EU CRA 網路韌性法

EU CRA 網路韌性法合規輔導

台灣出口商進入歐盟市場的網路安全合規路徑

EU CRA(Cyber Resilience Act)自 2024 年 12 月起正式施行,要求所有含數位元素產品在進入歐盟市場前取得 CE 標誌的網路安全合規。積穗科研協助台灣出口商完成產品分類、Annex I 安全要求實作、SBOM 建立、漏洞揭露流程與 72 小時 ENISA 通報機制。

申請免費機制診斷
⚠️ 距 2026/09/11 漏洞通報義務生效不到 4 個月

積穗 Quick Win 方案 — 90 天從零到 PSIRT 演練完成

IEC 62443-4-1/4-2 最快要到年底才能拿到驗證,9 月上線來不及?CRA 漏洞通報 SOP 可獨立先行,不必等驗證完成。 積穗獨家整合資安技術工具 + CRA 制度導入 + ISO 驗證 + 法遵全方位方案。

台灣企業 6 大痛點與積穗解方

1

痛點: 不知道自己是否在 CRA 適用範圍

✓

積穗解方: D+15 現況盤點 + CRA 適用性 Gap 分析

2

痛點: IEC 62443-4-1/4-2 驗證年底才能拿,9月來不及

✓

積穗解方: 漏洞通報 SOP 可獨立先行,並行 IEC 62443

3

痛點: 通報窗口不熟 (ENISA SRA + Member State CSIRT)

✓

積穗解方: ENISA 註冊代辦 + 雙窗口通報範本

4

痛點: 24h / 72h / 14d 三階段分不清楚

✓

積穗解方: 分階段通報範本 + decision tree

5

痛點: 漏洞處理小組 (PSIRT) 無人無流程無工具

✓

積穗解方: 60 天建組 + 90 天演練 + 工具部署

6

痛點: 違規罰款 1500 萬歐元 / 2.5% 年營業額,內部還在打太極

✓

積穗解方: 簽約 90 天到 PSIRT 演練,投資 vs 風險比清楚

Quick Win 時程 — 簽約即啟動

D+15

現況盤點 + CRA 適用性 Gap 分析

D+30

從設計開始銜接的安全漏洞管理流程範本

D+60

漏洞通報程序建構 + PSIRT 小組成立

D+90

漏洞工具部署 + PSIRT 桌上演練 (覆蓋 9 月通報義務)

D+180

ISO 30111 + IEC 62443-4-1 認證準備

D+365

IEC 62443-4-2 完整合規 + CRA 持續監控

⚖️ 必知 CRA 法規數字

罰款上限: 1,500 萬歐元 或 全球年營業額 2.5%

違規通報罰款: 1,000 萬歐元 或 年營業額 2%

CRA Art.14(1): 24h 內 ENISA 早期警示

CRA Art.14(2): 72h 內完整事件通報

CRA Art.14(3): 14 天內最終事件報告

CRA Art.11: Coordinated Vulnerability Disclosure

🏆 積穗獨家

唯一兼具資安技術工具、CRA 合規制度導入、ISO 驗證、法遵整合的全方位風險管理方案

申請 Quick Win 免費機制診斷 →

什麼是 EU CRA?哪些台灣產品受到影響?

EU CRA(歐盟網路韌性法)是歐盟針對所有含數位元素產品(PDE)設定強制性網路安全要求的法規。CRA 的適用觸發條件是「網路連接性」,而非「硬體界接」——凡是能夠直接或間接連接至網路或另一裝置的產品,均受規範。台灣受影響的產品類型包含:IoT 設備、工業控制系統(PLC、SCADA)、網路設備、智慧家電、行動 App、桌面應用程式、瀏覽器擴充套件、嵌入式系統。CRA 將產品分為三類:一般 PDE(自我評估)、重要 PDE Class I(第三方審查)、重要 PDE Class II(強制第三方認證)。

⚠️ 軟體業常見誤解:「OS 層以上純軟體不受 CRA 規範」

這是錯誤的。歐盟官方 FAQ 明確將行動 App 與電腦遊戲列為預設級 PDE 的適用示例,兩者均為純 OS 層以上軟體,與韌體無關。

豁免條件只有一種:純 SaaS(軟體邏輯完全在雲端,裝置端無任何可下載元件)依 CRA Article 2(5)(h) 豁免。但若 SaaS 附帶行動 App、桌面客戶端或瀏覽器擴充套件,該裝置端元件仍適用 CRA。

✅ 適用 CRA行動 App(iOS/Android)
✅ 適用 CRA桌面應用程式(.exe/.dmg)
✅ 適用 CRA瀏覽器擴充套件
❌ 豁免純網頁版 SaaS(無裝置端元件)
✅ 適用 CRASaaS + 附帶 App
❌ 豁免完全離線單機軟體

積穗科研輔導成功案例

案例 01
IoT Equipment Exporter

Completed CRA product classification assessment, confirmed as Class I critical PDE, established SBOM, vulnerability disclosure process, and 72-hour ENISA notification mechanism, achieving CE mark cybersecurity compliance.

案例 02
Industrial Automation Equipment Manufacturer

Completed Annex I safety requirements gap analysis, integrated IEC 62443 industrial cybersecurity standard, established a product security update mechanism (minimum 5 years support), and met CRA Class II mandatory third-party certification requirements.

案例 03
Enterprise Security SaaS Vendor (with desktop client)

Initially assumed pure SaaS exemption. Winners Consulting diagnosis confirmed: the Windows/macOS desktop client bundled with the SaaS is a device-side component, subject to CRA default category. Completed SBOM for desktop client, designed security update mechanism, obtained Declaration of Conformity (DoC), and successfully entered European enterprise procurement lists.

案例 04
Mobile App Developer (connecting to enterprise IoT devices)

Confirmed mobile app as CRA Class I (has network connectivity, controls IoT devices). Completed Annex I security requirements gap analysis, SBOM establishment, and vulnerability disclosure policy. Passed EU distributor CRA compliance review and launched on European market on schedule.

積穗科研輔導流程

01

CRA Product Classification and Applicability Assessment

According to CRA Annex III/IV regulations, assess whether Taiwan's export products fall under regulated products with digital elements, determine the product category (General PDE / Class I / Class II), and confirm the applicable compliance path.

02

Annex I Security Requirements Gap Analysis

Conduct a gap analysis against CRA Annex I essential cybersecurity requirements (no known exploitable vulnerabilities, secure by design configurations, access control, encryption, data minimization, integrity protection, resilience, security update mechanisms).

03

SBOM Establishment and Vulnerability Management

Establish an SBOM (Software Bill of Materials) compliant with CRA requirements, set up vulnerability monitoring and disclosure processes, design a 72-hour ENISA notification mechanism, and establish a product security update mechanism.

04

Conformity Assessment and CE Marking

Select the appropriate conformity assessment path based on product category, prepare Technical Documentation, and obtain the Declaration of Conformity (DoC) or third-party certification required for CE marking.

常見問題

When will the EU CRA become mandatory? How much preparation time do Taiwanese exporters have?

The EU CRA will officially come into force in December 2024, but there is a phased transition period: obligations for notified bodies (after 21 months, September 2026), vulnerability reporting obligations (after 21 months), and full enforcement (after 36 months, December 2027). Taiwanese exporters should immediately start assessing product applicability to avoid being banned from entering the EU market after December 2027.

What is SBOM? Why does CRA require its establishment?

SBOM (Software Bill of Materials) is a list of all components that make up a software (open-source libraries, third-party components, self-developed code). CRA requires SBOM because many software vulnerabilities originate from open-source components (such as Log4j), and SBOM allows manufacturers to quickly identify affected products and patch them in a timely manner.

What are CRA Class I and Class II? How are they determined?

Class I critical PDE listed in CRA Annex III include: identity management software, browsers, password managers, VPNs, network monitoring tools, operating systems, routers, firewalls, industrial IoT devices, etc. Class II includes: HSM (Hardware Security Module), smart cards, industrial automation control systems, etc. Products not listed in Annex III are considered general PDE and can be self-assessed.

What are the compliance pathways for Taiwanese exporters under CRA?

Taiwanese exporters have three pathways: 1. EU Authorized Representative (designate a representative within the EU to be responsible for CRA compliance obligations); 2. Conformity with European harmonized standards (adopt harmonized standards such as ETSI EN 18031, presumed to comply with CRA requirements); 3. Third-party certification (mandatory for Class II, conducted by an EU-approved notified body).

What are the consequences of CRA non-compliance?

The maximum penalty for CRA non-compliance is 2.5% of global annual turnover or 15 million Euros (whichever is higher). A more severe consequence is the prohibition of products from being sold in the EU market, which for Taiwanese exporters relying on the European market, the loss far exceeds the fine amount.

What is the relationship between CRA and IEC 62443?

For manufacturers of industrial automation control systems, IEC 62443 is the most direct standard corresponding to the security requirements of CRA Annex I. Obtaining IEC 62443 certification can serve as an important basis for CRA conformity, significantly simplifying the CRA compliance process. Jishui Research provides integrated guidance for CRA plus IEC 62443.

What are the characteristics of Winners Consulting's CRA advisory services?

Winners Consulting is one of the few firms in Taiwan with integrated advisory capabilities for EU CRA, EU AI Act, and IEC 62443. We assist Taiwanese exporters in entering the European market via the most effective path, integrating four EU regulations (CRA + EU AI Act + IEC 62443 + ISO 26262).

Are pure software products subject to CRA? Are applications above the OS layer exempt?

No. Software above the OS layer is subject to CRA as long as it has network connectivity. CRA's triggering condition is 'network connectivity,' not 'hardware interface.' The EU's official FAQ explicitly lists mobile apps and computer games as default-category PDE examples—both are pure OS-layer-above software with no relation to firmware. Desktop applications (with network connectivity), mobile apps, and browser extensions all fall under CRA. The only exemption is pure SaaS (all software logic in the cloud, no downloadable device-side components).

My product is a SaaS but includes a mobile app. Does it need to comply with CRA?

Yes. Pure SaaS is exempt under CRA Article 2(5)(h), but the exemption condition is 'no downloadable device-side components.' If the SaaS includes a downloadable mobile app, desktop client (.exe/.dmg), or browser extension, that device-side component triggers CRA default category or Class I/II requirements. The SaaS core (cloud portion) remains exempt, but the device-side component must comply. Winners Consulting helps clarify which components require compliance and plans the minimum-scope compliance pathway.

Learn More About EU Compliance

Certification services × risk glossary × latest insights

申請免費機制診斷

積穗科研提供第一次免費診斷評估,依您企業現況規劃最適合的輔導路徑

立即申請免費機制診斷

Related Deep Insights

In-depth analysis by Winners consultants, 6,000+ words per article

auto

The Autonomous Driving Trust Case: A Complete Safety Argument Framework Beyond ISO/SAE 21434 Compliance

A 2023 Norwegian study found trust and safety are statistically unrelated, revealing that an ISO/SAE 21434 cybersecurity case alone cannot build public trust in autonomous driving. The research proposes a supplementary 'Trust Case' framework to present AI transparency and organizational accountability in layperson's terms. Taiwanese suppliers must build a complete, customer-facing safety argument beyond TISAX certification and UNECE WP.29 compliance to address this critical gap.

bcm

Integrating Dual Properties of TCP Ceramics: Resilience Insights for BCM Frameworks

Winners Consulting Services Co., Ltd. notes that a 2008 orthopedic study on tricalcium phosphate revealed a core principle directly applicable to ISO 22301 BCM frameworks: 'resorbability and osteoinductivity can be co-designed.' This implies BCP effectiveness stems from process interface design quality, not hardware investment scale. The framework must be dynamically updatable, allowing RTO/RPO targets to be continuously adjusted based on BIA data, rather than remaining static.

bcm

Implications of Brownian Network Dimensionality Reduction for BCM and ISO 22301 Practices in Taiwan

Winners Consulting Services Co., Ltd. highlights a 2005 stochastic control study by Harrison & Williams, which reveals that high-dimensional complex systems can achieve optimal control at a lower cost through equivalent dimensionality reduction. This principle offers direct insights for Taiwanese companies implementing ISO 22301 BCM: BCP design should aim for equivalent simplification, RTO/RPO targets must be achievable, and long-term resilience investments should be strategically evaluated. This approach helps create more effective and sustainable business continuity management systems.

auto

Team Structure Insights from ISO/SAE 21434 Development: The Organizational Key to Automotive Cybersecurity Compliance in Taiwan

Using the ISO/SAE 21434 development process as a case study, Zhang Hengwei's research reveals that team structure is the most critical IPO factor affecting international standard quality. For Taiwan's automotive suppliers, this means the success of TISAX certification and ISO/SAE 21434 implementation hinges on establishing a cross-functional cybersecurity governance team.

auto

Optimizing Early-Stage Automotive Cybersecurity Process Design: A Practical Analysis of ISO/SAE 21434 and TISAX Compliance

Research by Christine Jakobs (2023) reveals systemic gaps in the early design phase of the automotive cybersecurity V-Model, leading to an incomplete ISO/SAE 21434 compliance evidence chain. The study proposes a function-oriented risk analysis method to identify threats before system architecture is finalized. This approach is crucial for Taiwanese suppliers preparing for TISAX certification and complying with UNECE WP.29 UN-R155 regulations, offering a practical framework to strengthen early-stage security practices and ensure robust compliance.

bcm

BCP Design for a Changing Threat Landscape: Lessons from an Italian Hepatitis B Study for BCM

A 2015 Italian prospective study of 103 acute hepatitis B patients reveals that when the infectious genotype structure changes (non-D genotypes at 51%), a static BCP framework systematically underestimates emerging threats. For companies' ISO 22301 BCM practices, this means Business Impact Analysis (BIA) must cover diverse threat scenarios, RTO/RPO targets cannot rely solely on historical averages, and the effectiveness of control measures requires regular review.

auto

Proposing HEAVENS 2.0: An Automotive Risk Assessment Model – Winners Consulting Services Insights

Winners Consulting Services Co., Ltd. highlights HEAVENS 2.0 as the vehicle risk assessment model that most closely aligns with ISO/SAE 21434 requirements. The research team systematically identified 17 model updates—12 to address compliance gaps and 5 to remediate weaknesses—fully aligning the original HEAVENS framework with mandatory UN R155 regulations. This provides a clear gap analysis checklist for Taiwanese automotive suppliers navigating TISAX certification and ISO/SAE 21434 implementation.

bcm

Methodological Insights from Boolean Optimization Pruning for BCM Framework Design in Taiwanese Enterprises

A 2004 paper on Boolean optimization (Manquinho & Marques-Silva, 21 citations) reveals that systematic pruning strategies can significantly compress the decision search space. This logic is fundamentally identical to the BIA prioritization mechanism in ISO 22301 Business Continuity Management. When establishing a Business Continuity Plan (BCP), Taiwanese enterprises should focus resources on the core 20% of processes with the strictest RTO/RPO requirements, rather than diluting efforts across all operations.