【EU CRA】 Reporting Guide: Mandatory 24-Hour Notification Starts September 11, 2026

As the European Union moves toward the full implementation of the Cyber Resilience Act (CRA), the European Commission has clarified the mandatory reporting obligations for products with digital elements. Starting September 11, 2026, manufacturers must comply with rigorous timelines for reporting actively exploited vulnerabilities and severe security incidents. 1. The “24-Hour” Compliance Challenge Under the […]

【EU CRA】歐盟 CRA 網路韌性法案通報機制將於 2026 年 9 月 11 日上路

隨著《歐盟網路韌性法案》(Cyber Resilience Act, CRA)的推動,歐盟委員會近日進一步明確了受管制產品(含數位元素產品)的強制性漏洞通報規則。自 2026 年 9 月 11 日起,所有在歐盟市場銷售的數位產品製造商,將面臨極其嚴格的網路安全漏洞與事故通報義務。 一、 嚴苛的「24小時」通報時效 CRA 要求製造商在發現「已被積極利用的漏洞(Actively Exploited Vulnerabilities)」或「嚴重安全事故」時,必須履行階梯式通報義務: 24小時內: 提交「早期預警(Early Warning)」。 72小時內: 提交「完整通知(Full Notification)」。 最終報告: 對於漏洞,須在採取修正措施後 14 天內提交;對於事故,則須在 1 個月內提交報告。 二、 單一通報平台(SRP)正式定案 為簡化流程,歐盟網路暨資訊安全局(ENISA)正在開發**「CRA 單一通報平台(Single Reporting Platform, SRP)」**。 製造商只需透過該平台通報一次,資訊將自動分發至該企業主要據點國家的電腦安全事件應變小組(CSIRT)及 ENISA。 該平台預計於 2026 年 9 月 11 日前正式啟用,在此之前將進行測試。這代表企業必須在未來 18 個月內,將其內部的漏洞監測與通報系統與此外部平台完成對接。 三、 對認證體系與製造商的影響 身為認證服務供應商,我們觀察到 CRA 不僅是「事後通報」,更強調「事前合規」: 漏洞監控能力: 企業若無法證明其具備 24 小時內的偵測與反應能力,將難以通過產品的安全性符合性評估(Conformity […]

【QCVN】Vietnam New Cybersecurity Standard QCVN 11 Released, Effective July 2026

The Ministry of Public Security of Vietnam (BCA) has officially issued Circular No. 48/2026/TT-BCA, introducing the new national technical regulation QCVN 11:2026/BCA (National technical regulation on Internet Protocol surveillance camera devices – Basic cybersecurity requirements). This standard will officially take effect on July 1, 2026, replacing the previous QCVN 135 regulation. The introduction of QCVN […]

【EU CRA】 EN 304 627 Final Draft Released, Clarifying Security Requirements for Network Devices

The European Telecommunications Standards Institute (ETSI) has recently released ETSI EN 304 627 V1.0.0 Final Draft. As a vertical product standard supporting the EU Cyber Resilience Act (CRA), it specifies technical cybersecurity requirements and conformity assessment criteria for routers, modems, and switches. Once officially cited in the Official Journal of the European Union (OJEU), this […]

【TC260】China Releases 18 National Cybersecurity Standards Effective Dec 2026

China’s National Information Security Standardization Technical Committee (TC260) has announced the approval of 18 national cybersecurity standards, set to take effect on December 1, 2026. This update reflects China’s strengthening framework, which will substantially impact the security design of digital products, embedded devices, and cloud services entering the market. 💡 Key Covered Domains of the […]

【BSMI】Taiwan BSMI to Enforce Mandatory Inspection for LED Light Source Control Devices

If your product portfolio includes lighting equipment, LED drivers, or power supplies targeting the Taiwanese market, please look closely at this upcoming regulatory change. The Bureau of Standards, Metrology and Inspection (BSMI) under the Ministry of Economic Affairs in Taiwan has officially announced that LED light source control devices will be included in the list […]

【SDPPI】Indonesia Revises SAR Regulations for Tablets and Wearables (KEPMEN No. 197 of 2026)

The Indonesian Ministry of Communication and Digital Affairs (KOMDIGI, formerly KEMKOMINFO/SDPPI) has officially issued a new decree, KEPMEN No. 197 of 2026, regarding Specific Absorption Rate (SAR) limits for telecommunication devices. This latest regulation immediately replaces the previous KEPMEN No. 177 of 2024. For manufacturers of mobile phones, tablets, and connected wearables targetting the Indonesian […]

【CAK】Kenya Enforces Mandatory Certification for Short-Range and Wireless Devices

If you are manufacturing, importing, or distributing wireless products targetting East African markets, please take note of an important regulatory enforcement. The Communications Authority of Kenya (CAK) has clarified and strictly enforced type approval mandates for Short-Range Devices (SRDs) and Wireless LAN (WLAN) equipment operating within the 2.4 GHz and 5 GHz frequency bands. To […]

【EU】EU Agrees to Simplify AI Rules to Boost Innovation, Ban ‘Nudification’ Apps, and Set Clear Hardware Integration Timelines

Understanding the “Digital Omnibus on AI”: Key Compliance Deadlines Enforced for High-Risk Systems (2027) and Smart Integrated Products (2028). Global software compliance and smart hardware market access have reached a pivotal milestone. The European Commission has welcomed the political agreement reached between the European Parliament and the Council of the EU on simpler, innovation-friendly rules […]

【Vietnam ICT】Enforces Circular No. 14/2026/TT-BKHCN: Paradigm Shift to Risk-Based Conformity Framework and Introduction of E-Labeling

A significant regulatory transition is set to reshape the market access landscape in Southeast Asia. The Vietnamese Ministry of Science and Technology (MoST) officially issued Circular No. 14/2026/TT-BKHCN. This landmark regulation will enter into force on May 25, 2026, fully replacing the long-standing Circular No. 28/2012/TT-BKHCN. The core of this regulatory overhaul is Vietnam’s transition […]

【FCC Announcement】FCC Looks to Prohibit Electronic Device Testing Using Labs in CountriesWithout Reciprocal Agreements

【FCC Public Announcement】 April 30, 2026, the Federal Communications Commission (FCC) voted to launch a rulemaking which proposes prohibiting the recognition of electronic device test labs and certification bodies in foreign countries that have not signed reciprocity agreements to recognize American test labs and certification bodies. The FCC also adopted new rules streamlining the approval […]

【EU】EU AI Act: Key Timeline for Businesses Using AI

As artificial intelligence continues to grow rapidly, the European Union has introduced the EU AI Act, the world’s first comprehensive regulation on AI. The regulation officially entered into force in 2024 and will be implemented in phases over the next few years. Businesses that develop or use AI-related products are encouraged to start paying attention […]