CRA Statement

PSIRT Policy
PSIRT Policy

Zyxel EU Cyber Resilience Act and Product Security Statement

Product security is an integral part of how Zyxel designs, develops, maintains, and supports its products.

Zyxel is aligning its product security processes and governance framework with the requirements of the European Union Cyber Resilience Act (“CRA”) applicable to its products and activities. This includes preparing to meet the vulnerability and incident reporting obligations under Article 14 of the CRA, which apply from 11 September 2026.

This statement describes Zyxel’s general product security approach. It is not a product-specific declaration of conformity. The applicability of CRA requirements and the support period for a particular product depend on the relevant product information and applicable regulatory requirements.

Scope and Applicability


This statement provides a general overview of Zyxel's product security practices. Product security features, support arrangements, security update processes, and lifecycle commitments may vary by product and are described in the applicable product documentation, contractual terms, and regulatory requirements. For customized or project-specific products, applicable security and support commitments are set out in the relevant contract and associated project documentation.

Secure by Design and Default


Zyxel addresses security throughout the product life cycle, from design and development through maintenance and support.

Zyxel’s product security practices include secure default configurations, risk-based access controls, the reduction of unnecessary attack surfaces, and mechanisms for the secure delivery of security updates.

Risk-Based Vulnerability Management


Zyxel evaluates vulnerabilities using a risk-based methodology that considers factors such as active exploitation, technical severity, product exposure, and potential impact on customers and users.

Zyxel uses software bills of materials (“SBOMs”) and other software component information to facilitate identification of affected products and support vulnerability assessment, prioritization, and remediation activities.

Vulnerability and Incident Reporting


Zyxel maintains processes to assess actively exploited vulnerabilities and severe incidents affecting product security. Zyxel also maintains procedures intended to support compliance with applicable regulatory reporting and notification requirements, including those arising under Article 14 of the CRA.

Product Security Support


During defined support periods for applicable products, Zyxel provides vulnerability management, security advisories, and security updates.

Where technically feasible and proportionate, security updates are made available independently of feature or functional updates.

Product-specific support periods and lifecycle information are available through Zyxel’s End-of-Life page.

Zyxel periodically reviews and updates its product security practices to reflect evolving CRA requirements, harmonized standards, regulatory guidance, and industry best practices.

Reporting a Security Vulnerability


Customers, partners, and security researchers who identify a potential security vulnerability in a Zyxel product should report it to the Zyxel’s Product Security Incident Response Team (“PSIRT”) at security@zyxel.com.tw.

For information regarding vulnerability reporting procedures, coordinated vulnerability disclosure, and published security advisories, please refer to Zyxel‘s Security Advisories.

CRA-Related Enquiries


For enquiries concerning CRA-related regulatory or procedural matters, please contact Zyxel’s Product Compliance Management (“PCM”) at pcm-cra@zyxel.com.tw.

Potential product security vulnerabilities should be reported to PSIRT rather than to the PCM contact address.