
Our Approach to the CRA
AEWIN treats cyber resilience as a core strategic direction for industrial computing, embedding security into product architecture from the ground up. AEWIN maintains a rigorous security process across design, development, testing, and lifecycle maintenance. With the EU Cyber Resilience Act (CRA) ushering in mandatory cybersecurity compliance for digital products, AEWIN has proactively begun related technical and process preparations to help customers align with international standards efficiently and reduce compliance costs.
The CRA (EU 2024/2847) establishes cybersecurity requirements for all products with digital elements sold into the EU. AEWIN's early preparation ensures its industrial computing equipment delivers superior built-in defense capability and market competitiveness.

To give manufacturers sufficient time to adjust and align, the EU Cyber Resilience Act (CRA) adopts a phased rollout strategy. The regulation officially took effect on December 10, 2024, and will be progressively implemented over the following years.
During this transition period, companies must pay particular attention to two key milestones: first, September 11, 2026, when mandatory reporting of security vulnerabilities becomes a legal requirement; and second, December 11, 2027, the "full compliance deadline," by which all products falling within the scope of the CRA must meet the relevant market access requirements. This timeline will affect CE marking and eligibility for sale in the EU market for applicable products.

Security Advisories & Vulnerability Procedures
AEWIN has established a Product Security Incident Response Team (PSIRT), taking a proactive approach through established processes to help reduce product security risks and helping customers obtain relevant security information and support resources to address cybersecurity challenges.
We evaluate, investigate, and handle reports that may affect the security of AEWIN products according to our established vulnerability management procedures. We have therefore developed a Security Vulnerability Management Policy and established a Security Advisories section to provide customers with guidance and information when security vulnerabilities are discovered. This policy ensures that all customers have ongoing access to clear resources for understanding how AEWIN resolves or mitigates security vulnerabilities reported by customers.
If you discover a potential security vulnerability in a AEWIN product
please submit a detailed report to help expedite our risk assessment and enable us to provide a fix or mitigation as quickly as possible.
The report should include the following information:
|
|
|
|
|
|
|
|
PSIRT@aewin.com

