CTC Union Prepares for CRA Reporting Requirements

22 September 2026 Product News

CTC Union has completed its preparations for the vulnerability and incident reporting requirements of the EU Cyber Resilience Act (CRA).

The reporting obligations under Article 14 of the CRA have applied since 11 September 2026. The main CRA requirements will apply from 11 December 2027.

CTC_Union_CRA.jpg

PSIRT and SBOM Support Structured Vulnerability Management

CTC Union has established a Product Security Incident Response Team (PSIRT) to receive and assess vulnerability reports, coordinate corrective measures and manage the required notifications.

A Software Bill of Materials (SBOM), together with product and firmware records, helps identify the software components, products and firmware versions affected by a newly disclosed vulnerability.

CTC Union uses the Common Vulnerability Scoring System (CVSS) to assess severity and prioritise remediation. Product management, R&D, quality assurance and other relevant teams are involved in vulnerability analysis and the coordination of corrective measures.

Secure Development Lifecycle Based on IEC 62443-4-1

CTC Union bases its Secure Development Lifecycle on IEC 62443-4-1 and holds certification for the corresponding development processes. The approach covers security activities throughout product development and maintenance.

CRA Reporting Deadlines

Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident affecting the security of a product with digital elements. A full notification follows within 72 hours. Depending on the type of case, additional deadlines apply for the final report. Notifications are submitted through the CRA Single Reporting Platform.

Relevance for Industrial Network Operators

For operators of industrial networks, structured vulnerability handling, documented firmware versions and clearly defined security update processes are becoming increasingly important selection criteria. They help companies identify affected devices and implement corrective measures more efficiently when new vulnerabilities become known.

IPC2U offers industrial Ethernet switches from CTC Union and other manufacturers for demanding network applications. We support the selection of a suitable solution for your project.


Contact us!