
Our Approach to the CRA
As a global leader in high-performance computing technology, DFI has always treated cyber resilience as a core strategic direction for industrial applications, embedding security deeply into product architecture. Through IEC 62443-4-1 certification, DFI has established a rigorous security process spanning design, development, testing, and lifecycle maintenance. The enactment of the EU Cyber Resilience Act (CRA) marks the beginning of a new era of mandatory compliance in global digital product cybersecurity regulation. DFI has initiated and continues to advance related preparations to help customers more efficiently align with international standards and regulatory requirements, ensuring industrial computing equipment is built with superior defense capability and competitive advantage from the ground up in R&D.
EU Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), establishes horizontal cybersecurity requirements for all products with digital elements (PwDE) sold into the EU, representing a further step by the EU toward mandatory cybersecurity requirements for digital products. In response, DFI has begun the relevant technical and process preparations, using comprehensive technical and compliance planning to help customers reduce the technical and communication costs of adopting the new regulations.
The main objectives of the EU Cyber Resilience Act include:
• Strengthening full lifecycle security of digital products: Ensuring all products with digital elements have comprehensive cybersecurity protection and vulnerability remediation mechanisms from design through production to after-sales maintenance.
• Enhancing supply chain and digital market resilience: Establishing unified European cybersecurity standards to reduce the risk of systemic cascading cyberattacks triggered by a single hardware or software vulnerability.
• Protecting users' right to information and transparency: Providing clear security guidance and transparent vulnerability reporting mechanisms to help businesses and consumers make informed and safe decisions when purchasing and using digital products.
To give manufacturers sufficient time to adjust and align, the EU Cyber Resilience Act (CRA) adopts a phased rollout strategy. The regulation officially took effect on December 10, 2024, and will be progressively implemented over the following years.
During this transition period, companies must pay particular attention to two key milestones: first, September 11, 2026, when mandatory reporting of security vulnerabilities becomes a legal requirement; and second, December 11, 2027, the "full compliance deadline," by which all products falling within the scope of the CRA must meet the relevant market access requirements. This timeline will affect CE marking and eligibility for sale in the EU market for applicable products.
DFI's secure development process has obtained IEC 62443-4-1 certification, forming the foundation for advancing CRA readiness. We continue to track the progress of harmonized standards from European standardization bodies (CEN/CENELEC/ETSI), strengthening overall resilience through horizontal standards while introducing vertical standards for specific product categories, progressively aligning our product development processes; product security functional specifications are also being planned in accordance with the IEC 62443-4-2 framework.
Per Annex I of the CRA, products with digital elements must meet related horizontal security requirements across two dimensions: first, essential requirements relating to product properties, emphasizing that defense starts at the source — manufacturers must conduct comprehensive risk assessments during the design and production stages, adopt "security by design/secure by default" thinking, and implement corresponding permission and access controls based on risk level; second, essential requirements for vulnerability handling, extending compliance responsibility to the post-sale period — manufacturers must establish vulnerability handling and security update mechanisms during the product's expected period of use, managing known vulnerabilities and reducing lifecycle security risk. Based on this, DFI proposes three cybersecurity focus strategies:
• Security by Design: Integrating SSDLC (Secure Software Development Lifecycle) into industrial motherboard and system development processes, building defense from the hardware Root of Trust upward.
• Deep Embedded Resilience: Partnering with leading chip suppliers to build multi-layered defenses from BIOS and firmware to the OS level, reducing exposure to complex threats.
• Full Lifecycle Vulnerability Management: Establishing a PSIRT and vulnerability management process to support vulnerability management and security updates throughout the long operational life of industrial-grade equipment, improving resilience against emerging threats.
Committed to the philosophy of "security by design." We conduct ongoing cybersecurity risk assessments, rigorous supply chain due diligence, and provide secure update mechanisms to ensure long-term sustainable support.
• Continuous Assessment: Cybersecurity risk assessments are conducted and records maintained throughout the product's planning, design, production, and maintenance phases.
• Supply Chain Security: Rigorous due diligence is performed when integrating third-party and open-source components to guard against security risks.
• Continued Support: We have established secure update mechanisms to provide security updates based on risk level and verification results within the specified support period.
We maintain a dedicated Product Security Incident Response Team (PSIRT), operating with reference to the ISO 29147 and ISO 30111 practice guidelines, and adopting the FIRST services framework for coordinated response, ensuring reliable vulnerability disclosure and handling.
• Global Framework: Our PSIRT operates in line with the best practices of ISO 29147 (vulnerability disclosure) and ISO 30111 (vulnerability handling), consistent with the reference frameworks adopted by the CRA.
• Coordinated Response: We have adopted the FIRST services framework to reliably handle reported security vulnerabilities and issue security advisories.
• Long-Term Commitment: Our processes provide ongoing support for industrial equipment expected to operate securely over long lifecycles.
We maintain the necessary technical documentation and audit records, provide users with clear product transparency information (such as end-of-support dates and vulnerability contact points), and equip products with authentication and patch deployment tools.
• User Transparency: We provide clear product information, including intended use, end-of-support dates, and vulnerability reporting contact details.
• Built-in Defense Mechanisms: Products feature tiered authentication and access control designs, support secure default configurations, and provide reliable mechanisms for deploying security updates and patches.

Security Advisories & Vulnerability Procedures
DFI is committed to rigorous management of product security vulnerabilities, providing customers with reliable guidance and mitigation methods for product information security vulnerabilities, in order to minimize related risks. To this end, DFI PSIRT is responsible for handling product information security incidents reported to DFI and related vulnerability notifications. DFI continues to reference internationally and industry-recognized practices and standards, continually strengthening its vulnerability handling procedures and response measures, and taking a proactive approach to supporting industrial cybersecurity as a trusted partner to our customers.
• Product Security Vulnerability Management Process: DFI's product security vulnerability management process consists of five stages, each with a rigorous handling procedure. For updates and publication of product security advisories, please refer to the CRA "Security Advisories" section.
• Product Security Contact: If you discover a suspected security vulnerability in any DFI product, please report it through the DFI PSIRT contact: PSIRT@dfi.com. For DFI, timely discovery of security vulnerabilities is key to reducing potential product security risks.
Aspects of the information security vulnerability management principles may be subject to change on a case-by-case basis. DFI will evaluate and handle reports based on their content, scope of impact, and risk level; handling methods and timelines may vary by case. Use of the information contained in this document, or content linked from this document, is at your own risk. DFI reserves the right to modify any content within this policy at any time without prior notice. Any revisions will be published on the CRA-related information page of the official DFI website.
Should a security concern be identified, DFI will follow relevant CRA requirements to issue security advisories and complete corresponding notifications, while providing security update guidance for customers to download and use to resolve related issues. Please see the download section on the right for related files.

Report a Security Vulnerability
If you discover a potential security vulnerability in a DFI product, please submit a detailed report to help expedite our risk assessment and enable us to provide a fix or mitigation as quickly as possible.
The report should include the following information:
- Product name and model
- Software/firmware version
- Equipment and software required to reproduce the issue
- Steps to reproduce the issue (please include images or code where possible)
- Proof of concept or exploit code
- Description of potential attack impact
- Packet capture of the attack process
- Any other supplementary information you believe would aid the analysis

Learn More About the CRA
DFI has comprehensively addressed CRA requirements and is committed to providing customers with the most robust compliance assurance and support. Visit DFI Insights to explore CRA-related articles, or refer to the FAQ below for a comprehensive understanding of the CRA.
CRA Frequently Asked Questions (FAQ)
The EU Cyber Resilience Act (CRA) sets a new benchmark for all Products with Digital Elements (PwDE) entering the European market, bringing both hardware and software fully within the scope of mandatory cybersecurity regulation. This regulation is designed to compel manufacturers to uphold end-to-end security commitments, requiring the adoption of secure design, vulnerability management, and security update mechanisms throughout the product lifecycle to enhance product resilience.
The EU Cyber Resilience Act (CRA) has an extremely broad scope, covering all Products with Digital Elements (PwDE) that can connect directly or indirectly to other devices or networks — whether connectable hardware such as smartphones, IoT devices, and routers, or software such as operating systems, applications, and software libraries. Only specific products already regulated under other dedicated regulations, such as medical devices and vehicles, as well as non-commercial open-source software, are exempt. In response to this new regulation, most of DFI's network-connectable industrial computers, embedded systems, and related software may fall within the CRA's definition of PwDE, though actual applicability still depends on the product configuration and market use. DFI has included relevant product lines within the scope of CRA preparation and assessment, to help customers align with international cybersecurity requirements.
Under the CRA framework, manufacturers' compliance obligations span the product's entire lifecycle, from development to post-sale support. During the pre-market readiness phase, companies must carry out cybersecurity risk assessments to ensure compliance, and complete the preparation of technical documentation, conformity assessment procedures, and CE marking; during the operational phase after product launch, manufacturers must fulfill security update and vulnerability management obligations throughout the support period, and proactively and promptly report to the relevant authorities in the event of an actively exploited vulnerability or a major security incident.
Harmonized standards are technical specifications developed by European standardization bodies such as CEN, CENELEC, and ETSI, whose core purpose is to translate the essential security requirements of the Cyber Resilience Act (CRA) into clear, implementable specifications for R&D teams. These standards are built on existing global cybersecurity standards, with the "horizontal" and "vertical" standards expected to be published in August and October 2026 respectively; DFI will continue to track the latest standards developments and progressively adjust its product development and security processes to remain aligned.
Understanding the CRA compliance timeline helps reduce compliance risk when bringing products into the EU market. The regulation will be implemented in two key phases: starting September 11, 2026, vulnerability and security incident reporting will become a mandatory statutory obligation; and the most critical full compliance deadline is set for December 11, 2027, by which time the relevant CRA market access requirements will formally apply — products that do not meet the requirements will be unable to obtain CE marking, so companies must accelerate their product line security planning starting now.
Companies that fail to meet CRA requirements may face administrative fines, product withdrawal from the market, or restrictions on market sales. The regulation establishes strict penalty mechanisms for core violations, with fines of up to €15 million or 2.5% of a company's total global annual turnover, whichever is higher; other technical or procedural violations carry corresponding penalties. This clearly demonstrates the EU's determination to comprehensively strengthen the cybersecurity of digital devices, and CRA compliance will become an essential condition for applicable products to enter the EU market.
The EU's CRA and NIS2 are two cybersecurity regulations advancing in parallel, but they establish different dimensions of security defense. The NIS2 Directive focuses on protecting the information systems and network security of "operators of critical infrastructure and essential services," whereas the CRA focuses directly on "the digital product itself," mandating security-by-design from the source and full lifecycle vulnerability governance. The two regulations complement each other, together building comprehensive defense resilience across Europe's digital environment, and DFI's industrial computing platforms can serve as an important foundation for customers building CRA-ready products, helping them adopt secure design, vulnerability management, and long-term maintenance mechanisms.
A Software Bill of Materials (SBOM) is a "digital ingredient list" detailing all software components and libraries contained within a product. The CRA requires manufacturers to establish relevant lists and technical documentation for their product's software components, in order to support vulnerability management and compliance verification. While current regulations do not require manufacturers to proactively disclose this information to the public, companies must be able to provide the relevant SBOM information upon request from regulators or market surveillance authorities as required by law.
DFI has obtained IEC 62443-4-1 Secure Development Lifecycle (SDL) certification, ensuring that its product design and development processes meet rigorous industrial control cybersecurity standards. The company is currently planning to pursue IEC 62443-4-2 certification in line with internal policy and customer requirements. Please click here to view the relevant certificate.
