What ships, what is next
Two headline features ship today. One-click CRA readiness for the EU Cyber Resilience Act runs on both nRF and ESP: an SBOM (SPDX), a secure-by-design posture check, and a CVE fix loop. And a guided 3-layer debug on Nordic nRF correlates your app log, the HCI bus, and the over-the-air radio to pinpoint where a BLE flow actually broke, not just what the app logged. Next up is extending 3-layer decoding beyond BLE, plus more chips and protocols, and, in beta, handing a running task to your own coding agent so Adsum brings the embedded expertise and drives the toolchain while your agent does the work. The roadmap is shaped by what the community asks for and contributes. Open an issue, propose a benchmark task, or contribute a knowledge module.
Limitations
We publish what is true today, not what we wish were true.- Scope. Today the tool ships for Nordic nRF52/53/54 (BLE) and Espressif ESP32/S3/C6 (Wi-Fi, BLE). Other Nordic families (nRF7x, nRF9x) and other protocols (Thread, Matter, LTE-M) are roadmap, not shipping.
- Benchmark sample size. Six tasks is a proof of concept, not statistical significance. v0.2 targets 20 to 30 tasks, including an ESP suite.
- SDK coverage. All benchmark tasks ran on a single NCS version (v3.2.1). Older LTS versions are roadmap items.
- CRA readiness. A readiness aid, not a conformity assessment and not legal advice. The CVE flow confirms a component you name is present in your build and helps you patch it; it does not scan for unknown CVEs. See CRA readiness.
- Trademarks. nRF and Nordic Semiconductor are trademarks of Nordic Semiconductor ASA; ESP32 and ESP-IDF are trademarks of Espressif Systems. This is an independent project, not affiliated with or endorsed by either.

