Burkhard Zimmermann
Leading IEC SC62 D JWG 36 and support IEC SC62A JWG 9 as an expert
Leading IEC SC62 D JWG 36 and support IEC SC62A JWG 9 as an expert
Co-founder of a circular economy startup developing infrastructure for DPP-enabled resale in the European textile sector, based in Berlin. Leading business development, regulatory strategy, and product design for a platform that enables verified resale through Digital Product Passports. The startup is incubated at ESCP Blue Factory.
French national with experience in business development and technology. Self-taught technical skills in product prototyping and data systems. Previous experience includes roles in consulting and business analysis.
Beyond this project: Active in the European circular economy ecosystem. Relocating to Paris in May 2026 to continue building at the intersection of sustainability regulation and commerce technology.
The sectors of Digital Twins, Virtual Worlds/Citiverse, IoT and Data Spaces are fragmented, especially the uneven uptake of NGSI‑LD, Smart Data Models/SAREF and governance models creates a barrier for cross‑domain interoperability in cities. Therefore, I focus on harmonising these layers within ITU‑T Citiverse and EU Local Digital Twin (LDT) Toolbox. I also contribute to aligning LDT and Data Space governance with UNE 0087:2025 and the Gaia‑X Trust Framework to operationalise sovereignty, compliance and automated conformance. Moreover, I contribute to mapping LDT/MIM8, NGSI‑LD, SIMPL and Citiverse deliverables to speed deployment and avoid duplicate or conflicting specs.
This fellowship supports my role as a convener of ISO TCC307 WG3. The priority is to organise the appropriate ballots and meetings to allow the experts to discuss and reach a consensus based on the comments received for the projects in ISO TC 307 WG3. Another priority is to complete the norms with the attendance list and verify that all experts in the meeting were duly registered in the portal and authorised to participate in the meetings.
One of the main challenges of this work has been overcoming the cultural barriers and language differences encountered during this period, particularly through various meetings and ad hoc meetings for the three projects, which are ongoing in preparation for the final stage to publication.
This fellowship supported my work in updating to the IEEE 802.11 standard to prevent a recently discovered security weakness. This weakness is related to mesh networks, where, without extra defenses, an adversary could inject arbitrary packets into protected mesh networks. We designed a defense to mitigate this challenging gap. Unique about our created defense is that it is fully backward compatible, meaning each individual mesh client can independently enable this defense. As a proof-of-concept, we also implemented this defense in the Linux kernel to demonstrate practicality and confirm it prevents attacks.
The fellowship addressed key limitations found in version 2.0 of the OASIS Collaborative Automated Course of Action Operations (CACAO) standard. While CACAO v2.0 introduced the first machine-readable format for cybersecurity playbooks, real-world use revealed gaps that limited interoperability and automation. The most critical issues included ambiguous schema elements, unclear execution semantics, and limited support for graphical and modular representations needed to visualize and exchange playbooks. From a European standpoint, these shortcomings directly affected operations. SOCs, CSIRTs, and critical infrastructure operators faced difficulties creating executable playbooks, hindering the coordinated responses envisioned by the NIS2 Directive, the Cyber Solidarity Act, and the EU Cyber Crisis Blueprint.
The fellowship, therefore, focused on three main goals:
1. Consolidating feedback from European and international stakeholders who implemented CACAO v2.0.
2. Designing and drafting CACAO v3.0 — a major revision introducing structural schema improvements, more precise execution semantics, and modular extensibility.
3. Aligning the work with EU cybersecurity policy and operational priorities so that standardized, machine-readable playbooks can support coordinated preparedness and response.
The effort resulted in the ongoing working CACAO v3.0 Draft Specification and accompanying validation outputs, now progressing toward formal adoption within OASIS. By resolving the main technical and semantic issues, the fellowship strengthened Europe’s role in cybersecurity standardization. It established a solid, vendor-neutral foundation for automated, collaborative cyber defense across the EU.