services](https://www.emerald-he.eu/uc-1/) - The first category includes three pilots, which aim at demonstrating Certification as a Service with EMERALD, on the level of cloud services for IaaS (Pilot 1, IONOS), IaaS / PaaS (Pilot 2, CF) and SaaS (Pilot 3, FABA). All three will describe the path for integrating EMERALD tools from for European cloud service providers, considering ## My Templates - [Kit predefinito](https://www.emerald-he.eu/?elementor_library=kit-predefinito) ## Categories - [fragments](https://www.emerald-he.eu/category/fragments/) - [press](https://www.emerald-he.eu/category/press/) - [presentations](https://www.emerald-he.eu/category/presentations/) - [networking](https://www.emerald-he.eu/category/networking/) ## Tags - [MEETINGS](https://www.emerald-he.eu/tag/meetings/) - [DELIVERABLES](https://www.emerald-he.eu/tag/deliverables/) - [EVENTS](https://www.emerald-he.eu/tag/events/) - [COMMUNICATION](https://www.emerald-he.eu/tag/communication/) - [NETWORKING](https://www.emerald-he.eu/tag/networking/) - [TECHNICAL ADVANCEMENTS](https://www.emerald-he.eu/tag/technical-advancements/) - [AUDITING](https://www.emerald-he.eu/tag/auditing/)