Our Approach to the CRA

AEWIN treats cyber resilience as a core strategic direction for industrial computing, embedding security into product architecture from the ground up. AEWIN maintains a rigorous security process across design, development, testing, and lifecycle maintenance. With the EU Cyber Resilience Act (CRA) ushering in mandatory cybersecurity compliance for digital products, AEWIN has proactively begun related technical and process preparations to help customers align with international standards efficiently and reduce compliance costs.

The CRA (EU 2024/2847) establishes cybersecurity requirements for all products with digital elements sold into the EU. AEWIN's early preparation ensures its industrial computing equipment delivers superior built-in defense capability and market competitiveness.

To give manufacturers sufficient time to adjust and align, the EU Cyber Resilience Act (CRA) adopts a phased rollout strategy. The regulation officially took effect on December 10, 2024, and will be progressively implemented over the following years.

During this transition period, companies must pay particular attention to two key milestones: first, September 11, 2026, when mandatory reporting of security vulnerabilities becomes a legal requirement; and second, December 11, 2027, the "full compliance deadline," by which all products falling within the scope of the CRA must meet the relevant market access requirements. This timeline will affect CE marking and eligibility for sale in the EU market for applicable products.

Security Advisories & Vulnerability Procedures

AEWIN has established a Product Security Incident Response Team (PSIRT), taking a proactive approach through established processes to help reduce product security risks and helping customers obtain relevant security information and support resources to address cybersecurity challenges.

We evaluate, investigate, and handle reports that may affect the security of AEWIN products according to our established vulnerability management procedures. We have therefore developed a Security Vulnerability Management Policy and established a Security Advisories section to provide customers with guidance and information when security vulnerabilities are discovered. This policy ensures that all customers have ongoing access to clear resources for understanding how AEWIN resolves or mitigates security vulnerabilities reported by customers.

 PSIRT

If you discover a potential security vulnerability in a AEWIN product

please submit a detailed report to help expedite our risk assessment and enable us to provide a fix or mitigation as quickly as possible.

The report should include the following information:

  • Product name and model
  • Steps to reproduce the issue (please include images or code where possible)
  • Packet capture of the attack process
  • Software/firmware version
  • Proof of concept or exploit code
  • Any other supplementary information you believe would aid the analysis
  • Equipment and software required to reproduce the issue
  • Description of potential attack impact
 

 PSIRT@aewin.com

CRA Frequently Asked Questions (FAQ)

What is the EU Cyber Resilience Act (CRA)?

Which products are actually covered by the CRA?

What are the main obligations manufacturers must fulfill?

What are CRA harmonized standards?

When does the CRA take effect, and what are the deadlines?

What penalties apply for non-compliance with the CRA?

How does the CRA differ from the NIS2 Directive?

What is a Software Bill of Materials (SBOM)?

洽詢車

你的洽詢車總計 0 件產品

產品比較

你的比較總計 0 件產品

訂閱電子報

數字驗證

請由小到大,依序點擊數字

我們使用 cookies 以確保我們的網站正常運作,個性化內容和廣告,提供社交媒體功能並分析流量。我們還會與社交媒體、廣告和分析合作夥伴分享您使用我們網站的信息。

管理Cookies

隱私權偏好設定中心

我們使用 cookies 以確保我們的網站正常運作,個性化內容和廣告,提供社交媒體功能並分析流量。我們還會與社交媒體、廣告和分析合作夥伴分享您使用我們網站的信息。

管理同意設定

必要的Cookie

一律啟用

這些 cookies 是網站運作所必需的,您無法在系統上關閉它們。

這些 Cookie 通常僅在您執行某個動作(即服務請求)時設置,例如設置隱私偏好、登錄或填寫表單。

您可以設置瀏覽器以阻止或提示您這些Cookie,但這可能會導致某些網站功能無法正常運作。