Moxa Prepares for EU Cyber Resilience Act
With the EU’s new cybersecurity reporting rules about to take effect, industrial networking company Moxa says it is ready for one of the regulation’s most demanding requirements: responding to...
With the EU’s new cybersecurity reporting rules about to take effect, industrial networking company Moxa says it is ready for one of the regulation’s most demanding requirements: responding to serious cyber threats within hours.
The company announced that its processes are prepared for the EU Cyber Resilience Act (CRA) reporting obligations, which begin on September 11, 2026. Under the rules, manufacturers must issue an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe security incident affecting a product with digital elements. A fuller notification follows within 72 hours, with final reporting deadlines tied to remediation or incident closure.
For industrial technology suppliers, the challenge goes well beyond having a cybersecurity team on standby. A company must be able to quickly determine which products, firmware versions, and software components are affected and coordinate engineering, product, legal, and security teams within this period.
Moxa says its approach is built around a mature Secure Development Lifecycle (SDL), supported by a Product Security Incident Response Team (PSIRT), Software Bill of Materials (SBOM) management, and product traceability. The company also holds IEC 62443-4-1 Maturity Level 3 certifications from IECEE and ISASecure, which it cites as evidence of established and repeatable product-security processes.
When a vulnerability appears in a known-exploited-vulnerability catalogue, security teams can more quickly map it against affected components and products, assess the risk, and begin the appropriate response.
That matters particularly in industrial environments, where equipment can remain in service for years and a single vulnerability may affect multiple generations of products.
The CRA’s reporting requirements and the corresponding reaction from suppliers point to a broader industry shift toward lifecycle cybersecurity, where secure development, software visibility, and rapid incident response increasingly become part of the product itself.





