Our Approach to the CRA

AEWIN treats cyber resilience as a core strategic direction for industrial computing, embedding security into product architecture from the ground up. AEWIN maintains a rigorous security process across design, development, testing, and lifecycle maintenance. With the EU Cyber Resilience Act (CRA) ushering in mandatory cybersecurity compliance for digital products, AEWIN has proactively begun related technical and process preparations to help customers align with international standards efficiently and reduce compliance costs.

The CRA (EU 2024/2847) establishes cybersecurity requirements for all products with digital elements sold into the EU. AEWIN's early preparation ensures its industrial computing equipment delivers superior built-in defense capability and market competitiveness.

The main objectives of the EU Cyber Resilience Act include:

• Strengthening full lifecycle security of digital products: Ensuring all products with digital elements have comprehensive cybersecurity protection and vulnerability remediation mechanisms from design through production to after-sales maintenance.

• Enhancing supply chain and digital market resilience: Establishing unified European cybersecurity standards to reduce the risk of systemic cascading cyberattacks triggered by a single hardware or software vulnerability.

• Protecting users' right to information and transparency: Providing clear security guidance and transparent vulnerability reporting mechanisms to help businesses and consumers make informed and safe decisions when purchasing and using digital products.

Security Advisories & Vulnerability Procedures

AEWIN has established a Product Security Incident Response Team (PSIRT), taking a proactive approach through established processes to help reduce product security risks and helping customers obtain relevant security information and support resources to address cybersecurity challenges.

We evaluate, investigate, and handle reports that may affect the security of AEWIN products according to our established vulnerability management procedures. We have therefore developed a Security Vulnerability Management Policy and established a Security Advisories section to provide customers with guidance and information when security vulnerabilities are discovered. This policy ensures that all customers have ongoing access to clear resources for understanding how AEWIN resolves or mitigates security vulnerabilities reported by customers.

 PSIRT

If you discover a potential security vulnerability in a AEWIN product

please submit a detailed report to help expedite our risk assessment and enable us to provide a fix or mitigation as quickly as possible.

The report should include the following information:

  • Product name and model
  • Steps to reproduce the issue (please include images or code where possible)
  • Packet capture of the attack process
  • Software/firmware version
  • Proof of concept or exploit code
  • Any other supplementary information you believe would aid the analysis
  • Equipment and software required to reproduce the issue
  • Description of potential attack impact
 

 PSIRT@aewin.com

CRA Frequently Asked Questions (FAQ)

What is the EU Cyber Resilience Act (CRA)?

Which products are actually covered by the CRA?

What are the main obligations manufacturers must fulfill?

What are CRA harmonized standards?

When does the CRA take effect, and what are the deadlines?

What penalties apply for non-compliance with the CRA?

How does the CRA differ from the NIS2 Directive?

What is a Software Bill of Materials (SBOM)?

Inquiry Cart

total 0 items

Compare

total 0 items

Email Subscribe

Verification

Click the numbers from smallest to largest.

We use cookies to allow our website to work properly, personalize content and advertising, provide social media features and analyze traffic. We also share information about your use of our site with our social media, advertising and analytics partners

Manage Cookies

Privacy Settings

We use cookies to allow our website to work properly, personalize content and advertising, provide social media features and analyze traffic. We also share information about your use of our site with our social media, advertising and analytics partners

Privacy Policy

Manage Consent Settings

Essential Cookies

Accept All

The website cannot function without these cookies and you cannot switch them off on your system.

These cookies are typically set only in response to an action you perform (i.e. a service request), such as setting privacy preferences, logging in, or filling in a form.

You can set your browser to block or prompt you for these cookies, but this may prevent some site features from working.