Frequently Asked Questions
▌Q: What products and activities does the CRA cover?
A: The CRA is Regulation (EU) 2024/2847. It establishes horizontal cybersecurity requirements for products with digital elements that can connect directly or indirectly to another device or network. Its requirements cover secure product design, vulnerability management, security updates, technical documentation, and reporting obligations.
▌Q: Which IBASE products may fall within its scope?
A: The assessment depends on whether a product has direct or indirect data connectivity and whether it is made available on the EU market. Unless covered by other sector-specific legislation, many IBASE industrial computers, embedded systems, and related software products may be within scope. Applicability to a specific model must be determined based on its functional configuration, delivery form, and sales region. Contact your IBASE sales representative to discuss a specific model.
▌Q: How are products classified, and what does classification affect?
A: The CRA divides products into the default category, important products Class I, important products Class II, and critical products. Important and critical products are listed in Annexes III and IV. Classification determines the available conformity assessment route; higher-risk classes generally require greater third-party involvement.
▌Q: What are harmonised standards, and what is their current status?
CEN, CENELEC, and ETSI develop harmonised standards in response to the European Commission's standardisation request. These standards translate the CRA's essential requirements into verifiable technical specifications. CRA-related horizontal and product-specific standards remain under development and review, and their publication status should be checked against the latest EU notices.
▌Q: When do the reporting obligations begin, and what are the deadlines?
A: The reporting obligations apply from 11 September 2026. After becoming aware of an actively exploited vulnerability or a severe incident, a manufacturer must submit an early warning within 24 hours and a notification within 72 hours. A final report must then be submitted after remediation of the vulnerability or completion of incident handling, within the applicable regulatory deadline.
▌Q: Does the CRA apply to products already on the market?
A: The CRA contains transitional provisions for existing products. The essential requirements generally apply to products placed on the market after the full application date or to products that undergo a substantial modification after that date. Reporting obligations have a separate application date and also cover products already made available on the Union market. The actual determination must be made case by case based on market placement and subsequent changes.
▌Q: What may constitute a substantial modification?
A: A modification may be substantial when it changes a product's intended purpose or may affect its compliance with the essential cybersecurity requirements. Such a product may be treated as newly placed on the market. The nature and impact of the modification must be assessed case by case.
▌Q: What are the consequences of non-compliance with the CRA?
A: Authorities may require corrective action and may impose market measures such as withdrawal or sales restrictions. For infringements of essential cybersecurity requirements or key manufacturer obligations, administrative fines may reach EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Lower maximum fines apply to certain failures to provide information or cooperate with authorities.
▌Q: How do the CRA, NIS2, EN 18031, and IEC 62443 differ?
A: The CRA regulates products with digital elements. NIS2 addresses organisational cybersecurity management for critical infrastructure and essential or important entities. EN 18031 supports relevant requirements for radio equipment. IEC 62443 is a family of technical standards that can support secure development processes and product security capabilities. They serve different purposes and do not replace one another.
▌Q: What is IBASE's role under the CRA?
A: Many IBASE products are components or motherboards intended for integration. The party that places the final product on the EU market under its own name or trademark is generally the manufacturer under the regulation and assumes the corresponding obligations. Roles depend on the actual transaction and market placement model. IBASE can assist customers in discussing their product architecture.
▌Q: What cybersecurity foundations and certifications does IBASE currently have?
A: IBASE is certified to ISO 27001 for its information security management system. It has also established a secure product development lifecycle in accordance with IEC 62443-4-1 and obtained certification. Implementation of relevant IEC 62443-4-2 requirements is being planned. Certificates are available in the Certificates and Compliance Documents section.
▌Q: Does IBASE provide an SBOM, and what happens if a supplier cannot provide one?
A: IBASE has established software bills of materials for its products and evaluates the method and scope of disclosure based on customer requirements and confidentiality conditions. IBASE generally requires suppliers to provide an SBOM for third-party components. If a complete SBOM cannot be provided, the supplier must provide alternative information sufficient for component identification, vulnerability analysis, and risk assessment. IBASE then assesses whether the component may be adopted.
▌Q: How can I report a cybersecurity vulnerability or request compliance documents?
A: Email cybersecurity vulnerability reports to PSIRT@ibase.com.tw and include the information listed in this section. For compliance documents, declarations, and component-related information, contact your IBASE sales representative.