## Slide 1

![The slide features the ADLINK logo and the text 'LEADING EDGE COMPUTING' in the top right corner. The main title, displayed in white text against a dark red background, reads 'ADLINK Cybersecurity Strategy'. In the bottom left corner, smaller white text reads 'ADLINK | Leading Edge Computing'. The background image depicts an industrial facility with large storage tanks and smokestacks situated on water, overlaid with a glowing white digital network mesh and faint circular graphics in the sky.](engineering/regulations/cra/.adlink-cyber-security-customer/slide-001.jpg)

## Slide 2

![This slide is titled **Cyber Resilience Act (CRA)** and provides an overview of the act's scope, timeline, and penalties.\n\n**Top Left: Definitions and Scope**\n*   **Product of Digital Element:** 'Any hardware or software product whose intended use involves data processing or network connectivity'\n*   **In Scope:**\n    *   'Hardware: laptops, mobile phones, routers, etc.'\n    *   'Software: computer applications, video games, etc.'\n    *   'Remote data processing solutions'\n*   **Not in Scope:**\n    *   'Non-commercial: non-profit open-source software'\n    *   'Services: websites, cloud services, or software-as-a-service (SaaS)'\n    *   'Specific regulated products: including medical devices, automobiles, aviation equipment, and maritime equipment'\n\n**Top Center: Introduction**\n*   'The European Parliament passed the Cyber Resilience Act in 2023, which entered into force on December 10, 2024.'\n\n**Middle: Timeline**\nA timeline displays key dates across the years 2024, 2025, 2026, and 2027:\n*   **March 2024:** 'Validation by the European Parliament'\n*   **December 10th:** 'The CRA enters into force'\n*   **April 11th:** 'Notification of national conformity assessment bodies'\n*   **September 11th:** 'Reporting obligations (actively exploited vulnerabilities & severe incidents)'\n*   **December 11th:** 'Mandatory compliance with the CRA'\n\n**Center Text:**\n*   'During this period, collaborate with ADLINK and our strategic certification partners for self-preparation for CRA.'\n\n**Bottom: Risks of non-compliance**\nTwo boxes detail fines:\n*   **15,000,000€:** 'fine in case of failure to meet cybersecurity requirements'\n*   **5,000,000€:** 'fines in case of inaccurate information provided to authorities'](engineering/regulations/cra/.adlink-cyber-security-customer/slide-002.jpg)

## Slide 3

![**Cyber Resilience Act (CRA) Alignment with IEC 62443 Standards**\nIEC 62443-4 standards provide a strong framework for CRA compliance, especially for industrial and critical infrastructure products.\n\n**CRA**\nEU regulation mandating essential cybersecurity requirements for digital products throughout their lifecycle.\n**Focus**\nTargets hardware, software, and related services with a focus on secure design, vulnerability management, and lifecycle security..\n**Key Goals**\n• Reduce cybersecurity risks.\n• Standardize security requirements across the EU.\n\n**IEC 62443**\nA globally recognized standard for industrial automation and control system (IACS) cybersecurity.\n**Focus**\nIndustrial control system (ICS) components and their secure development practices.\n**Key Goals**\n• Security by Design\n• Security features\n• Risk Assessment\n\n**Cyber Resilience Act Requirements Standards Mapping**\nSecurity requirements relating to the properties of products with digital elements Vulnerability handling requirements\n\n**Table:**\nHeaders: Security requirements relating to the properties of products with digital elements (1, 2, 3a, 3b, 3c, 3d, 3e, 3f, 3g, 3h, 3i, 3j, 3k) | Vulnerability handling requirements (1, 2, 3, 4, 5, 6, 7, 8)\n\nRow 1: EN IEC 62443-3-2 | X (under 1) | X (under 3i)\nRow 2: EN IEC 62443-4-1 | X (under 1) | X (under 2) | X (under Vuln 3) | X (under Vuln 4) | X (under Vuln 6) | X (under Vuln 7) | X (under Vuln 8)\nRow 3: EN IEC 62443-4-2 | X (under 3b) | X (under 3c) | X (under 3d) | X (under 3f) | X (under 3h) | X (under 3j) | X (under 3k)](engineering/regulations/cra/.adlink-cyber-security-customer/slide-003.jpg)

## Slide 4

![**Title:** Cyber Resilience Act (CRA) Alignment with IEC 62443 Standards\n\n**Left Diagram (Concentric Circles):**\n*   1.General\n*   2. Policy & Procedure\n*   3. System\n*   4. Component\n*   Label below diagram: Industrial Automation & Control System\n\n**Middle Column Text:**\nThe Scope of IEC 62443 standard\n*   1-1 : Terminology and concepts\n*   1-2 : Master glossary\n*   1-3 : System security compliance metrics\n*   1-4 : IACS security lifecycle and use-case\n*   2-1: Requirements for an IACS security management system\n*   2-2: Implementation guidance\n*   2-3: Patch management\n*   2-4: Installation & maintenance\n*   Apply to Asset Owner\n*   3-1: Security technologies for IACS\n*   3-2: Security levels for zones and conduits\n*   3-3: System security requirements and levels\n*   Apply to System Integrator\n*   4-1: Product development requirements\n*   4-2: Technical security requirement for IACS components\n*   Apply to Component Supplier\n*   ADLINK (Logo)\n\n**Right Box (Red Background):**\n2 key standards for cybersecurity compliance:\n*   IEC 62443-4-1\n    *   Governs secure development processes within organizations, directly supporting CRA's horizontal requirements.\n*   IEC 62443-4-2\n    *   Ensures individual product certification, addressing CRA's vertical requirements by certifying cybersecurity features.](engineering/regulations/cra/.adlink-cyber-security-customer/slide-004.jpg)

## Slide 5

![**Title:**\nPlatform Security – IEC 62443 foundation\n\n**Layer 1:**\n*   **Label:** Secure Environment\n*   **Section:** Ubuntu Security\n    *   Basic Security setup\n    *   Network security\n    *   Advanced User Management\n    *   Application Security\n    *   Data Encryption\n*   **Section:** Windows Security\n    *   Trusted boot\n    *   Windows security settings\n    *   BitLocker\n    *   Personal Data Encryption\n    *   Windows security baselines\n    *   Microsoft Defender SmartScreen\n    *   Windows Firewall\n\n**Layer 2:**\n*   **Label:** Operating System\n*   **Content:** Ubuntu / Debian eLxr (WindRiver)\n*   **Content:** Windows\n\n**Layer 3:**\n*   **Label:** BIOS Bootloader\n*   **Content:** Secure Boot\n*   **Content:** Secure Boot, Boot Guard, Secure Capsule Update\n\n**Layer 4:**\n*   **Label:** Hardware\n*   **Content:** ARM (MTK, Qualcomm)\n*   **Content:** X86\n*   **Content:** Root of Trust\n\n**Footer:**\n*Select operating system without long term support will face problem for the security maintenance (Like Yocto)](engineering/regulations/cra/.adlink-cyber-security-customer/slide-005.jpg)

## Slide 6

![**Title:** Certification and CRA Updates\n\n**Top Section (Timeline & Standards):**\n\n*   **Left Header:** IEC 62443-4-1\n    *   **Target:** Build the ADLINK Security Development Process\n    *   **Scope:** ADLINK\n*   **Right Header:** IEC 62443-4-2\n    *   **Target:** Develop the Secure Product\n    *   **Scope:** ODM products require the certification\n\n**Timeline Boxes (Left to Right):**\n1.  Gap Analysis\n2.  Training\n3.  Integrate Secure Development Process\n4.  Internal Audit/ Improvement\n5.  External Audit\n6.  Consulting Services / Training\n7.  Pre-Assessment Security Test Improvement\n8.  Assessment Compliance Checklist\n9.  External Audit\n\n**Timeline Dates (Bottom Red Bar, Left to Right):**\n2024 Sep, Oct, Nov, 2025 Jan, Aug, Oct, Nov, Dec, 2026 Feb, Mar\n\n**Middle Section:**\n*   **Logo:** ADLINK\n*   **Timeline Bar:** 2024 Oct (Left) — 2027 H2 (Right)\n*   **Center Text:** EU CRA\n*   **Left Box:** EU adopts cyber resilience act\n*   **Right Box:** Regulation enforcement\n\n**Bottom Section (Updates):**\n\n**Certification Updates**\n*   IEC 62443-4-1 process security underway.\n*   Gap analysis completed; standard training ongoing -) refine DEV process.\n*   Planning for IEC 62443-4-2 (product security).\n\n**CRA Updates**\n*   Monitoring CRA development; mandatory horizontal requirements by 2026 and vertical by 2027.\n*   Efforts: Ongoing gap analysis between IEC 62443 and CRA standards.](engineering/regulations/cra/.adlink-cyber-security-customer/slide-006.jpg)

## Slide 7

![The slide features a split layout with text on the left and a certificate image on the right.\n\n**Left Side Text:**\n**Security Starts at the Source**\n**— with IEC 62443-4-1**\n\nADLINK has achieved IEC 62443-4-1 certification, a globally recognized cybersecurity standard for industrial control systems. This milestone confirms that Secure-by-Design is embedded across our Secure Product Development Lifecycle (SDL)—ensuring that our edge computing solutions are built for resilience, reliability, and long-term protection.\n\n**Right Side (Certificate Image):**\n**Top Header:** IEC | IECCEE | Ref. Certif. No. FR_Cyber10248\n**Blue Banner:** IEC System of Conformity Assessment Schemes for Electrotechnical Equipment and Components (IECEE)\n**Title:** Certificate of Conformity – Industrial Cyber Security Capability\n\n**Table Content:**\n*   **Type:** Process Capability Assessment\n*   **Name and address of the applicant:** ADLINK Technology, Inc No. 66, Huaya 1st Rd., Guishan Dist, 333411 Taoyuan City TAIWAN\n*   **Certificate Coverage (including Version):** ADLINK Product Security Development Lifecycle Process V 1.0\n*   **Standard:** IEC 62443-4-1:2018\n*   **Requirements Assessed:** Security management (13,0,13) Specification of security requirements (5,0,5) Secure by design (4,0,4) Secure implementation (2,0,2) Security verification and validation testing (5,0,5) Management of security-related issues (8,0,8) Security update management (5,0,5) Security guidelines (7,0,7) Maturity Level: ML2\n*   **Additional information (if necessary may also be reported on page 2):** / Additional Information on page 2\n*   **As shown in the Test Report Ref. No. which forms part of this Certificate:** CYT-BCCD-WTW-P24060697 001\n\n**Footer Text:** This Certificate of Conformity, issued by the National Certification Body, certifies that the above have been found to be in conformity with the requirements of the Industrial Cyber Security Capability Scheme (IECEE OD-2061) as it relates to the claims declared by the Applicant.\n\n**Bottom Section:**\nLABORATOIRE CENTRAL DES INDUSTRIES ELECTRIQUES - LCIE 33 avenue du Général Leclerc 92290 Fontenay-aux-Roses, FRANCE www.lcie.fr\n**Date:** 25/11/2025\n**Signature:** (Signed) JCLEN GAUTHIER Certification Officer](engineering/regulations/cra/.adlink-cyber-security-customer/slide-007.jpg)

## Slide 8

![The slide is titled **'Integrate Secure Software Development Life Cycle into ADLINK PLC'**.\n\nIt displays a process diagram organized into four horizontal rows labeled on the left: **Stage**, **AS-IS**, **TO-BE**, and **Automation**.\n\n**Row 1 (Stage):**\nA sequence of arrows displaying the lifecycle phases:\n*   Project Init\n*   Product Requirement\n*   Design\n*   Implementation\n*   Validation\n*   Maintenance\n\n**Row 2 (AS-IS):**\nA yellow band containing text aligned with the stages above:\n*   Functional Requirement\n*   HW/SW Function Implementaion\n*   Functional & IntegrationTest\n*   Ad-Hoc response\n\n**Row 3 (TO-BE):**\nThis section lists security practices and tools:\n*   Security Requirement\n*   Threat Modelling\n*   Seurity Design\n*   Secure Code Scanning\n*   sonarqube\n*   Source Code Review (next to an 'AI' icon)\n*   Software BOM SBQM\n*   Vulnerability Scan\n*   OSV Scanner\n*   Fuzzing Testing\n*   Vulnerability Testing\n*   Penetration Testing\n*   Incident Response\n*   Vulnerability Monitoring OpenCVE\n*   Vulnerability Management Jira Confluence\n\n**Row 4 (Automation):**\nA flowchart at the bottom showing:\n*   Code Analysis\n*   SBOM\n*   Vulnerability Scan\n*   CVE monitor](engineering/regulations/cra/.adlink-cyber-security-customer/slide-008.jpg)

## Slide 9

![The slide is titled '**How ADLINK Support Comply with CRA**' with the subtitle '**Support Customers IEC 62443-4-2 Certification**'.\n\nIt presents a flowchart comparing **ADLINK** and **Customers**:\n\n*   **ADLINK** provides two orange boxes:\n    *   '**IEC 62443-4-2 implementation**'\n    *   '**IEC 62443-4-1 compliance documents**'\n\n*   **Customers** section involves:\n    *   A central blue box: '**Integrated IEC 62443-4 documents**'\n    *   A green box: '**Certification Body**'\n    *   Two dark blue ovals feeding into the central blue box:\n        *   '**Customer’ s SW (IEC 62443-4-2)**'\n        *   '**3rd Party SW (IEC 62443-4-2)**'\n\nThe diagram shows arrows indicating that ADLINK's implementation and compliance documents, along with the customer and third-party software documents, combine into the '**Integrated IEC 62443-4 documents**,' which then lead to the '**Certification Body**'.](engineering/regulations/cra/.adlink-cyber-security-customer/slide-009.jpg)

## Slide 10

![The slide is titled '**How ADLINK Support the Cybersecurity**' with the subtitle '**Continuously Monitor and Report the Vulnerability**'.\n\nThe diagram features a central box with a shield icon labeled '**Secure office**'. This box is connected to surrounding elements via arrows:\n\n*   **Top:** A box with a Jira logo labeled '**Jira**' and '**Issue Tracking**'.\n*   **Right:**\n    *   A box with a purple logo labeled '**OpenCVE**' and '**CVE Database**'.\n    *   A box containing logos for 'intel', 'NXP', 'Microsoft', and 'ami', labeled '**Vendor Report**'.\n    *   Text between the right-side boxes reads '**Report Security Incident**'.\n    *   A box with an envelope icon labeled '**Customer Report**'.\n*   **Bottom:** A box with a blue 'Ai' icon labeled '**Security Report Update**'.\n*   **Left:**\n    *   A box with a red logo labeled '**OSV Scanner**' and '**Vulnerability Scan**'.\n    *   Below that, a box with a red document icon labeled '**SBOM**' and '**Product SBOM database**', with an arrow pointing from 'SBOM' to 'OSV Scanner'.](engineering/regulations/cra/.adlink-cyber-security-customer/slide-010.jpg)

## Slide 11

![**Title:** Vulnerability Management\n\n**Introduction:** To meet CRA obligations, a systematic process is needed:\n\n**List:**\n**1 Vulnerability Detection**\n*   Continuous monitoring of CVE/NVD/OSV feeds.\n*   Review the Errata or platform update report from vendor\n*   Customer report\n\n**2 Impacted product identification**\n*   Automated vulnerability scans integrated with CI/CD.\n\n**3 Assessment & Prioritization**\n*   Risk scoring (CVSS/EPSS) with mapping to product impact.\n*   Maintain a central Vulnerability Tracking Register (JIRA)\n\n**4 Remediation & Patching**\n*   Define patch release\n*   Ensure EOL products have clear vulnerability disclosure statements.\n\n**5 Communication & Transparency**\n*   Provide VEX (Vulnerability Exploitability eXchange) statements\n*   Publish security advisories and customer notification channels (Web or Email).\n\n**Diagram Components:**\n*   **Top Box (labeled 4):** Vulnerability Fixing\n*   **Middle Top Box:** Jira Issue Tracking\n*   **Right Box (labeled 1):** OpenCVE CVE Database\n*   **Center Box (labeled 3):** Secure office\n*   **Left Box (labeled 2):** Product database\n*   **Bottom Box (labeled 5):** Security Report Update\n*   **Right Middle Box:** Contains logos for Intel, NXP, Microsoft, and AAMI with text 'Vendor Report'.\n*   **Right Bottom Box:** Contains an envelope icon and text 'Customer Report'.\n*   **Connecting Text:** 'Report Security Incident' pointing to the center box.](engineering/regulations/cra/.adlink-cyber-security-customer/slide-011.jpg)

## Slide 12

![ADLINK Deliverables to Support EU CRA\n\nDeliverables\n\nSecurity Development Lifecycle Documentation\nPrepare technical documentation for CRA conformity\n(risk assessments, design reviews, patch records, and vulnerability handling evidence).\n\nSBOM & Vulnerability Reporting\nEnsure every released product version includes a Software Bill of Materials (SBOM) and associated vulnerability reports.\nMaintain traceability between SBOM, product versions, and security advisories.\n\nSecurity Updates & VEX Statements\nProvide timely security patches and issue VEX (Vulnerability Exploitability eXchange) statements to clarify exploitability status.](engineering/regulations/cra/.adlink-cyber-security-customer/slide-012.jpg)

## Slide 13

![This slide features a graphic design resembling interlocking puzzle pieces to highlight three key areas regarding ADLINK's security initiatives, alongside a central value proposition.\n\n**Top Left Puzzle Piece:**\n*   **Logo:** A shield icon with text 'Compliance IEC 62443'\n*   **Heading:** 'Compliance-Driven Design & Certification'\n*   **Text:** 'ADLINK is on track for IEC 62443-4-1 certification, showcasing secure design practices, full security lifecycle management, and effective vulnerability response to reduce risks.'\n\n**Top Right Puzzle Piece:**\n*   **Logos:** 'arm', the Ubuntu logo, and 'FOUNTRIES.IO'\n*   **Heading:** 'Partnership with Platform Experts for Cybersecurity'\n*   **Text:** 'ADLINK collaborate with partners across CPU, BIOS, and OS to stay ahead of regulatory changes and implement advanced cybersecurity mechanisms.'\n\n**Bottom Right Puzzle Piece:**\n*   **Logos:** 'BUREAU VERITAS' and 'DELTA'\n*   **Heading:** 'Accelerating Certification with Partnerships'\n*   **Text:** 'ADLINK has partnered with Bureau Veritas and Delta Cybersecurity Lab to provide customers with comprehensive cybersecurity testing and certification services, ensuring compliance with international standards and enhancing product security.'\n\n**Bottom Left Text Block:**\n*   **Large Heading:** 'Why ADLINK?'\n*   **Text:** 'ADLINK provides fast and reliable solutions to enhance security and accelerate market deployment.'](engineering/regulations/cra/.adlink-cyber-security-customer/slide-013.jpg)

## Slide 14

![The slide features a solid red background with the following text and elements:\n\n**Top Left:**\n'Backup'\n\n**Center:**\nA repeating geometric pattern of white triangles.\n\n**Bottom Left:**\n'ADLINK Technology, Inc.'\n'No. 66, Huaya 1st Rd., Guishan Dist., Taoyuan City 333411, Taiwan'\n\n**Bottom Center:**\n'Tel: +886-3-216-5088'\n'Fax: +886-3-328-5706'\n\n**Bottom Right:**\nSocial media icons (Twitter, Facebook, YouTube, LinkedIn) followed by 'www.adlinktech.com'](engineering/regulations/cra/.adlink-cyber-security-customer/slide-014.jpg)

[🔗 Link to the original document](engineering/regulations/cra/.adlink-cyber-security-customer/adlink-cyber-security-customer.pdf)
