
CRA Compliance Policy
CTC Union's Commitment to Cybersecurity
Since its founding in 1993, CTC Union has spent more than 30 years in the telecommunications and industrial networking industry, dedicated to delivering secure, reliable, and high-quality network communication products widely used in railway, intelligent transportation, power, surveillance, industrial automation, and other critical infrastructure environments.
We believe product cybersecurity is an essential part of product quality. Guided by a Secure by Design philosophy, we embed security requirements throughout the full product lifecycle — planning, design, development, verification, and maintenance. CTC Union has established a Secure Development Lifecycle (SDL) in accordance with the IEC 62443 series of standards, and continues to strengthen product security governance, vulnerability management, and security update mechanisms to enhance the overall security and resilience of our products.
In response to the requirements of the EU Cyber Resilience Act (CRA) regarding product cybersecurity, CTC Union continuously reviews and optimizes its product development processes and related management systems, ensuring that products remain compliant with applicable security requirements both before market launch and throughout their lifecycle. Through vulnerability management, security updates, and product maintenance mechanisms, we help customers reduce cybersecurity risk and build secure, reliable, and resilient network infrastructure.
The Cyber Resilience Act (CRA) is a horizontal EU cybersecurity regulation covering Products with Digital Elements (PwDE). It applies to hardware, software, and related products with digital functionality or network connectivity that are placed on the EU market.
The CRA requires manufacturers to take responsibility for product cybersecurity across the entire product lifecycle, covering secure design, vulnerability management, security updates, technical documentation, and information disclosure requirements, in order to raise the overall security and resilience of digital products in the EU.
Products within the scope of the CRA must complete a Conformity Assessment in accordance with regulatory requirements. Only after meeting the applicable requirements may a product bear the CE marking and be placed on the EU market.
Scope of Application
The CRA applies to products that contain digital elements and can be connected, directly or indirectly, to other devices or networks, including networked hardware, software, and related digital products.
Some of CTC Union's industrial Ethernet switches, media converters, PoE devices, and network management software may fall within the scope of the CRA. Applicability will be assessed on a product-by-product basis according to product function, intended use, and target market.
Under the CRA, manufacturers must complete a cybersecurity risk assessment before placing a product on the market to ensure it meets the essential security requirements. Manufacturers must also prepare technical documentation, undergo conformity assessment, affix the CE marking, and report actively exploited vulnerabilities or significant cybersecurity incidents to the competent authorities.
| Date | Milestone |
|---|---|
| December 10, 2024 | The regulation officially enters into force |
| September 11, 2026 | Vulnerability and security incident reporting obligations become mandatory |
| December 11, 2027 | Products within the scope of the CRA must meet the applicable requirements before being placed on the EU market |
In response to the CRA's product cybersecurity requirements, CTC Union continues to strengthen its product security management processes, covering the following areas:
These standardized processes strengthen our cybersecurity capabilities during the product design, development, and verification stages.
We conduct ongoing cybersecurity risk assessments throughout product planning, design, production, and maintenance. When integrating third-party or open-source components, we perform necessary security reviews and maintain a Software Bill of Materials (SBOM) to support vulnerability management.
CTC Union maintains a dedicated Product Security Incident Response Team (PSIRT) to handle externally reported product security vulnerabilities. For details, please refer to the CTC Union Vulnerability Disclosure Policy (VDP).
Product documentation includes intended use, support period, and vulnerability reporting channels to help customers stay informed of a product's security status.
The CRA primarily applies to networked digital products sold in the EU market. CTC Union assesses CRA applicability and compliance progress on a product-by-product basis, according to product type and target market.
Customers can obtain a product's support period, security update policy, and other information through product documentation or by contacting their CTC Union sales representative. If you discover a potential product security vulnerability, please contact us at PSIRT@ctcu.com.
This policy will be reviewed and updated as needed in response to developments in the CRA regulation, the publication of related harmonized standards, and the evolution of CTC Union's internal cybersecurity management measures. No individual notice will be given for such updates.
This document describes CTC Union's approach to the EU Cyber Resilience Act (CRA). It does not constitute legal advice or a compliance guarantee for any specific product.
Whether a product falls within the scope of the CRA, and which conformity requirements apply, will be assessed based on the product's characteristics, intended use, and applicable regulations.
CTC Union reserves the right to revise this policy at any time without prior notice.