Frequently Asked Questions
▌Q: What products and activities does the CRA cover?
A: The CRA is Regulation (EU) 2024/2847. It applies to products with digital elements, meaning hardware and software products that can connect directly or indirectly to other devices or networks. Products of this kind that are sold on the EU market, or otherwise made available in the course of a commercial activity, are in principle subject to the CRA. Whether the CRA actually applies depends on the product's intended purpose, its reasonably foreseeable use, and the exclusions specified in the regulation.
▌Q: Which IBASE products may fall within its scope?
A: The assessment depends on whether a product has direct or indirect data connectivity and whether it is made available on the EU market. Unless covered by other sector-specific legislation, many IBASE industrial computers, embedded systems, and related software products may be within scope. Applicability to a specific model must be determined based on its functional configuration, delivery form, and sales region. Contact your IBASE sales representative to discuss a specific model.
▌Q: How are products classified, and what does classification affect?
A: The CRA divides products into the default category, important products Class I, important products Class II, and critical products. Important and critical products are listed in Annexes III and IV. Classification determines the available conformity assessment route; higher-risk classes generally require greater third-party involvement.
▌Q: What are harmonised standards, and what is their current status?
CEN, CENELEC, and ETSI develop harmonised standards in response to the European Commission's standardisation request. These standards translate the CRA's essential requirements into verifiable technical specifications. CRA-related horizontal and product-specific standards remain under development and review, and their publication status should be checked against the latest EU notices.
▌Q: When do the reporting obligations begin, and what are the deadlines?
A: Starting September 11, 2026, manufacturers shall submit an early warning notification within 24 hours and a notification within 72 hours of becoming aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product. A final report on a vulnerability shall be submitted no later than 14 days after a corrective or mitigating measure is available; a final report on a severe incident shall be submitted within one month after the incident notification.
▌Q: Does the CRA apply to products already on the market?
A: Starting September 11, 2026, the reporting and user notification obligations under CRA Article 14 apply, including to products that were placed on the EU market before that date.
Other CRA requirements depend on the date each individual unit is first placed on the EU market, not on when the model was launched:
Units placed on the market before December 11, 2027: In principle, only the Article 14 obligations above apply. However, if such units undergo a substantial modification on or after December 11, 2027, they must comply with the other applicable CRA requirements.
Units first placed on the market on or after December 11, 2027: They must comply with all applicable CRA requirements, including product security, vulnerability handling, and conformity assessment. This applies even if the model has long been on the market.
▌Q: What may constitute a substantial modification?
A: A modification may be substantial when it changes a product's intended purpose or may affect its compliance with the essential cybersecurity requirements. Such a product may be treated as newly placed on the market. The nature and impact of the modification must be assessed case by case.
▌Q: What are the consequences of non-compliance with the CRA?
A: Authorities may require corrective action and may impose market measures such as withdrawal or sales restrictions. For infringements of essential cybersecurity requirements or key manufacturer obligations, administrative fines may reach EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Lower maximum fines apply to certain failures to provide information or cooperate with authorities.
▌Q: How do the CRA, NIS2, EN 18031, and IEC 62443 differ?
A: The CRA regulates the products themselves. NIS2 governs organizational management for operators of critical infrastructure and essential services. EN 18031 sets out requirements for equipment with wireless functions. IEC 62443 is a family of technical standards that can serve as a basis for establishing processes and product capabilities. The scope of each regulation and standard differs. In particular, the RED cybersecurity delegated regulation (EU) 2022/30 will be repealed as of December 11, 2027. From then on, the cybersecurity obligations of the relevant products shall be determined under the CRA, while the other applicable RED requirements must still be met.
▌Q: What is IBASE's role under the CRA?
A: Many IBASE products are components or motherboards intended for integration. The party that places the final product on the EU market under its own name or trademark is generally the manufacturer under the regulation and assumes the corresponding obligations. Roles depend on the actual transaction and market placement model. IBASE can assist customers in discussing their product architecture.
▌Q: What cybersecurity foundations and certifications does IBASE currently have?
A: IBASE is certified to ISO 27001 for its information security management system. It has also established a secure product development lifecycle in accordance with IEC 62443-4-1 and obtained certification. Implementation of relevant IEC 62443-4-2 requirements is being planned. Certificates are available in the Certificates and Compliance Documents section.
▌Q: Does IBASE provide an SBOM, and what happens if a supplier cannot provide one?
A: IBASE has established software bills of materials for its products and evaluates the method and scope of disclosure based on customer requirements and confidentiality conditions. IBASE generally requires suppliers to provide an SBOM for third-party components. If a complete SBOM cannot be provided, the supplier must provide alternative information sufficient for component identification, vulnerability analysis, and risk assessment. IBASE then assesses whether the component may be adopted.
▌Q: How can I report a cybersecurity vulnerability or request compliance documents?
A: Email cybersecurity vulnerability reports to PSIRT@ibase.com.tw and include the information listed in this section. For compliance documents, declarations, and component-related information, contact your IBASE sales representative.