Our Approach to the CRA

AEWIN treats cyber resilience as a core strategic direction for industrial computing, embedding security into product architecture from the ground up. AEWIN maintains a rigorous security process across design, development, testing, and lifecycle maintenance. With the EU Cyber Resilience Act (CRA) ushering in mandatory cybersecurity compliance for digital products, AEWIN has proactively begun related technical and process preparations to help customers align with international standards efficiently and reduce compliance costs.

The CRA (EU 2024/2847) establishes cybersecurity requirements for all products with digital elements sold into the EU. AEWIN's early preparation ensures its industrial computing equipment delivers superior built-in defense capability and market competitiveness.

To give manufacturers sufficient time to adjust and align, the EU Cyber Resilience Act (CRA) adopts a phased rollout strategy. The regulation officially took effect on December 10, 2024, and will be progressively implemented over the following years.

During this transition period, companies must pay particular attention to two key milestones: first, September 11, 2026, when mandatory reporting of security vulnerabilities becomes a legal requirement; and second, December 11, 2027, the "full compliance deadline," by which all products falling within the scope of the CRA must meet the relevant market access requirements. This timeline will affect CE marking and eligibility for sale in the EU market for applicable products.

Security Advisories & Vulnerability Procedures

AEWIN has established a Product Security Incident Response Team (PSIRT), taking a proactive approach through established processes to help reduce product security risks and helping customers obtain relevant security information and support resources to address cybersecurity challenges.

We evaluate, investigate, and handle reports that may affect the security of AEWIN products according to our established vulnerability management procedures. We have therefore developed a Security Vulnerability Management Policy and established a Security Advisories section to provide customers with guidance and information when security vulnerabilities are discovered. This policy ensures that all customers have ongoing access to clear resources for understanding how AEWIN resolves or mitigates security vulnerabilities reported by customers.

 PSIRT

If you discover a potential security vulnerability in a AEWIN product

please submit a detailed report to help expedite our risk assessment and enable us to provide a fix or mitigation as quickly as possible.

The report should include the following information:

  • Product name and model
  • Steps to reproduce the issue (please include images or code where possible)
  • Packet capture of the attack process
  • Software/firmware version
  • Proof of concept or exploit code
  • Any other supplementary information you believe would aid the analysis
  • Equipment and software required to reproduce the issue
  • Description of potential attack impact
 

 PSIRT@aewin.com

CRA Frequently Asked Questions (FAQ)

What is the EU Cyber Resilience Act (CRA)?

Which products are actually covered by the CRA?

What are the main obligations manufacturers must fulfill?

What are CRA harmonized standards?

When does the CRA take effect, and what are the deadlines?

What penalties apply for non-compliance with the CRA?

How does the CRA differ from the NIS2 Directive?

What is a Software Bill of Materials (SBOM)?

咨询车

您的咨询车共计 0 件产品

产品比较

您的比较共计 0 件产品

订阅电子报

数字验证

请由小到大,依序点击数字

我们使用 cookies 以确保我们的网站正常运作,个性化内容和广告,提供社交媒体功能并分析流量。我们还会与社交媒体、广告和分析合作伙伴分享您使用我们网站的信息。

管理Cookies

隱私權偏好設定中心

我们使用 cookies 以确保我们的网站正常运作,个性化内容和广告,提供社交媒体功能并分析流量。我们还会与社交媒体、广告和分析合作伙伴分享您使用我们网站的信息。

管理同意設定

必要的Cookie

一律啟用

这些 cookies 是网站运作所必需的,您无法在系统上关闭它们。

这些 Cookie 通常仅在您执行某个动作(即服务请求)时设置,例如设置隐私偏好、登录或填写表单。

您可以设置浏览器以阻止或提示您这些Cookie,但这可能会导致某些网站功能无法正常运作。