Key Takeaway: QNAP has completed the first phase of EU CRA compliance
QNAP completed the first phase of its EU Cyber Resilience Act (CRA) compliance program on September 11, 2026 — the same day the CRA's obligation to report actively exploited vulnerabilities and severe incidents took effect.
-
Incident reporting: The QNAP Security Reporting Platform is now live. QNAP initiates its statutory response process within 24 hours of receiving a report.
-
Secure development: QNAP follows a publicly available Secure Software Development Lifecycle (SSDLC) policy and has passed IEC 62443-4-1 process verification.
-
Vulnerability management: QNAP PSIRT coordinates vulnerability handling and commits to verifying externally reported vulnerabilities and assigning CVE IDs within one week.
-
Supply chain transparency: QNAP maintains SBOMs in CycloneDX and SPDX formats and cross-checks them against CVE databases and the CISA Known Exploited Vulnerabilities (KEV) catalog.
-
Coverage: QNAP's entire product portfolio, including enterprise ZFS storage, business NAS, Edge AI NAS, and all networking products (routers and switches).
What is the EU Cyber Resilience Act (CRA)?
The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, requires every product with digital elements (PwDE) sold in the EU to meet mandatory cybersecurity requirements throughout its entire lifecycle. CRA compliance is a prerequisite for the CE marking, and products without a CE marking cannot be placed on the EU market.
Three Goals of the CRA
- Strengthen the overall resilience of the EU digital market.
- Give users clearer visibility into the security of the products they buy.
- Reduce the number of vulnerabilities in digital products after they reach the market.
Which Products Does the CRA Cover?
The CRA covers any hardware or software that can connect, directly or indirectly, to a device or network — including its remote data processing solutions. NAS devices, routers, switches, operating systems, and applications all fall within scope. Medical devices, motor vehicles, civil aviation, and marine equipment are excluded because they are already governed by equivalent regulations.
Core Obligations for All Manufacturers Under the CRA
- Conduct a cybersecurity risk assessment at the design stage, applying Secure by Design and Secure by Default principles.
- Establish a vulnerability handling process that meets CRA requirements.
- Provide security updates throughout the support period, until the product reaches end of support.
- Prepare technical documentation, complete a conformity assessment, and affix the CE marking (applies from December 11, 2027).
- Provide clear instructions for secure use, the end-of-support date, and a point of contact for vulnerability reporting.
- Report actively exploited vulnerabilities and severe incidents to the relevant authorities.
When does the CRA take effect? Three key dates
The CRA is being phased in: reporting of actively exploited vulnerabilities became mandatory on September 11, 2026, and full compliance is required for all products placed on the EU market from December 11, 2027.
| Date |
Milestone |
QNAP status |
| December 10, 2024 |
CRA enters into force; transition period begins |
CRA compliance program launched |
| September 11, 2026 |
Reporting obligations for actively exploited vulnerabilities and severe incidents apply |
First phase completed; Security Reporting Platform live |
| December 11, 2027 |
Full compliance deadline, including pre-market conformity assessment and CE marking |
Ongoing, in line with EU guidance and harmonised standards |
Source: European Commission – Cyber Resilience Act
How is the CRA different from NIS2, and why look at them together?
The CRA regulates products; NIS2 regulates organizations. Where they overlap is a unified, risk-based strategy that secures the digital supply chain. For an organization to comply with NIS2, the equipment it buys must itself comply with the CRA.

How the CRA and NIS2 relate a unified strategy from products to organizations
|
EU CRA |
EU NIS2 Directive |
| Focus |
Cybersecurity of products with digital elements |
Security of network and information systems at essential and important entities |
| Who it applies to |
Manufacturers, importers, and distributors |
Organizations in energy, transport, telecom, healthcare, utilities, and other sectors |
| Expected outcome |
Secure hardware and software with transparent components |
Organizational cybersecurity governance and critical infrastructure protection |
| Relevance to QNAP |
QNAP must comply directly as a manufacturer |
QNAP customers must assess supplier security; QNAP provides verifiable evidence |
NIS2 Article 21(2)(d) requires organizations to assess the security risks of their direct suppliers and service providers. Article 21(2)(e) requires security in the acquisition, development, and maintenance of systems, including vulnerability handling and disclosure. QNAP's IEC 62443-4-1 verification, public vulnerability disclosure process, and completion of the first phase of CRA compliance can serve as third-party evidence when customers assess their suppliers.
Learn more: Choose QNAP solutions to achieve EU NIS2 network security and supply chain risk management
How does QNAP meet CRA requirements? Four pillars
QNAP addresses the CRA's essential cybersecurity requirements through four pillars: a secure development process verified against international standards, 24-hour incident reporting, proactive vulnerability management, and a transparent software supply chain. These mechanisms were in place before the CRA took effect — they are not a last-minute fix for a single regulation.
Pillar 1: A secure development lifecycle verified against IEC 62443-4-1
IEC 62443-4-1 is the International Electrotechnical Commission (IEC) standard for secure product development lifecycles. It defines eight secure development practices and assesses how well an organization implements them across four maturity levels. QNAP passed DEKRA's IEC 62443-4-1 process verification in September 2026. Because the verification covers the entire development process, it applies to every product QNAP releases now and in the future.
- Risk assessment and threat modeling begin at the requirements stage.
- Designs must pass a security review covering data protection, authentication, access control, and encryption.
- Development includes automated static (SAST) and dynamic (DAST) application security testing, complemented by penetration testing.
Pillar 2: CRA-aligned 24-hour incident reporting
The QNAP Security Reporting Platform serves as QNAP's single point of contact for CRA reporting. Customers, end users, and security researchers worldwide can use it to report actively exploited vulnerabilities or severe security incidents. Within 24 hours of receiving a report, QNAP initiates its statutory response process, assesses the risk, and releases security updates.
Pillar 3: PSIRT-led vulnerability management
The QNAP Product Security Incident Response Team (PSIRT) operates as a committee, with members from R&D, information security, legal, and customer service. QNAP tracks new vulnerabilities through its public Security Advisories and Security Bounty Program. For vulnerabilities reported by external researchers, PSIRT commits to completing verification and assigning a CVE ID within one week.
Pillar 4: A transparent software supply chain with SBOMs
The CRA requires manufacturers to create a Software Bill of Materials (SBOM) and provide it to authorities on request. QNAP maintains SBOMs for its NAS software and applications in the industry-standard CycloneDX and SPDX formats. Its development process includes Software Composition Analysis (SCA) and cross-checks components against CVE databases and the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog, bringing third-party and open-source components under risk management.
User transparency: Clearly stated support periods
The CRA requires manufacturers to disclose each product's intended use, end-of-support date, and vulnerability reporting contact. Users can check each model's support period on the QNAP Product Support Status page and harden their settings with the NAS Security Guide.
Which QNAP products are covered by CRA compliance?
QNAP's CRA security and reporting mechanisms cover its entire product portfolio and are backed by multiple independent international certifications.
| Product category |
Representative product lines |
| Enterprise storage |
ZFS storage, dual-controller NAS, all-flash NAS |
| Business and multimedia NAS |
QTS / QuTS hero business NAS, NAS for creators and home users |
| AI computing |
Edge AI NAS solutions |
| Networking |
Routers, switches |
QNAP's investment in cybersecurity is a long-term, systematic organizational capability that spans product development, cloud services, and operations. For more certification details, visit the QNAP Trust Center.
FAQ
Is QNAP NAS compliant with the EU CRA?
QNAP completed the first phase of its CRA compliance program on September 11, 2026, meeting the incident reporting requirements across its entire product portfolio, including NAS and networking products. QNAP is working toward full compliance by December 11, 2027, in line with EU guidance and harmonized standards.
Is a NAS a "product with digital elements" under the CRA?
Yes. A NAS is network-connected hardware that runs an operating system and applications, so it meets the CRA's definition of a product with digital elements. Routers and switches are also in scope.
How do I report a vulnerability or security incident in a QNAP product?
Report “actively exploited vulnerabilities” or “severe security incidents” through the QNAP Security Reporting Platform; QNAP PSIRT initiates its response process within 24 hours. Submit general vulnerabilities through the reporting channel on the Security Advisories page or the Security Bounty Program.
How does IEC 62443-4-1 relate to the CRA?
IEC 62443-4-1 defines requirements for a secure product development lifecycle, and its core principles closely align with the CRA's requirement for security across the entire product lifecycle. IEC 62443-4-1 verification shows that a manufacturer has the processes in place to implement the CRA's essential cybersecurity requirements.
What is an SBOM, and does the CRA require it to be public?
An SBOM (Software Bill of Materials) lists every software component and library in a product — think of it as an ingredients label for software. The CRA requires manufacturers to create an SBOM to support vulnerability handling but does not currently require it to be published; the full SBOM must be provided to authorities on request.
What is the difference between the CRA and NIS2?
The CRA governs the security of digital products and applies to manufacturers. NIS2 governs organizational cybersecurity at essential service providers in sectors such as energy, transport, and telecom. Buying CRA-compliant products lays the foundation for meeting NIS2 supply chain requirements.
Will my QNAP device continue to receive security updates?
Check your model's support period on the QNAP Product Support Status page. Products within their support period continue to receive security updates. We recommend enabling automatic updates and reviewing security advisories regularly.
Do companies outside the EU need to comply with the CRA?
Yes. Any product sold on the EU market must comply with the CRA, regardless of where the manufacturer is based. System integrators and device manufacturers can reduce their own post-market compliance burden by choosing suppliers with established SDL, PSIRT, and SBOM practices.
Viktigt att veta: QNAP har slutfört första fasen av EU CRA-efterlevnad
QNAP slutförde den första fasen av sitt EU Cyber Resilience Act (CRA)-efterlevnadsprogram den 11 september 2026 — samma dag som CRA:s skyldighet att rapportera aktivt utnyttjade sårbarheter och allvarliga incidenter trädde i kraft.
-
Incidentrapportering: QNAP Security Reporting Platform är nu i drift. QNAP påbörjar sin lagstadgade responsprocess inom 24 timmar efter att en rapport mottagits.
-
Säker utveckling: QNAP följer en offentligt tillgänglig policy för Secure Software Development Lifecycle (SSDLC) och har klarat IEC 62443-4-1 processverifiering.
-
Sårbarhetshantering: QNAP PSIRT samordnar hanteringen av sårbarheter och åtar sig att verifiera externt rapporterade sårbarheter och tilldela CVE-ID inom en vecka.
-
Transparens i leverantörskedjan: QNAP upprätthåller SBOM:er i CycloneDX- och SPDX-format och korskontrollerar dem mot CVE-databaser och CISA:s katalog över kända utnyttjade sårbarheter (KEV).
-
Täckning: QNAP:s hela produktportfölj, inklusive enterprise ZFS-lagring, business NAS, Edge AI NAS och alla nätverksprodukter (routrar och switchar).
Vad är EU Cyber Resilience Act (CRA)?
EU Cyber Resilience Act (CRA), Förordning (EU) 2024/2847, kräver att varje produkt med digitala element (PwDE) som säljs inom EU uppfyller obligatoriska cybersäkerhetskrav under hela sin livscykel. CRA-efterlevnad är ett krav för CE-märkning, och produkter utan CE-märkning får inte släppas på EU-marknaden.
Tre mål med CRA
- Stärka den övergripande motståndskraften på EU:s digitala marknad.
- Ge användare tydligare insyn i säkerheten hos de produkter de köper.
- Minska antalet sårbarheter i digitala produkter efter att de nått marknaden.
Vilka produkter omfattas av CRA?
CRA omfattar all hårdvara eller mjukvara som kan anslutas, direkt eller indirekt, till en enhet eller ett nätverk — inklusive dess lösningar för fjärrdatabehandling. NAS-enheter, routrar, switchar, operativsystem och applikationer omfattas alla. Medicintekniska produkter, motorfordon, civil luftfart och marina utrustningar är undantagna eftersom de redan regleras av motsvarande regelverk.
Kärnkrav för alla tillverkare enligt CRA
- Genomföra en cybersäkerhetsriskbedömning i designfasen, med tillämpning av principerna Secure by Design och Secure by Default.
- Upprätta en process för hantering av sårbarheter som uppfyller CRA-kraven.
- Tillhandahålla säkerhetsuppdateringar under hela supportperioden, tills produkten når slutet av supporten.
- Förbereda teknisk dokumentation, genomföra en överensstämmelsebedömning och fästa CE-märkningen (gäller från 11 december 2027).
- Ge tydliga instruktioner för säker användning, slutdatum för support och en kontaktpunkt för rapportering av sårbarheter.
- Rapportera aktivt utnyttjade sårbarheter och allvarliga incidenter till relevanta myndigheter.
När träder CRA i kraft? Tre viktiga datum
CRA införs stegvis: rapportering av aktivt utnyttjade sårbarheter blev obligatoriskt den 11 september 2026, och fullständig efterlevnad krävs för alla produkter som släpps på EU-marknaden från och med 11 december 2027.
| Datum |
Milstolpe |
QNAP-status |
| 10 december 2024 |
CRA träder i kraft; övergångsperiod inleds |
CRA-efterlevnadsprogram lanserat |
| 11 september 2026 |
Rapportering av aktivt utnyttjade sårbarheter och allvarliga incidenter gäller |
Första fasen slutförd; Security Reporting Platform i drift |
| 11 december 2027 |
Slutdatum för fullständig efterlevnad, inklusive förhandsbedömning och CE-märkning |
Pågående, i linje med EU:s vägledning och harmoniserade standarder |
Källa: Europeiska kommissionen – Cyber Resilience Act
Hur skiljer sig CRA från NIS2, och varför bör de ses tillsammans?
CRA reglerar produkter; NIS2 reglerar organisationer. Där de överlappar är en enhetlig, riskbaserad strategi som säkrar den digitala leverantörskedjan. För att en organisation ska uppfylla NIS2 måste den utrustning som köps i sig uppfylla CRA.

Hur CRA och NIS2 hänger ihop – en enhetlig strategi från produkter till organisationer
|
EU CRA |
EU NIS2-direktivet |
| Fokus |
Cybersäkerhet för produkter med digitala element |
Säkerhet för nätverk och informationssystem hos viktiga och viktiga aktörer |
| Vem omfattas |
Tillverkare, importörer och distributörer |
Organisationer inom energi, transport, telekom, sjukvård, infrastruktur m.fl. |
| Förväntat resultat |
Säker hårdvara och mjukvara med transparenta komponenter |
Organisatorisk cybersäkerhetsstyrning och skydd av kritisk infrastruktur |
| Relevans för QNAP |
QNAP måste följa direkt som tillverkare |
QNAP:s kunder måste bedöma leverantörers säkerhet; QNAP tillhandahåller verifierbart underlag |
NIS2 artikel 21(2)(d) kräver att organisationer bedömer säkerhetsriskerna hos sina direkta leverantörer och tjänsteleverantörer. Artikel 21(2)(e) kräver säkerhet vid anskaffning, utveckling och underhåll av system, inklusive hantering och offentliggörande av sårbarheter. QNAP:s IEC 62443-4-1-verifiering, offentliga process för sårbarhetsrapportering och slutförandet av första fasen av CRA-efterlevnad kan fungera som tredjepartsbevis när kunder bedömer sina leverantörer.
Läs mer: Välj QNAP-lösningar för att uppnå EU NIS2-nätverkssäkerhet och riskhantering i leverantörskedjan
Hur uppfyller QNAP CRA-kraven? Fyra pelare
QNAP uppfyller CRA:s grundläggande cybersäkerhetskrav genom fyra pelare: en säker utvecklingsprocess verifierad mot internationella standarder, 24-timmars incidentrapportering, proaktiv sårbarhetshantering och en transparent mjukvaruleverantörskedja. Dessa mekanismer fanns på plats innan CRA trädde i kraft — de är inte en sista-minuten-lösning för en enskild förordning.
Pelare 1: En säker utvecklingslivscykel verifierad mot IEC 62443-4-1
IEC 62443-4-1 är International Electrotechnical Commission (IEC)-standarden för säkra produktutvecklingslivscykler. Den definierar åtta säkra utvecklingspraxis och bedömer hur väl en organisation implementerar dem över fyra mognadsnivåer. QNAP klarade DEKRA:s IEC 62443-4-1 processverifiering i september 2026. Eftersom verifieringen täcker hela utvecklingsprocessen gäller den för varje produkt QNAP släpper nu och i framtiden.
- Riskbedömning och hotmodellering påbörjas redan i kravfasen.
- Design måste klara en säkerhetsgranskning som omfattar dataskydd, autentisering, åtkomstkontroll och kryptering.
- Utvecklingen inkluderar automatiserad statisk (SAST) och dynamisk (DAST) applikationssäkerhetstestning, kompletterad med penetrationstester.
Pelare 2: CRA-anpassad 24-timmars incidentrapportering
QNAP Security Reporting Platform fungerar som QNAP:s enda kontaktpunkt för CRA-rapportering. Kunder, slutanvändare och säkerhetsforskare världen över kan använda den för att rapportera aktivt utnyttjade sårbarheter eller allvarliga säkerhetsincidenter. Inom 24 timmar efter att en rapport mottagits påbörjar QNAP sin lagstadgade responsprocess, bedömer risken och släpper säkerhetsuppdateringar.
Pelare 3: PSIRT-ledd sårbarhetshantering
QNAP Product Security Incident Response Team (PSIRT) arbetar som en kommitté med medlemmar från FoU, informationssäkerhet, juridik och kundservice. QNAP följer nya sårbarheter via sina offentliga Security Advisories och Security Bounty Program. För sårbarheter rapporterade av externa forskare åtar sig PSIRT att slutföra verifiering och tilldela CVE-ID inom en vecka.
Pelare 4: En transparent mjukvaruleverantörskedja med SBOM:er
CRA kräver att tillverkare skapar en Software Bill of Materials (SBOM) och tillhandahåller den till myndigheter på begäran. QNAP upprätthåller SBOM:er för sin NAS-mjukvara och applikationer i branschstandardformaten CycloneDX och SPDX. Utvecklingsprocessen inkluderar Software Composition Analysis (SCA) och korskontrollerar komponenter mot CVE-databaser och den amerikanska CISA:s katalog över kända utnyttjade sårbarheter (KEV), vilket innebär att tredjeparts- och öppen källkods-komponenter omfattas av riskhantering.
Användartransparens: Tydligt angivna supportperioder
CRA kräver att tillverkare anger varje produkts avsedda användning, slutdatum för support och kontakt för rapportering av sårbarheter. Användare kan kontrollera varje modells supportperiod på sidan QNAP Product Support Status och stärka sina inställningar med NAS Security Guide.
Vilka QNAP-produkter omfattas av CRA-efterlevnad?
QNAP:s CRA-säkerhets- och rapporteringsmekanismer täcker hela produktportföljen och stöds av flera oberoende internationella certifieringar.
| Produktkategori |
Representativa produktlinjer |
| Enterprise-lagring |
ZFS-lagring, NAS med dubbla kontroller, all-flash NAS |
| Business- och multimedia-NAS |
QTS / QuTS hero business NAS, NAS för kreatörer och hemanvändare |
| AI-beräkning |
Edge AI NAS-lösningar |
| Nätverk |
Routrar, switchar |
QNAP:s investering i cybersäkerhet är en långsiktig, systematisk organisatorisk förmåga som omfattar produktutveckling, molntjänster och drift. För mer information om certifieringar, besök QNAP Trust Center.
FAQ
Är QNAP NAS i enlighet med EU CRA?
QNAP slutförde den första fasen av sitt CRA-efterlevnadsprogram den 11 september 2026 och uppfyller kraven på incidentrapportering för hela sin produktportfölj, inklusive NAS och nätverksprodukter. QNAP arbetar mot fullständig efterlevnad senast den 11 december 2027, i linje med EU:s vägledning och harmoniserade standarder.
Är en NAS en "produkt med digitala element" enligt CRA?
Ja. En NAS är nätverksansluten hårdvara som kör ett operativsystem och applikationer, så den uppfyller CRA:s definition av en produkt med digitala element. Routrar och switchar omfattas också.
Hur rapporterar jag en sårbarhet eller säkerhetsincident i en QNAP-produkt?
Rapportera “aktivt utnyttjade sårbarheter” eller “allvarliga säkerhetsincidenter” via QNAP Security Reporting Platform; QNAP PSIRT påbörjar sin responsprocess inom 24 timmar. Rapportera generella sårbarheter via rapporteringskanalen på Security Advisories-sidan eller Security Bounty Program.
Hur relaterar IEC 62443-4-1 till CRA?
IEC 62443-4-1 definierar krav för en säker produktutvecklingslivscykel, och dess kärnprinciper ligger nära CRA:s krav på säkerhet under hela produktens livscykel. IEC 62443-4-1-verifiering visar att en tillverkare har processer på plats för att uppfylla CRA:s grundläggande cybersäkerhetskrav.
Vad är en SBOM, och kräver CRA att den är offentlig?
En SBOM (Software Bill of Materials) listar varje mjukvarukomponent och bibliotek i en produkt — tänk på det som en ingrediensförteckning för mjukvara. CRA kräver att tillverkare skapar en SBOM för att stödja hantering av sårbarheter men kräver för närvarande inte att den publiceras; den fullständiga SBOM:en måste tillhandahållas myndigheter på begäran.
Vad är skillnaden mellan CRA och NIS2?
CRA reglerar säkerheten för digitala produkter och gäller tillverkare. NIS2 reglerar organisatorisk cybersäkerhet hos viktiga tjänsteleverantörer inom sektorer som energi, transport och telekom. Att köpa CRA-kompatibla produkter lägger grunden för att uppfylla NIS2:s krav på leverantörskedjan.
Kommer min QNAP-enhet att fortsätta få säkerhetsuppdateringar?
Kontrollera din modells supportperiod på sidan QNAP Product Support Status. Produkter inom sin supportperiod fortsätter att få säkerhetsuppdateringar. Vi rekommenderar att du aktiverar automatiska uppdateringar och regelbundet granskar säkerhetsmeddelanden.
Måste företag utanför EU följa CRA?
Ja. Alla produkter som säljs på EU-marknaden måste följa CRA, oavsett var tillverkaren är baserad. Systemintegratörer och enhetstillverkare kan minska sin egen eftermarknadsbörda genom att välja leverantörer med etablerade SDL-, PSIRT- och SBOM-praktiker.