ISO/IEC 29147 漏洞揭露

當研究員找到你產品的漏洞,他知道該寄給誰、你知道該怎麼回嗎?CRA 現在要求這必須是制度,不是運氣。

Book a Free Risk Diagnosis

ISO/IEC 29147:2018 規範廠商如何接收外部漏洞通報、如何對外發布修補與公告資訊——也就是協調式漏洞揭露(CVD)的「對外介面」標準(新版修訂已在 ISO 工作組進行中)。它的法遵重量來自 EU CRA:CRA 附件一第二部分要求含數位元素產品的製造商建立並執行協調式漏洞揭露政策,且漏洞通報義務自 2026-09-11 起適用——主動遭利用漏洞須在時限內通報指定 CSIRT 與 ENISA。歐盟 JRC 與 ENISA 的官方標準對映報告中,EN ISO/IEC 29147 正是漏洞處理類要求的核心對應標準之一(八項要求中對應四項),與 ISO/IEC 30111 成對構成 CRA 漏洞義務的標準答案。

29147 與 30111 的分工

29147 管「揭露」:通報受理管道、與通報者的溝通、公告(advisory)的內容與發布;30111 管「處理」:收到通報後的內部驗證、分級、修補開發與部署流程。CRA 的漏洞義務同時涉及兩端,兩標準應成對導入。

CRA 時程與義務內容

CRA 已於 2024-12-10 生效:漏洞與事件通報義務 2026-09-11 起適用、主要義務 2027-12-11 起全面適用。製造商須建立 CVD 政策、提供通報聯絡點、無不當延遲地修補並發布安全更新、隨 SBOM 文件化漏洞——這些正是 29147/30111 的條文內容。

導入的實務樣貌

典型交付:security.txt 與通報信箱/表單、通報受理與回覆 SLA、CVD 政策文件(含安全港聲明)、公告模板與發布流程、與 30111 內部處理流程的銜接、必要時的 CVE 編號申請程序。積穗科研自身即營運完整的漏洞監測與合規證據鏈,輔導內容來自實際落地經驗。

Who This Is For

  • 出口歐盟的含數位元素產品(PDE)製造商
  • 韌體、IoT、網通與嵌入式系統業者
  • 被客戶要求提供 CVD 政策與 PSIRT 聯絡點的供應商
  • 需要回應 CRA 第三方符合性評估的廠商

Related Deep Insights

In-depth analysis by Winners consultants, 6,000+ words per article

eu-comp

EU CRA and IEC 62443 Integration: A Compliance Guide for Taiwan Companies The EU Cyber Resilience Act (CRA) is set to be a transformative regulation, imposing strict cybersecurity requirements on digital products and services placed on the European market. For companies in Taiwan, many of which are part of the global electronics and industrial automation supply chain, compliance is no longer optional—it is a prerequisite for market access. The challenge lies in the fact that the EU CRA is a broad legislative framework, whereas IEC 62443 is a technical standard-set specifically designed for Industrial Automation and Control Systems (IACS). Integrating these two requires a strategic approach that bridges the gap between legal requirements and technical implementation. ### Understanding the EU CRA Landscape The EU CRA aims to ensure that all digital products—including software and hardware with digital elements—meet a baseline level of cybersecurity. This includes requirements for: - Risk-based security measures throughout the product lifecycle. - Vulnerability handling and incident reporting obligations. - Mandatory software-bill-of-materials (SBOM)-like transparency. - Restrictions on products with "high risk" profiles (e.g., critical infrastructure components). For companies operating in the industrial sector, these requirements often overlap with existing standards like IEC 62443, but the CRA adds a layer of legal accountability and market-wide uniformity that did not exist previously. ### The Role of IEC 62443 in CRA Compliance IEC 62443 is the most relevant technical standard for companies preparing for the EU CRA. It provides a structured approach to securing industrial systems through: - **Security Levels (SL):** Defined levels of resistance against different classes of threats. - **Lifecycle-based requirements:** Ensuring security is integrated from design through decommissioning. - **Component-level-to-system-level-assurance:** Addressing both individual products and the systems they inhabit. The EU CRA's risk-based approach aligns closely with the IEC 62443 concept of "security-by-design." However, the CRA's definition of "digital products" is broader than the traditional IACS scope of IEC 62443, meaning companies must be careful to identify which of their products fall under the regulation's jurisdiction. ### Strategic Integration: A Roadmap for Taiwan Companies To successfully navigate this dual requirement, we recommend a phased approach: 1. **Inventory and Classification:** Identify all digital products and components within your portfolio. Determine which products are subject to the EU CRA based on their intended use and risk profile. 2. **Gap Analysis:** Map your current IEC 62443 implementation against the specific requirements of the EU CRA. Pay close attention to the CRA's unique mandates, such as the obligation to report actively exploited vulnerabilities to ENISA within 24 hours. 3. **SBOM-Ready Documentation:** The EU CRA will require transparency regarding software components. Companies should be closely monitoring the development of the EU AI Act and the Cyber Resilience Act's specific technical standards, which will likely be published by CEN/CENELEC. 4. **Lifecycle Management:** Ensure that your product development lifecycle (SDLC) includes documented processes for vulnerability management, patch distribution, and end-of-life security measures as required by the CRA. ### Challenges and Considerations - **The "High Risk" Category:** Products used in critical infrastructure (e.g., energy, water, transport) will face stricter certification requirements under the CRA. Companies must be closely monitoring the EU's definition of these categories. - **Supply Chain Transparency:** The CRA places the burden of compliance on the "manufacturer" or importer. This means even if you are a component supplier, you must provide sufficient documentation to your EU-based customers to enable their compliance. - **Global vs. Regional Standards:** While IEC 62443 is a global standard, the EU CRA is a regional regulation. Companies must ensure their technical measures satisfy both the global industry expectation and the specific legal requirements of the EU market. ### About Our Company Winners Consulting Services Co., Ltd. (Winners) assists companies in navigating the complexities of international cybersecurity regulations. We specialize in aligning industrial practices with standards like IEC 62443 and emerging regulations like the EU CRA. Our team provides the technical expertise and strategic guidance necessary to ensure your digital products meet both regulatory and customer expectations, securing your position in the global marketplace. For a detailed assessment of your company's compliance status, please contact us to schedule a consultation.

Winners Consulting Services Co., Ltd. (Winners) has identified that if Taiwanese companies fail to complete simultaneous EU CRA and IEC 62443 certification by 2026, they face a risk of up to 30% order loss. We provide a four-step solution to help companies achieve compliance within 7 to 12 months.

eu-comp

EU CRA Compliance and IEC 62443 Gaps: Key Strategies for Taiwan Companies The EU Cyber Resilience Act (CRA) is set to be a transformative regulation, imposing strict cybersecurity requirements on digital products and services placed on the European market. For Taiwan companies, many of whom are integral parts of global electronics and industrial supply chains, the compliance burden is significant. A critical question for our clients is: How do the requirements of the EU CRA differ from the existing IEC 62443 standard, and how can we bridge these gaps? ### Understanding the Regulatory Landscape The EU CRA is a legally binding regulation, not just a technical standard. It mandates "security-by-design" principles, requiring manufacturers to be able to identify, be accountable for, and remediate digital vulnerabilities throughout the entire lifecycle of a product. IEC 62443, on the other hand, is a collection of standards and technical reports focused on the security of Industrial Automation and Control Systems (IACS). While IEC 62443 provides the technical "how-to," the EU CRA provides the legal "must-do." ### Key Differences and Challenges 1. **Scope and Application:** IEC 62443 is primarily focused on industrial environments (OT). The EU CRA has a much broader scope, covering any digital product with digital elements, including consumer electronics and IoT devices. 2. **Legal Liability:** The EU CRA introduces significant penalties for non-compliance, including fines of up to €15 million or 2.5% of global annual turnover. IEC 62443 is a voluntary standard; compliance is a market-driven decision rather than a legal obligation. 3. **Lifecycle Management:** The EU CRA explicitly requires ongoing vulnerability management, incident reporting to ENISA (European Union Agency for Cybersecurity), and a clear path for security updates. While IEC 62443 touches on lifecycle management, the CRA's requirements are more prescriptive and legally enforceable. 4. **Documentation and Transparency:** The EU CRA will require manufacturers to provide technical documentation, a declaration of conformity, and information for users on how to use the product securely. This level of transparency is more stringent than what is typically required under IEC 62443. ### Strategic Measures for Taiwan Companies To navigate these challenges, we recommend a three-pronged approach: **1. Conduct a Comprehensive Gap Analysis** The first step is to map your current security practices against the specific requirements of the EU CRA. This means evaluating your existing IEC 62443 implementation—or any other frameworks you currently follow—against the new regulations. We can assist in identifying which products fall under the CRA's scope and where your current controls fall short. **2. Integrate Security into the Product Development Lifecycle** The EU CRA's "security-by-design" requirement means that cybersecurity cannot be an afterthought. It must be integrated from the initial design phase through to decommissioning. This requires changes in processes, documentation, and team structures. We help companies implement these processes, ensuring that security considerations are documented and verifiable at every stage. **3. Establish Robust Vulnerability and Incident Management Processes** The EU CRA will be closely closely monitored by national authorities. Companies must be able to detect, report, and remediate vulnerabilities within strict timelines. This means establishing a dedicated team or process for vulnerability monitoring, patch management, and incident response. ### About the Company Winners Consulting Services Co., Ltd. (Winners) is a leading cybersecurity consultancy based in Taiwan, specializing in helping industrial and technology companies navigate complex regulatory landscapes. With deep expertise in both IEC 62443 and emerging regulations like the EU CRA, we provide the strategic guidance necessary to ensure our clients remain competitive in the global market. For more information on how to prepare your company for the EU CRA, please contact us at [insert contact information].

Winners Consulting Services Co., Ltd. (Winners) has identified that if Taiwanese companies fail to integrate EU CRA and IEC 62443 standards by September 2026, they face a risk of up to 30% order loss. Based on our latest research, this article outlines common pitfalls and provides a three-step solution.

FAQ

QCRA 一定要求做到 29147 嗎?

CRA 要求的是「結果」(CVD 政策、通報、修補、公告),29147 是歐盟官方對映報告認定最直接的對應標準——依標準建立制度,就是向公告機構與客戶證明合規最有效率的方式。

Q我們是小廠,需要 PSIRT 嗎?

不需要大編制,但需要明確的接收管道、責任人與回覆流程。29147 的最低規範要求本就考量規模彈性,制度可以精實但不能缺席。

Q通報義務的時限多嚴?

CRA 對主動遭利用漏洞與重大事件採分段時限通報(以小時計的早期通知加後續報告),對象為指定的國家 CSIRT 與 ENISA。沒有事前建好的內部流程,時限內根本來不及。

Q和 ISO 27001 的關係?

27001 是組織資安管理系統,29147/30111 是產品漏洞揭露與處理的專門標準。已有 27001 的組織可把 CVD 流程掛載於既有 ISMS,文件與稽核機制共用。