CRA Countdown: Why Taiwan's ICT Makers Should Prepare Now
The EU Cyber Resilience Act is counting down, with fines up to 2.5% of global revenue. What EN 18031's three parts actually test, and why waiting until 2027 is too late.
Read article →Latest industry updates, including news and PCI-related knowledge.

The EU Cyber Resilience Act is counting down, with fines up to 2.5% of global revenue. What EN 18031's three parts actually test, and why waiting until 2027 is too late.
Read article →
As the US FDA, EU MDR, the CRA and Taiwan's TFDA keep raising cybersecurity requirements, SV Surveillance and Applus+ Laboratories build a Taiwan security lab to help medical device makers clear security verification.
Read article →
Under Mastercard GLB 12772, a 5% refund/chargeback rate triggers a mandatory 72-hour investigation. See how Payment Facilitators should react.
Read article →
Master PCI DSS v4.0.1 rules for 6 and 8-digit BINs. Learn exact PAN truncation (storage) and masking (display) limits to secure your payment data.
Read article →At Medical Taiwan 2026, Taiwanese device makers asked most about the MDR transition, FDA Section 524B, and the SVS-Applus+ route to FDA and MDR compliance.
Read article →
Secure Vectors Surveillance signs an alliance with Applus+ Laboratories, becoming a recognized security lab offering full EN 18031 testing and a one-stop CRA compliance path in Taiwan. (iThome coverage)
Read article →
On June 29, Secure Vectors Surveillance and Applus+ Laboratories formally signed their alliance: Taiwanese medical device makers can now complete the full path from QMS and security testing to EU Notified Body review locally.
Read article →
prEN 40000-11:2026 gives Hardware Devices with a Security Box a harmonised route to EU CRA conformity: scope, the 18 requirement families, and evidence reuse.
Read article →
What ISO 27701 (PIMS) covers, how it differs from ISO 27001, its link to GDPR compliance, and who needs certification.
Read article →
What internal auditors do in ISO management systems — why they're mandatory, how priorities shift across ISO standards, and the step-by-step audit process.
Read article →
Why medical device makers need ISO 27001 — patient data sensitivity, IoMT attack surfaces, supply chain risk, and the 5-step certification process.
Read article →
Most ASV scan failures aren't real vulnerabilities — the CVSS 4.0 threshold, QSA-ready reporting, and the backporting trap explained.
Read article →
What ISO 13485 is, why medical device companies need it, the 5-step certification process, and common misconceptions about the standard.
Read article →
From September 2026 the EU Cyber Resilience Act makes Article 14 incident reporting mandatory. The two triggers, the reporting deadlines, and who to notify.
Read article →
FDA guidance pushes medical device cybersecurity governance into the QMS — what QMSR harmonization and Section 524B mean for manufacturers.
Read article →
Applus+ Laboratories' Shanghai lab passed an EMVCo on-site audit, adding Contactless (C-8) testing - an accredited certification route for APAC terminal makers.
Read article →
Secure Vectors is now a PCI SSC Approved Scanning Vendor, adding ASV to its QSA, 3DS and PIN Security accreditations. What ASV status demands, and why.
Read article →
Microsoft's July 2025 Patch Tuesday fixes 130 vulnerabilities including CVE-2025-49719 in SQL Server — what it means for PCI DSS environments.
Read article →
From August 1, 2025 all radio equipment sold in the EU must meet the RED cybersecurity requirements. Who is affected, EN 18031, and what to do if you miss it.
Read article →
Anyone storing, processing or transmitting cardholder data must meet PCI DSS. Here are the merchant and service provider levels and what each level submits.
Read article →
There are 10 PCI DSS SAQ types. This guide compares SAQ A, A-EP and D for merchants and service providers, and walks through the five steps of self-assessment.
Read article →
Service Providers must conduct quarterly inspections under PCI DSS v4.0 provision 12.4.2 — the 5 inspection items and how to comply.
Read article →
Google Cloud Build may have a Bad.Build vulnerability allowing privilege escalation — what PCI DSS entities using GCP should check.
Read article →
A critical SSL-VPN flaw (CVE-2023-27997, CVSS 9.8) lets attackers run remote code on FortiOS, FortiOS-6K7K and FortiProxy. Check your version and patch.
Read article →
CVE-2021-36934 lets an ordinary Windows 10 or 11 user read system files and gain administrator rights. What it means for cardholder data, and how to fix it.
Read article →
An out-of-bounds write flaw in the Linux kernel's seq_file — what it means for PCI DSS compliance and how to remediate.
Read article →
An introduction to the PCI DSS compliance standards process, an explanation of PCI DSS levels of compliance and their required costs.
Read article →
3DS 2.0 changes who must validate. This guide sets out which 3DSS, ACS, cloud and HSM providers need a PCI 3DS assessment, and the seven steps to certification.
Read article →Related