Biostar

  • CRA Scope

  • CRA Compliance

  • CRA Requirements

  • Vulnerability Reporting

  • Cyber Resilience Act (CRA)

    Starting September 11, 2026, manufacturers will be obligated to report actively exploited vulnerabilities and severe security incidents. By December 11, 2027, all connected products entering the EU market must fully comply with the Cyber Resilience Act (CRA). Designed to protect consumers and businesses against escalating cybersecurity threats in an interconnected world, the CRA establishes stringent standards for the design, development, and production of "Products with Digital Elements" (PDE), alongside mandatory processes for vulnerability management throughout the product lifecycle.

    As a global leader in motherboards and industrial PC solutions, BIOSTAR is actively tracking CRA regulatory updates and driving internal process transformations. We are committed to helping our customers and partners seamlessly navigate EU compliance requirements, ensuring secure and compliant products enter the European market with confidence.

    CRA Scope

    Compliance with the CRA is mandatory for any business operating in the European Union, serving as an essential prerequisite for legal EU market access. BIOSTAR is committed to enhancing product security and resilience within the digital ecosystem, proactively auditing and bringing our regulated product lines under strict compliance management.

    In-Scope Products

    Products and Components with Digital Elements (PDE):

    Hardware:
    • Hardware Devices: Hardware products equipped with networking and computing capabilities (e.g., motherboards, industrial PCs).
    • Software & Firmware: System BIOS, drivers, and various application software.
    • Integrated Components: Integrated hardware-software modules.
    • Networking & Connected Devices
    • Connected Equipment: End products equipped with remote data transmission or processing capabilities.
    Out of Scope

    Products Regulated by Existing EU Sector-Specific Legislation:

    Excluded Equipment:
    • Medical Devices & In Vitro Diagnostic Medical Devices
    • Automotive & In-Vehicle Systems
    • Certain Civil Aviation Products & Marine Equipment
    • Products Exclusively Designed for National Security, Defense, or Classified Information
    • Certain Like-for-Like Spare Parts

    CRA Compliance

    The CRA represents a significant challenge for manufacturers. It mandates that businesses assume responsibility for extended product lifecycle maintenance, allocate greater resources to R&D and security testing, and establish incident response mechanisms capable of issuing an early warning within 24 hours and a detailed notification within 72 hours of becoming aware of actively exploited vulnerabilities or severe security incidents.

    In the face of increasingly complex cyber threats and stringent global regulatory environments, BIOSTAR remains committed to investing dedicated resources to ensure cybersecurity is not merely a compliance checkbox, but a core value that safeguards our global customers' computing platforms and solutions.

    CRA Requirements

    In line with the EU CRA cybersecurity requirements for Products with Digital Elements (PDE), we integrate security measures across the entire product lifecycle management:

    Security by Design
    • Cybersecurity risk assessments are fully integrated across hardware circuitry, BIOS, firmware, and software development phases, establishing tailored protection mechanisms based on specific product application scenarios.
    Security by Default
    • Products are shipped with high-level secure default configurations, enforcing the principle of least privilege access control to mitigate risks of unauthorized access and zero-day attacks.
    Vulnerability Management & Security Updates
    • A dedicated process for vulnerability identification, assessment, and patch tracking has been established, with a commitment to providing continuous security updates throughout each product's support period (at least 5 years from market placement, with end-of-support dates for specific product lines announced separately).
    Product Lifecycle Security
    • Product cybersecurity risks are monitored continuously from design, manufacturing, and launch to End of Life (EOL), ensuring system resilience throughout its operational lifespan.
    Supply Chain Security
    • Rigorous cybersecurity assessments are conducted for third-party hardware chips, open-source software, and firmware components used in our products, mitigating potential vulnerabilities at the supply chain level.
    Incident Response & Vulnerability Reporting
    • A transparent and agile Incident Response mechanism is established to ensure that upon becoming aware of actively exploited vulnerabilities or severe incidents, notifications are submitted via the ENISA single reporting platform within statutory deadlines under Article 14 of the CRA, and affected users are notified. Other vulnerabilities are handled in accordance with our Coordinated Vulnerability Disclosure (CVD) policy.

    Vulnerability Reporting

    If you discover a security vulnerability in a BIOSTAR product, please report it via the dedicated channels below. We process all reports in accordance with our Coordinated Vulnerability Disclosure (CVD) policy and extend safe harbor protection to good-faith security research.

    Product Security Incident Response Team (PSIRT)

    Twitter

    BACK

    TOP