" " indicates required fields
[Read the Chinese version of this announcement]
Tel Aviv, Israel and Shanghai, China – July 30, 2025: C2A Security, the only context-driven product security orchestration platform that addresses the specific needs of software-defined products and cyber-physical systems, and Itbigtec, a leading IT solutions company in China, today announced a strategic partnership. The joint initiative is tailored towards cyber-physical systems in critical industries such as energy, manufacturing, transportation, smart devices, and critical infrastructure. This initiative will empower enterprises to efficiently comply with domestic and international standards and regulations, as GB 44495-2024, European Cyber Resilience Act (CRA), FDA HIPAA, ISO/SAE 21434, and others, accelerating their digital transformation and global expansion.
C2A Security also announced that Eason Yu has joined the team, leading account management activities in Mainland China, based in Shanghai. Reporting to Stephane Khelifi, VP Account Management and Solutions, Eason brings extensive experience to the role from companies as Cybellum and HARMAN, where he held similar positions.
C2A Security’s product security orchestration platform empowers customers as Daimler Truck AG, Elekta, Aptiv, BMW Group, NTT Data, Deloitte, and many others to stay ahead of regulatory demands by streamlining compliance and automating the generation of audit-ready reports for UN R155, CRA, ISO/CD 24882, FDA HIPAA, and others. Designed for software-defined products and complex cyber-physical systems, the platform enables a proactive, context-driven approach that significantly reduces manual effort while maintaining complete transparency into software risks. This ensures that customers can efficiently manage product security at scale, across the entire product lifecycle, from early design and development through testing, production, and post-production updates.

“I am excited about this new partnership with Itbigtec,” said Stephane Khelifi, VP Accounts and Solutions, C2A Security. “The partnership will help us expand our footprint in the Chinese market, allowing us to deliver our innovative product security platform to Chinese manufacturers in the healthcare, automotive, industrial, and robotics sectors, to name a few.”
The EVSec Platform distinguishes itself from traditional, siloed tools through its context-driven approach to risk management:

C2A Security’s solutions have established a leadership position in global industries such as automotive, energy, and healthcare, helping enterprises reduce security costs while enhancing compliance transparency and market competitiveness.
“This partnership marks a critical milestone in Itbigtec’s our mission to build a security compliance ecosystem, offering Chinese enterprises a next-generation solution to tackle digital-era security challenges,” commented Lara Xu, Head of BU, Itbigtec. “Moving forward, the two companies will jointly develop a compliance ecosystem tailored to Chinese enterprises, empowering industries such as automotive, energy, and smart manufacturing to gain a competitive edge in global markets and advance toward a security-driven digital future.”
Dynamic threat modeling and risk assessment aligned with global regulations
LLM-agnostic generative AI layer powering automation across every module
Aggregated threat feed contextualized against your actual products
Generate, manage, and triage all BOMs and vulnerabilities across the lifecycle
Quantitative optimization of mitigation strategy and security control allocation
Configurable dashboards and reports across every EVSec data layer
Extract software composition and risk from firmware and binaries without source code
Optimized anomaly detection for Ethernet and CAN, plus ECU runtime protection
Quantify and manage cybersecurity risk for products operating in the field
Enrich SOC events with deep product and architecture context
Context-driven test and validation with intelligent fuzzing, integrated into CI/CD
AI-powered static analysis integrated into CI/CD with reduced false positives
Foundational layer: cyber model, workspaces, and integration backbone to DevOps toolchain
Out-of-the-box and customizable workflows for regulatory and security processes
Centralized compliance management with evidence generated from live data