Burkhard Zimmermann
Leading IEC SC62 D JWG 36 and support IEC SC62A JWG 9 as an expert
Leading IEC SC62 D JWG 36 and support IEC SC62A JWG 9 as an expert
Co-founder of a circular economy startup developing infrastructure for DPP-enabled resale in the European textile sector, based in Berlin. Leading business development, regulatory strategy, and product design for a platform that enables verified resale through Digital Product Passports. The startup is incubated at ESCP Blue Factory.
French national with experience in business development and technology. Self-taught technical skills in product prototyping and data systems. Previous experience includes roles in consulting and business analysis.
Beyond this project: Active in the European circular economy ecosystem. Relocating to Paris in May 2026 to continue building at the intersection of sustainability regulation and commerce technology.
The fellowship addressed key limitations found in version 2.0 of the OASIS Collaborative Automated Course of Action Operations (CACAO) standard. While CACAO v2.0 introduced the first machine-readable format for cybersecurity playbooks, real-world use revealed gaps that limited interoperability and automation. The most critical issues included ambiguous schema elements, unclear execution semantics, and limited support for graphical and modular representations needed to visualize and exchange playbooks. From a European standpoint, these shortcomings directly affected operations. SOCs, CSIRTs, and critical infrastructure operators faced difficulties creating executable playbooks, hindering the coordinated responses envisioned by the NIS2 Directive, the Cyber Solidarity Act, and the EU Cyber Crisis Blueprint.
The fellowship, therefore, focused on three main goals:
1. Consolidating feedback from European and international stakeholders who implemented CACAO v2.0.
2. Designing and drafting CACAO v3.0 — a major revision introducing structural schema improvements, more precise execution semantics, and modular extensibility.
3. Aligning the work with EU cybersecurity policy and operational priorities so that standardized, machine-readable playbooks can support coordinated preparedness and response.
The effort resulted in the ongoing working CACAO v3.0 Draft Specification and accompanying validation outputs, now progressing toward formal adoption within OASIS. By resolving the main technical and semantic issues, the fellowship strengthened Europe’s role in cybersecurity standardization. It established a solid, vendor-neutral foundation for automated, collaborative cyber defense across the EU.
My work aims to develop robust frameworks for the verification of cryptographic protocols within the security of ICT products, services, and processes, thereby enhancing resilience against cyber threats.
This project, towards enabling a fairer marketplace for rights holders and remuneration of authors and performers, initiated work on a new standard ISO/IEC 23000-23 Decentralised Media Rights Application Format currently at the Working Draft (WD) stage.
The objective of this fellowship is to include European contributions on viable methodologies on semantic interoperability in ISO standards: ISO SC41 IoT and Digital Twin, with a focus on practical use cases in the domains of health/well-being.
With this fellowship, I am addressing the standardisation of AI systems, with particular focus on the standardisation request of the EU Commission in relation to the AI Act.
This fellowship is meant to increase confidence in cybersecurity through the convergence of international SDOs and the alignment behind a common international standard which relates both to the market and society.