EU Cyber Resilience Act
EU Cyber Resilience Act (CRA)
- Quality Certificates & Policies
- Quality Documents
- Reliability Reports
- Failure Analysis
- EU Cyber Resilience Act
Supporting Customers through the CRA Journey
The EU Cyber Resilience Act (CRA) introduces cybersecurity requirements for products with digital elements made available on the European Union market.
MPS is actively preparing for the CRA, and is monitoring the development of related standards and implementation guidance. We are working to align our product security practices with applicable CRA requirements and to provide customers with the information and support they need for their own CRA compliance activities.
What Is the CRA?
The CRA, Regulation (EU) 2024/2847, establishes cybersecurity requirements throughout the lifecycle of products with digital elements. It covers areas including secure product development, cybersecurity risk management, vulnerability handling, security maintenance, technical documentation, and conformity assessment.
The CRA entered into force in December 2024. Vulnerability and incident reporting obligations apply from September 11, 2026, and the full CRA requirements apply from December 11, 2027.
MPS Commitment to CRA
MPS is committed to supporting applicable CRA requirements and helping customers build secure and resilient products. Our CRA preparation focuses on product security, vulnerability management, lifecycle support, and customer documentation. MPS will:
- Monitor CRA requirements, implementation guidance, and relevant standards.
- Consider applicable cybersecurity requirements throughout product development and lifecycle activities.
- Assess and address relevant product security risks and vulnerabilities.
- Maintain a defined process for receiving and responding to product security vulnerability reports.
- Provide relevant security and technical information to support customer CRA activities.
- Continue to strengthen product security practices as CRA requirements and standards evolve.
Security by Design
MPS considers product security to be part of product development. Where applicable, cybersecurity risks and security requirements are considered during product definition, design, and verification.
Our goal is to help reduce product security risks and provide customers with appropriate information to support secure integration of MPS products into their systems.
Vulnerability Management
Vulnerability handling is an important part of the CRA. MPS maintains a Product Security Incident Response Team (PSIRT) process for receiving, evaluating, and responding to potential security vulnerabilities involving MPS products.
Reported vulnerabilities are reviewed to determine their validity, potential impact, and affected products. When appropriate, MPS works to identify mitigation or corrective actions and communicate relevant information to affected customers.
Report a potential MPS product security vulnerability: PSIRT@monolithicpower.com
Lifecycle Security Support
The CRA requires cybersecurity to be considered beyond initial product development. MPS is working to support applicable product security responsibilities throughout the product lifecycle, including vulnerability monitoring, remediation support and relevant customer communication.
Product-specific support and security information may vary. Customers should refer to applicable MPS product documentation or contact MPS for additional information.
Supporting Customer CRA Compliance
MPS products are used as components in a wide range of customer products and systems. Under the CRA, manufacturers of final products with digital elements are responsible for assessing and demonstrating the conformity of their final products.
MPS supports customers by providing relevant product and security information, as applicable, to help customers evaluate MPS products as part of their cybersecurity risk assessment, technical documentation, and vulnerability-management activities.
Depending on the product, MPS support may include:
- Product and technical documentation
- Security-related product information
- Integration and configuration information
- Vulnerability information and mitigation guidance
- Applicable security or compliance documentation
- Product lifecycle and support information
CRA Timeline
- December 10, 2024 – CRA entered into force
- September 11, 2026 – Vulnerability and incident reporting obligations apply
- December 11, 2027 – Full CRA requirements apply
Product Security Incident Response Team (PSIRT)
MPS encourages customers and security researchers to report potential product security vulnerabilities to our Product Security Incident Response Team.
The MPS PSIRT coordinates the assessment of reported product security issues and works with relevant teams to determine potential impact, mitigation, and customer communication.
Contact MPS PSIRT: PSIRT@monolithicpower.com
Learn More
MPS continues to monitor CRA developments, and will update product security resources as implementation guidance and relevant standards evolve.
For product-specific questions related to CRA, please contact your MPS representative. For potential product security vulnerabilities, contact PSIRT@monolithicpower.com.
直接登录
创建新帐号