Taipei, Taiwan, September 2, 2026—Moxa Inc., a leader in industrial communications and networking, today announced its readiness to meet the first operational obligations of the European Union Cyber Resilience Act (CRA)—the mandatory vulnerability and incident reporting requirements—before they become enforceable on September 11, 2026. This regulation shifts vulnerability and incident handling from an internal practice to a legal obligation that mandates rapid detection, assessment, coordination, and regulatory response.
Under the CRA, manufacturers of products with digital elements must notify ENISA and the designated national CSIRT of an early warning within 24 hours after becoming aware of an actively exploited vulnerability or a severe security incident, followed by a full notification within 72 hours, and a final report within 14 days of a corrective measure/patch becoming available for exploited vulnerabilities, or within one month when incident notifications for severe incidents are submitted.
Moxa's readiness is based on a validated Secure Development Life Cycle (SDL). As one of the first vendors to achieve dual IEC 62443-4-1 Maturity Level 3 (ML3) certifications from both IECEE and ISCI/ISASecure, Moxa has shown that its product security processes are repeatable and consistently applied across the organization. These capabilities provide a solid foundation for meeting the CRA's post-market cybersecurity obligations.
Meeting the CRA's 24-hour reporting requirements goes beyond incident response; it requires an integrated cybersecurity governance framework. This enables manufacturers to quickly identify affected products, assess cybersecurity impacts, and coordinate engineering teams for timely regulatory decisions.
Moxa has implemented comprehensive vulnerability management to support these needs, including:
- A mature Product Security Incident Response Team (PSIRT) capable of rapidly validating, assessing, and coordinating vulnerability responses.
- Comprehensive Software Bill of Materials (SBOM) management that enables engineering teams to quickly identify affected software components, products, and firmware versions.
- End-to-end product traceability covering software composition, firmware releases, and life-cycle records.
- An SDL that provides complete engineering traceability and disciplined vulnerability remediation processes.
- Well-defined governance procedures that align engineering, product management, cybersecurity, legal, and executive decision-making for timely regulatory reporting.
To strengthen vulnerability reporting, Moxa is advancing its capabilities by integrating SBOM data with product databases. When new vulnerabilities are added to the known exploited vulnerabilities (KEV) catalog, our PSIRT can swiftly correlate data, assess impact, prioritize responses, and ensure timely CRA compliance.
“Meeting the CRA's 24-hour reporting requirement is not just a race against the clock; it also showcases an organization's cybersecurity maturity and the visible outcome of years of investment in cybersecurity governance,” said John Chang, director of R&D Management and the Product Security Center at Moxa. “Suppliers like Moxa that consistently meet this obligation have established the engineering governance, secure development practices, vulnerability management processes, and cross-functional coordination to rapidly understand affected products, assess cybersecurity risks, coordinate engineering responses, and provide accurate information to regulators.”
For machine builders, system integrators, and critical infrastructure operators, partnering with suppliers that have this capability provides confidence that their supplier is not only delivering secure products today, but is also equipped to manage emerging cyber-risks for years to come.
As the CRA reshapes cybersecurity accountability in industry, Moxa emphasizes that trust will be measured by both product security features and a manufacturer’s commitment to cybersecurity throughout the product life cycle. By implementing certified SDL practices, effective vulnerability management, PSIRT operations, SBOM governance, and transparent processes, Moxa helps customers mitigate cybersecurity risk and simplify post-market compliance under the CRA.
For more information about Moxa's commitment to CRA readiness, visit the Moxa Cyber Resilience Act (CRA) Portal.