Data I/O enters non-binding LOI to acquire IAR security assets
Data I/O Corporation and I.A.R. Systems AB announced a non-binding LOI for Data I/O to acquire IAR's embedded software security IP and related assets. The transaction includes platforms like Embedded Trust and Secure Deploy, building on a February 2026 collaboration. Financial terms were not disclosed.

*this image is generated using AI for illustrative purposes only.
Data I/O Corporation and I.A.R. Systems AB (IAR) jointly announced a non-binding Letter of Intent (LOI) for Data I/O to acquire IAR's embedded software security IP and related assets. The proposed transaction includes software, source code, hardware, intellectual property, engineering infrastructure, manufacturing equipment, and certifications. Financial terms and the anticipated timing of the closing were not disclosed.
The acquisition builds on the companies’ February 2026 technology collaboration, which unified security provisioning from embedded design through manufacturing. Data I/O will take full ownership of the core technology underlying that collaboration, including the Embedded Trust and Secure Deploy platforms, the eSecIP toolchain, and the certificate authority and provisioning infrastructure. Following the closing, Data I/O will assume full ownership of customer support for these products.
Full ownership of the IAR embedded software security technology stack will give Data I/O direct control over the security provisioning roadmap, device support, and release cadence. This positions the company to extend its security offering upstream into the design phase while continuing to serve customers through its programming and provisioning platforms. The move aims to strengthen Data I/O's position as government regulations and industry standards, such as the EU Cyber Resilience Act, increasingly mandate robust security measures for connected electronic products.
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity and vulnerability-handling standards for nearly all hardware and software products connected to a network. Full mandatory compliance for all products sold in the EU is required by December 2027. The act introduces lifecycle security requirements, CE marking, security-by-design standards, guaranteed security updates, and strict reporting for Software Bill of Materials (SBOM).
Strategic Assets and Collaboration
The intended transaction encompasses a range of assets critical to the embedded security ecosystem. The table below outlines the key components included in the proposed acquisition.
| Asset Category | Specific Components |
|---|---|
| Software Platforms | Embedded Trust, Secure Deploy |
| Toolchain | eSecIP |
| Infrastructure | Certificate authority, provisioning infrastructure |
| Other Assets | Source code, hardware, engineering infrastructure, manufacturing equipment, certifications |
Despite the asset transfer, the commercial partnership between IAR and Data I/O will continue. The February 2026 collaboration, which integrates IAR's embedded software security solution with Data I/O's PSV programming systems, remains unchanged and will serve as a cornerstone of the joint offering to OEMs worldwide.
Executive Commentary
William Wentworth, President and CEO of Data I/O Corporation, described the acquisition as a natural next step in the company's evolution. He stated that the acquisition of the IP and HSM design allows Data I/O to design security provisioning into its core platform rather than integrating multiple third-party products. Wentworth emphasized that the company's data provisioning platform is a natural extension for secure provisioning, aligning with its Programming-as-a-Service strategy and the regulatory tailwind of the EU Cyber Resilience Act.
Karin Schreil, Senior Vice President of BU IAR at Qt Group, expressed support for the transaction. She noted that IAR acquired the portfolio in 2018 and that many customers depend on the technology. Schreil stated that the transaction secures the future of the technology and ensures continuity for customers with a partner positioned to invest in its growth, while IAR and Qt Group continue to focus on their core offerings.
How will Data I/O integrate the newly acquired engineering teams and infrastructure to accelerate the security provisioning roadmap?
What is the expected financial impact of this acquisition on Data I/O's R&D expenses and revenue growth over the next fiscal year?
Will the full ownership of the security stack allow Data I/O to expand its market share beyond traditional manufacturing into the embedded design phase?

























