Under the CRA, manufacturers of products with digital elements must notify ENISA and the designated national CSIRT of an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a serious security incident, followed by a full notification within 72 hours and a final report within 14 days of a corrective action or patch being available for the exploited vulnerabilities, or within one month when serious incident notifications are submitted.
Moxa's preparedness is based on a validated Secure Development Lifecycle (SDL). As one of the first vendors to achieve dual Maturity Level 3 (ML3) certification under IEC 62443-4-1 from both IECEE and ISCI/ISASecure, Moxa has demonstrated that its product security processes are repeatable and consistently applied across the organization. These capabilities provide a solid foundation for meeting the post-market cybersecurity obligations set by the CRA.
Meeting the CRA's 24-hour notification requirements goes beyond incident response; it requires an integrated cybersecurity governance framework. This enables manufacturers to quickly identify affected products, assess the cybersecurity impact, and coordinate engineering teams to make timely regulatory decisions.
Moxa has implemented comprehensive vulnerability management to address these needs, including:
A mature Product Security Incident Response Team (PSIRT) capable of rapidly validating, assessing, and coordinating vulnerability responses.
Comprehensive Software Bill of Materials (SBOM) management that enables engineering teams to quickly identify affected software components, products, and firmware versions.
End-to-end product traceability, encompassing software composition, firmware versions, and lifecycle records.
A Software Development Link (SDL) that provides complete traceability of engineering and disciplined vulnerability remediation processes.
Well-defined governance procedures align engineering, product management, cybersecurity, legal, and executive decision-making for timely regulatory reporting.
To strengthen vulnerability notification, Moxa is enhancing its capabilities by integrating SBOM data with its product databases. When new vulnerabilities are added to the Known Exploited Vulnerabilities (KEV) catalog, our PSIRT can quickly correlate the data, assess the impact, prioritize responses, and ensure timely CRA compliance.
“Meeting the CRA’s 24-hour notification requirement is not just a race against time; it also demonstrates an organization’s cybersecurity maturity and the visible result of years of investment in cybersecurity governance,” said John Chang, Director of R&D Management and the Product Security Center at Moxa. “Vendors like Moxa, who consistently meet this obligation, have established engineering governance, secure development practices, vulnerability management processes, and cross-functional coordination that enable them to quickly identify affected products, assess cybersecurity risks, coordinate engineering responses, and provide accurate information to regulators.”.
For machinery manufacturers, systems integrators, and critical infrastructure operators, partnering with suppliers that have this capability gives them confidence that their supplier not only offers secure products today, but is also prepared to manage emerging cyber risks in the coming years.
As the CRA redefines cybersecurity responsibility across the industry, Moxa emphasizes that trust will be measured not only by product security features but also by the manufacturer's commitment to cybersecurity throughout the entire product lifecycle. By implementing SDL-certified practices, effective vulnerability management, PSIRT operations, SBOM governance, and transparent processes, Moxa helps customers mitigate cybersecurity risks and simplify post-market compliance under the CRA.
To learn more about Moxa's commitment to CRA preparedness, visit Moxa's Cyber Resilience Act (CRA) Portal.
