DJI Security Assessment Finds No Critical, High or Medium Risks: What Canadian Buyers Should Know
SpeedyDrone News & Updates

DJI Security Assessment Finds No Critical, High or Medium Risks: What Canadian Buyers Should Know

DJI News · May 28, 2026

A strong test result is evidence, not a universal certification.

OnDefend tested two defined DJI systems across software, hardware and radio frequency domains. Canadian buyers should use the findings inside a current, product-specific security review.

Quick answer

DJI announced on May 28, 2026 that U.S. cybersecurity firm OnDefend found zero critical, high or medium-risk issues during a five-month assessment of DJI Air 3S with RC 2 and DJI Matrice 4E with RC Plus 2 Enterprise. The result is useful procurement evidence. It does not certify every DJI model, later firmware, Canadian network path, cloud configuration or organization policy.

Request a Drone Security Fit Review

What was announced

The engagement tested two complete, market-standard configurations.

DJI authorized the assessment, while OnDefend conducted the work independently. Consumer units were bought through retail without advance notice to DJI. Enterprise units came from existing dealer stock. DJI says all tested devices reflected standard U.S. market distribution.

5 monthsTesting ran from October 2025 through March 2026.
2 systemsAir 3S with RC 2 and Matrice 4E with RC Plus 2 Enterprise.
0 medium+No critical, high or medium-risk findings were reported.
10 lowTen low-risk findings and thirteen observations were reported.
Real DJI Air 3S product image from SpeedyDrone Canada
The assessment used Air 3S with RC 2. This SpeedyDrone image shows the real aircraft; controller configuration must still be matched to the tested system.
Real DJI Matrice 4E product image from SpeedyDrone Canada
The enterprise configuration was Matrice 4E with RC Plus 2 Enterprise. Later firmware and organization settings require continuing review.

What the test found

No hidden backdoor, unexplained radio path or medium-plus risk was reported.

Evidence supported by the assessment

During the defined test window, OnDefend reported no evidence of data transmission outside the United States, no backdoors or unauthorized remote access mechanisms, no unexplained radio-frequency emissions and no supply-chain tampering in the tested units.

Questions the assessment does not close

The report is not a Canadian certification, procurement approval or guarantee covering every model. It does not replace a review of current firmware, application versions, user permissions, network architecture, data residency requirements, incident response or applicable public-sector policy.

Important independence context: DJI commissioned and authorized the engagement. OnDefend conducted the testing independently, and the published executive summary recommends continuing independent validation as firmware, software and hardware change.

Why it matters for SpeedyDrone Canada

Canadian procurement teams can ask better questions with concrete test evidence.

The assessment is relevant to buyers comparing a current DJI Air 3S workflow or evaluating DJI Matrice 4E for enterprise mapping and inspection. The strongest use is to turn a vague security concern into a written evidence matrix.

Match the tested bill of materials

Record aircraft, controller, mobile device, application, firmware, radio module and accessories. A different controller or firmware version is a different evidence boundary.

Define the data path

Map where flight logs, images, credentials and live video can travel. Review local data mode, cloud services, network routing, account region and any third-party integrations actually used by the organization.

Apply organization policy

Security controls must meet the buyer's sector, contract and internal risk framework. A technical assessment does not waive procurement restrictions or determine whether a public organization may buy a platform.

Plan ongoing validation

Record approved versions, change-control triggers, update testing, credential lifecycle, access reviews and incident response. Point-in-time testing loses value if the deployed configuration drifts without review.

Buyer checklist

Ask for evidence that matches the mission, not only the brand.

  1. Which exact aircraft and controller will be purchased?
  2. Which application, firmware and account region will be used?
  3. What data is collected, where is it stored and who can access it?
  4. Will local data mode, cloud features or third-party integrations be required?
  5. What sector-specific procurement and privacy rules apply?
  6. What changes trigger a new security review?
  7. Who owns patching, access control, logs and incident response?

SpeedyDrone's DJI Enterprise Canada page provides the current solution path. Security approval remains the buyer's governance decision.

DJI Security Assessment FAQ

Who conducted the 2026 DJI security assessment?

U.S. cybersecurity firm OnDefend conducted the assessment. DJI authorized and commissioned the engagement, while OnDefend performed the testing independently.

Which DJI products were tested?

The tested systems were DJI Air 3S with RC 2 and DJI Matrice 4E with RC Plus 2 Enterprise, using standard U.S. market units.

What risk findings were reported?

The assessment reported zero critical, high or medium-risk findings, along with ten low-risk findings and thirteen observations.

Did the assessment find data transmission outside the United States?

No such transmission was identified during the test window. The finding applies to the tested configurations and observed connections, not every possible future configuration.

Does the report certify every DJI drone?

No. It covers two defined systems and a defined test period. Other models, controllers, firmware, applications and network designs need their own evidence review.

Is this a Canadian government security certification?

No. It is an independent technical assessment, not a Canadian government certification, procurement approval or waiver of organization policy.

Why does firmware version matter?

Firmware and application updates can change code, permissions, communications and vulnerabilities. OnDefend recommended continuous independent validation as products change.

What should a Canadian buyer verify before deployment?

Verify the exact configuration, current software, data flows, account region, network controls, user permissions, sector policy, update process and incident-response ownership.

Official and live sources

Turn security claims into a configuration-specific evidence checklist.

Share the aircraft, controller, mission, organization, network and data requirements. SpeedyDrone can help identify the current product configuration and the evidence your security team still needs to review.

Request a Drone Security Fit Review

Checked August 8, 2026. This article does not provide legal, privacy, cybersecurity or procurement approval.

Previous
DJI O4 Ground Station Launch: What It Means for Canadian Dock and Remote Drone Operations
Next
DJI Agriculture's 2026 Global Report: What 51 Million Tonnes of Carbon and 410 Million Tonnes of Water Savings Mean