CRA Compliance Policy | Industrial & Telecom Network Equipment Manufacturer Since 1993

CTC Union Cyber Resilience Act (CRA) Compliance Policy | CTC Union is committed to delivering reliable, temperature-resistant, and rugged industrial networking solutions designed for harsh environments. Our comprehensive product portfolio includes L3/L2 Managed Switches, PoE solutions, and certified Ethernet switches meeting EN50155, IEC 61850-3 and E-Mark requirements for railway, power utility, transportation, and networks.

CTC Union Cyber Resilience Act (CRA) Compliance Policy

CRA Compliance Policy

CTC Union's Commitment to Cybersecurity

Since its founding in 1993, CTC Union has spent more than 30 years in the telecommunications and industrial networking industry, dedicated to delivering secure, reliable, and high-quality network communication products widely used in railway, intelligent transportation, power, surveillance, industrial automation, and other critical infrastructure environments.

We believe product cybersecurity is an essential part of product quality. Guided by a Secure by Design philosophy, we embed security requirements throughout the full product lifecycle — planning, design, development, verification, and maintenance. CTC Union has established a Secure Development Lifecycle (SDL) in accordance with the IEC 62443 series of standards, and continues to strengthen product security governance, vulnerability management, and security update mechanisms to enhance the overall security and resilience of our products.

In response to the requirements of the EU Cyber Resilience Act (CRA) regarding product cybersecurity, CTC Union continuously reviews and optimizes its product development processes and related management systems, ensuring that products remain compliant with applicable security requirements both before market launch and throughout their lifecycle. Through vulnerability management, security updates, and product maintenance mechanisms, we help customers reduce cybersecurity risk and build secure, reliable, and resilient network infrastructure.


What is the CRA?

The Cyber Resilience Act (CRA) is a horizontal EU cybersecurity regulation covering Products with Digital Elements (PwDE). It applies to hardware, software, and related products with digital functionality or network connectivity that are placed on the EU market.
The CRA requires manufacturers to take responsibility for product cybersecurity across the entire product lifecycle, covering secure design, vulnerability management, security updates, technical documentation, and information disclosure requirements, in order to raise the overall security and resilience of digital products in the EU.

Key objectives of the CRA include:
Implementing Secure by Design principles: requiring manufacturers to incorporate cybersecurity considerations during product planning, design, development, and maintenance to reduce cybersecurity risk across the product lifecycle.
Improving product transparency: requiring manufacturers to provide necessary security information, technical documentation, and product support information to help users understand a product's security features and support period.
Strengthening vulnerability management and security updates: requiring manufacturers to establish vulnerability management mechanisms to continuously identify, assess, and address security vulnerabilities throughout a product's expected support period, and to provide necessary security updates.
Enhancing the overall resilience of the EU digital market: reducing the risk of digital products being attacked and improving overall cybersecurity capability through consistent product security requirements.

Products within the scope of the CRA must complete a Conformity Assessment in accordance with regulatory requirements. Only after meeting the applicable requirements may a product bear the CE marking and be placed on the EU market.

Key Points of the CRA

Scope of Application

The CRA applies to products that contain digital elements and can be connected, directly or indirectly, to other devices or networks, including networked hardware, software, and related digital products.
Some of CTC Union's industrial Ethernet switches, media converters, PoE devices, and network management software may fall within the scope of the CRA. Applicability will be assessed on a product-by-product basis according to product function, intended use, and target market.

Essential Cybersecurity Requirements
The CRA divides the essential cybersecurity requirements into two main parts:
Requirements relating to the properties of products (Part I): Manufacturers must ensure, based on risk assessment results, that products comply with Secure by Design / Secure by Default principles and include appropriate access-control mechanisms.
Requirements relating to vulnerability handling (Part II): Manufacturers must effectively identify, assess, and address security vulnerabilities throughout the product's “expected support period,” and provide necessary security updates.
Manufacturer Obligations

Under the CRA, manufacturers must complete a cybersecurity risk assessment before placing a product on the market to ensure it meets the essential security requirements. Manufacturers must also prepare technical documentation, undergo conformity assessment, affix the CE marking, and report actively exploited vulnerabilities or significant cybersecurity incidents to the competent authorities.

Implementation Timeline
DateMilestone
December 10, 2024The regulation officially enters into force
September 11, 2026Vulnerability and security incident reporting obligations become mandatory
December 11, 2027Products within the scope of the CRA must meet the applicable requirements before being placed on the EU market
CTC Union's Response

In response to the CRA's product cybersecurity requirements, CTC Union continues to strengthen its product security management processes, covering the following areas:

Adherence to International Standards
CTC Union has built its product cybersecurity management framework in accordance with the IEC 62443 series of standards:
IEC 62443-4-1:Secure Development Lifecycle
IEC 62443-4-2:Security Requirements for IACS Components

These standardized processes strengthen our cybersecurity capabilities during the product design, development, and verification stages.

Security-by-Design Lifecycle Management

We conduct ongoing cybersecurity risk assessments throughout product planning, design, production, and maintenance. When integrating third-party or open-source components, we perform necessary security reviews and maintain a Software Bill of Materials (SBOM) to support vulnerability management.

Product Security Incident Response Mechanism

CTC Union maintains a dedicated Product Security Incident Response Team (PSIRT) to handle externally reported product security vulnerabilities. For details, please refer to the CTC Union Vulnerability Disclosure Policy (VDP).

Transparent Product Information

Product documentation includes intended use, support period, and vulnerability reporting channels to help customers stay informed of a product's security status.

Frequently Asked Questions
Does the CRA apply to all of CTC Union's products?

The CRA primarily applies to networked digital products sold in the EU market. CTC Union assesses CRA applicability and compliance progress on a product-by-product basis, according to product type and target market.

How can customers obtain a product's cybersecurity information?

Customers can obtain a product's support period, security update policy, and other information through product documentation or by contacting their CTC Union sales representative. If you discover a potential product security vulnerability, please contact us at PSIRT@ctcu.com.

Will this policy be updated?

This policy will be reviewed and updated as needed in response to developments in the CRA regulation, the publication of related harmonized standards, and the evolution of CTC Union's internal cybersecurity management measures. No individual notice will be given for such updates.

Policy Statement

This document describes CTC Union's approach to the EU Cyber Resilience Act (CRA). It does not constitute legal advice or a compliance guarantee for any specific product.
Whether a product falls within the scope of the CRA, and which conformity requirements apply, will be assessed based on the product's characteristics, intended use, and applicable regulations.
CTC Union reserves the right to revise this policy at any time without prior notice.

CRA Compliance Policy | Industrial & Telecom Network Equipment Manufacturer Since 1993

CTC Union Technologies Co., Ltd., founded in 1993, is an ISO9001/14001 certified designer and manufacturer. CTC Union’s software development system follows the cybersecurity IEC62443 regulations for the design of Industrial & Telecom networking products. With their own in-house R&D and factory, CTC Union develops and manufactures high-quality products in Taiwan. CTC Union offers a full spectrum of products, including Industrial Ethernet, PoE, EN50155 and E-Mark certified switches. CTC Union’s goal is to provide reliable, temperature resistant and rugged designs for mission critical systems used in harsh environments. With more than 30 years of experience in design of Telecom products, CTC Union is highly motivated to deliver various access switches and FTTP CPE products.

CTC Union is a leading Taiwanese manufacturer specializing in telecommunication products such as L2 Ethernet switches, transponders, and industrial Ethernet switches, converters, and injectors. The company maintains strict control over product design, ensuring compliance with certifications like CE, FCC, UL, IEC 62443-4-1, EN50155, EN45545-2, and IEC61850-3. CTC Union has established strong global partnerships with voice and data carriers, enterprises, and industrial Ethernet users, providing direct engineering and technical support from its headquarters in Taipei, Taiwan.