An important CRA milestone built on years of commitment to cybersecurity

Teamwork on cybersecurity in industrial networks

September 11th 2026 marked an important milestone in the implementation of the EU Cyber Resilience Act (CRA). Manufacturers of products with digital elements (PDEs) are now required to report actively exploited vulnerabilities and severe cybersecurity incidents to the relevant authorities under Article 14 of the regulation.

For customers operating critical infrastructure, this milestone reinforces the maturity and transparency of cybersecurity practices. It demonstrates that vulnerabilities are managed through established processes, that severe incidents can be handled in a structured manner, and that cybersecurity remains a priority throughout the product lifecycle.

For Westermo, being able to meet CRA reporting obligations of Article 14 is the result of years of investment in product cybersecurity. Long before the CRA was introduced, teams throughout our company were already building the foundations through secure development lifecycle practices aligned with IEC 62443, structured vulnerability management processes and a dedicated Product Security Incident Response Team (PSIRT). These capabilities have since been further developed and aligned through our CRA programme, creating a coordinated approach to cybersecurity governance, vulnerability management and incident reporting.

Teams across the Westermo group have worked closely together to strengthen and coordinate the capabilities that support the new reporting obligations. Product developers, cybersecurity experts, manufacturing sites, IT teams and management functions have all played an important role.

Together, they have further strengthened three key areas:

  • Product cybersecurity governance across the organisation
  • Vulnerability management and incident response throughout the product lifecycle
  • Regulatory reporting procedures to meet the new CRA requirements

By aligning processes, clarifying responsibilities and improving coordination between teams and sites, we have established a common approach to handling vulnerabilities and security incidents across the group.

A map showing Westermo group sites

The result is readiness for the CRA reporting obligations, and an even stronger foundation for identifying vulnerabilities, responding to incidents and supporting customers in an increasingly demanding cybersecurity landscape. For customers, this means greater transparency, clear responsibilities and the confidence that cybersecurity issues are managed through established processes and experienced teams.

“The reporting obligations entering into force on 11 September are an important milestone, but they are really the result of work that has been underway for many years. The foundations were already in place through our IEC 62443-aligned development processes, vulnerability management and PSIRT organisation."

The 11 September 2026 milestone is an important checkpoint, but not the finish line. Westermo continues to strengthen product cybersecurity across product development, lifecycle management, technical documentation, conformity assessment and support processes as we prepare for the full implementation of the Cyber Resilience Act in December 2027.

 

Press Contact
Fredric Mazzarello
Marketing & Communications Manager
Tel: +46 6420658
fredric.mazzarello@westermo.com


Nuri Shakeer

International Sales

Ask me about CRA reporting obligations

Bitte geben Sie eine Nachricht mit mindestens 30 Zeichen ein.

Bitte geben Sie eine gültige E‑Mail‑Adresse ein.

Bitte geben Sie eine gültige Telefonnummer ein.

Bitte geben Sie Ihre E-Mail-Adresse ein, um die Datei herunterzuladen


Vielen Dank! Eine E-Mail ist auf dem Weg zu Ihnen.

Etwas ist schief gelaufen! Bitte versuchen Sie es später erneut.