The EU Cyber Resilience Act (CRA), a mandatory cybersecurity regulation for hardware and software products with digital elements sold on the EU market
Industrial PC
Motherboards
Memorys
Cyber Resilience Act (CRA)
Starting September 11, 2026, manufacturers will be obligated to report actively exploited vulnerabilities and severe security incidents. By December 11, 2027, all connected products entering the EU market must fully comply with the Cyber Resilience Act (CRA). Designed to protect consumers and businesses against escalating cybersecurity threats in an interconnected world, the CRA establishes stringent standards for the design, development, and production of "Products with Digital Elements" (PDE), alongside mandatory processes for vulnerability management throughout the product lifecycle.
As a global leader in motherboards and industrial PC solutions, BIOSTAR is actively tracking CRA regulatory updates and driving internal process transformations. We are committed to helping our customers and partners seamlessly navigate EU compliance requirements, ensuring secure and compliant products enter the European market with confidence.
CRA Scope
Compliance with the CRA is mandatory for any business operating in the European Union, serving as an essential prerequisite for legal EU market access. BIOSTAR is committed to enhancing product security and resilience within the digital ecosystem, proactively auditing and bringing our regulated product lines under strict compliance management.
Products and Components with Digital Elements (PDE):
Products Regulated by Existing EU Sector-Specific Legislation:
CRA Compliance
The CRA represents a significant challenge for manufacturers. It mandates that businesses assume responsibility for extended product lifecycle maintenance, allocate greater resources to R&D and security testing, and establish incident response mechanisms capable of issuing an early warning within 24 hours and a detailed notification within 72 hours of becoming aware of actively exploited vulnerabilities or severe security incidents.
In the face of increasingly complex cyber threats and stringent global regulatory environments, BIOSTAR remains committed to investing dedicated resources to ensure cybersecurity is not merely a compliance checkbox, but a core value that safeguards our global customers' computing platforms and solutions.
CRA Requirements
In line with the EU CRA cybersecurity requirements for Products with Digital Elements (PDE), we integrate security measures across the entire product lifecycle management:
Vulnerability Reporting
If you discover a security vulnerability in a BIOSTAR product, please report it via the dedicated channels below. We process all reports in accordance with our Coordinated Vulnerability Disclosure (CVD) policy and extend safe harbor protection to good-faith security research.



Select Languages
BACK
TOP