測試服務技術測試諮詢與驗證
Industry
EU CRAFDA & MDR支付與金融新聞關於我們
EN繁中
聯絡我們
Regulation (EU) 2024/2847 · CE Marking

EU CYBER RESILIENCE ACT

One-stop service from gap analysis and testing to certification, ensuring your products connect seamlessly with global standards.

Applicability check

Four questions to define if you need CRA.

Step 1

Is the product sold commercially in the EU market?

Step 2

Does the product contain “digital elements”?

Step 3

Does the product exchange data with external devices or networks?

Step 4

Does the product fall under an official exclusion?

CRA self-assessment

How ready are you for the CRA? Find out in three minutes.

This CRA self-assessment helps manufacturers quickly evaluate cybersecurity readiness and identify compliance gaps. Please note: results are for initial reference only and do not constitute legal advice.

0 / 52 0 / 26 answered

Status: —

Answer the questions above to see where you stand.

Get a lab readiness assessment →

Indicative only, not legal advice. The binding text is Regulation (EU) 2024/2847.

Next step

不確定從何著手?參加 CRA 教育訓練課程。

開放報名
實體課程

EU CRA 法規動態

2026 年 9 月 18 日 · 14:00 · 台北

CRA 通報義務已生效,全面適用進入倒數。Applus+ Laboratories 資安事業處總監 Jose Ruiz Gualda 親自來台,分享銷歐產品符合性評估第一線實務,攜手安合規律解析台灣企業下一步。9/18 台北實體場,名額有限。

適合對象:決策者 · 外銷業務主管 · 法遵人員
更多詳情 →報名 →EU CRA 講座海報 — 2026 年 9 月 18 日・台北
FAQ

CRA 常見問題

CRA 是否適用於已上市的產品?

基本要求適用於 2027 年 12 月 11 日起投放於歐盟市場的產品。不過,既有產品若經實質性修改,可能被視為重新投放市場;而自 2026 年 9 月 11 日起的通報義務,無論產品何時出貨,製造商均須遵循。

我的產品是否排除於 CRA 適用範圍之外?

僅在其他歐盟法規已涵蓋相同風險時才排除:醫療器材(MDR / IVDR)、機動車輛、經驗證的航空產品、船舶設備,以及專為國家安全或國防用途製造的產品。其餘含數位元件的產品一律預設納入適用範圍。

我需要公告機構(Notified Body)嗎?

多數情況下不需要:約 90% 的產品屬於一般類(default),可依基本要求進行自我評鑑——尤其是在採用 EN 18031 等調和標準時。例外為重要類(important)第 I 級(在調和標準適用之前)、第 II 級與關鍵類(critical)產品。分類是任何 CRA 專案的第一步。

CRA 與無線電設備指令(RED)有何不同?

RED 適用於特定的無線電設備類別,且已經施行;CRA 則涵蓋所有含數位元件的產品,適用範圍廣得多。若貴公司已完成 RED 資安符合性程序,那些證據並不會白費——它正是 CRA 技術文件的基礎。

CRA 對 SBOM 有哪些要求?開源元件是否也包含在內?

貴公司的 SBOM 必須為機器可讀格式——SPDX 或 CycloneDX,而非人工彙整的文件。該格式與 EUVD 的 API 相符,因此可將元件與歐盟漏洞資料庫(EU Vulnerability Database)的項目交叉比對,標記出遭積極利用的漏洞。在商業活動之外提供的開源軟體不在適用範圍內;一旦隨貴公司的商業產品出貨,就必須納入 SBOM 與漏洞處理流程。