CRA Countdown: Why Taiwan's ICT Manufacturers Should Prepare Now — Not in 2027
If your product has any connectivity — Wi-Fi, Bluetooth, or any form of data connection — then after December 2027, whether it can legally be sold into the European market is no longer decided by quality or price. It is decided by whether you hold a compliance document.
Key Takeaways
- CRA timeline: In force Dec 2024 → EN 18031 mandatory Aug 2025 → vulnerability reporting from Sep 11, 2026 → fully applicable Dec 11, 2027
- Penalties: Up to €15 million (≈ NT$510 million) or 2.5% of global annual revenue, whichever is higher
- The bigger risk: Being dropped from brand supply chains — brands already require suppliers to submit SBOMs and test evidence
- What EN 18031 tests: Three parts mapping to RED 3.3(d)(e)(f) — network protection, privacy protection, fraud prevention
- What you can do now: Book a free gap analysis, or join the free "EU CRA Update" live session
The Regulatory Deadline Is at the Door — and the Clock Is Running
The timers below are calculated live. Every second you see is real.
CRA Enters into Force
The EU Cyber Resilience Act takes effect, covering all products with digital elements (PDE).
✓ In forceEN 18031 Becomes Mandatory
The security requirements under the amended Radio Equipment Directive (RED) become mandatory — no longer voluntary.
✓ In forceVulnerability Reporting Obligations Begin
Actively exploited vulnerabilities must be reported to CSIRT/ENISA within 24 hours, with a full report within 72 hours.
CRA Fully Applicable
Every PDE product sold into the EU must comply. Fines up to €15M (≈ NT$510 million) or 2.5% of global revenue.
For most ODM/OEM manufacturers, the real damage is being dropped from a brand's supply chain. Brand owners carry the final legal responsibility — even when a vulnerability originates with a single supplier — so they have already begun demanding SBOMs (software bills of materials) and test evidence as a new condition of market entry. Notified Body certification typically takes 12 to 18 months; wait until 2027 and you join a global queue the NBs cannot absorb.
CRA and EN 18031 Overlap Heavily — So What Exactly Gets Tested?
The good news: nothing you invest now is wasted. EN 18031 is the harmonized standard under Article 3.3 of the Radio Equipment Directive (RED) — RED 3.3 is the parent regulation, EN 18031 is the technical standard used to demonstrate compliance; they are two layers of the same thing. The CRA's own harmonized standards are still in draft, but they are widely expected to extend EN 18031's technical architecture — prepare for EN 18031 now and the foundation for the CRA is already laid.
EN 18031 is not a single standard. It splits into three independent parts, each mapping to a different security requirement in RED Article 3.3(d), (e) and (f):
Network Protection
Ensures the device and its network connections resist intrusion — the broadest of the three parts.
Privacy Protection
Examines how personal data is protected through collection, storage and transmission.
Fraud Prevention
Confirms the device cannot be used as a tool or springboard for fraud.
💡 Practical advice for decision-makers
Full conformity with all three parts of EN 18031 allows self-declaration — no Notified Body (NB) review — a realistic acceleration option for manufacturers weary of the NB queue. Use other standards, or fall short anywhere, and NB review is still required.
The CRA does not directly adopt EN 18031 as its official harmonized standard. Under standardization Mandate M/606, the EU is drafting a new series — prEN 40000 and EN 304 6xx — still at draft stage, but built as an extension of EN 18031's technical architecture. Complete EN 18031 now and the groundwork for the CRA harmonized standards is already done.
Worth noting: EN 18031-3 is designed specifically for connected devices handling virtual currency or monetary value — squarely within the payment-security domain Secure Vectors Surveillance has worked in for over a decade. If your product touches payment flows, stored value or transactions, this part deserves particular attention.
Note: this page focuses on general ICT connected devices. The MDR × EN 18031 dual-compliance challenge for smart medical devices is a larger topic we will cover in a dedicated deep dive.
Ready to Act? Here Is the Path
Secure Vectors Surveillance and Applus+ Laboratories propose a three-level strategy for getting ahead of the change:
Regulatory Awareness
Track CRA developments and clarify your products' risk classification and scope
Implementation Capability
Build a vulnerability-disclosure SOP that meets the 24-hour alert / 72-hour report requirement, and complete a gap analysis
Industry Ecosystem
Local testing × global certification through a partner network, so compliance is not a solo fight
Secure Vectors Surveillance and Applus+ Laboratories present “EU CRA Update” — a one-hour live online session, completely free, unlimited seats, built for decision-makers, export sales leads and compliance officers.
Don't scramble after the regulation fully applies — complete your gap analysis now
Keep your time for the product work that matters.
Frequently Asked Questions
The CRA entered into force in December 2024. EN 18031's security requirements became mandatory in August 2025; vulnerability-reporting obligations begin September 11, 2026; and on December 11, 2027 the CRA becomes fully applicable to every product with digital elements sold into the EU.
Up to €15 million (≈ NT$510 million) or 2.5% of global annual revenue, whichever is higher. In practice, the bigger risk for most ODM/OEM makers is being dropped from brand supply chains.
EN 18031 is the harmonized standard under RED Article 3.3, in three parts mapping to 3.3(d)(e)(f): Part 1 network protection (general connected devices), Part 2 privacy protection (children's products, toys, wearables), Part 3 fraud prevention (devices handling virtual currency or monetary value). Full conformity allows self-declaration with no Notified Body review.
Notified Body certification typically takes 12 to 18 months. Apply on the eve of full enforcement in 2027 and you risk a global queue the NBs cannot absorb — start the gap analysis now.