Zyxel Communications EU Cyber Resilience Act and Product Security Statement
Product security is an integral part of how Zyxel Communications Corp. (“Zyxel”) designs, develops, maintains, and supports its products.
Zyxel is aligning its product security processes and governance framework with the requirements of the European Union Cyber Resilience Act (“CRA”) applicable to its products and activities. This includes preparing to meet the vulnerability and incident reporting obligations under Article 14 of the CRA, which apply from 11 September 2026.
This statement describes Zyxel’s general product security approach. It is not a product-specific declaration of conformity. The applicability of CRA requirements and the support period for a particular product depend on the relevant product information and applicable regulatory requirements.
Scope and applicability
Zyxel offers generally available products as well as products developed or customized for specific customer or service provider projects under contractual arrangements.
Product security measures, support arrangements, security update processes, and lifecycle information may vary depending on the product category, intended use, contractual commitments, and applicable regulatory requirements.
For generally available products, product-specific security and support information is provided through the applicable product documentation and support channels. For products supplied under customized or project-specific arrangements, security and support commitments are defined in the applicable contract and associated project documentation, subject to applicable regulatory requirements.
This statement provides a general overview of Zyxel’s product security practices. Product-specific security obligations, support periods, and related security commitments are determined by the relevant product documentation, contractual arrangements, and applicable regulatory requirements.
Secure by design and default
Zyxel addresses security throughout the product life cycle, from design and development through maintenance and support.
Zyxel’s product security practices include secure default configurations, risk-based access controls, the reduction of unnecessary attack surfaces, and mechanisms for the secure delivery of security updates.
Risk-based vulnerability management
Zyxel evaluates vulnerabilities using a risk-based methodology that considers factors such as active exploitation, technical severity, product exposure, and potential impact on customers and users.
Zyxel uses software bills of materials (“SBOMs”) and other software component information to facilitate identification of affected products and support vulnerability assessment, prioritization, and remediation activities.
Vulnerability and incident reporting
Zyxel maintains processes to assess actively exploited vulnerabilities and severe incidents affecting product security. Zyxel also maintains procedures intended to support compliance with applicable regulatory reporting and notification requirements, including those arising under Article 14 of the CRA.
Product security support
During defined support periods for applicable products, Zyxel provides vulnerability management, security advisories, and security updates.
Where technically feasible and proportionate, security updates are made available independently of feature or functional updates.
Product-specific support periods and lifecycle information are available through Zyxel's End of life policy.
Zyxel periodically reviews and updates its product security practices to reflect evolving CRA requirements, harmonized standards, regulatory guidance, and industry best practices.
Reporting a security vulnerability
Customers, partners, and security researchers who identify a potential security vulnerability in a Zyxel product should report it to the Zyxel's Product Security Incident Response Team ("PSIRT") at security@zyxel.com.tw.
For information regarding vulnerability reporting procedures, coordinated vulnerability disclosure, and published security advisories, please refer to Zyxel's security advisories portal.
CRA-related enquiries
For enquiries concerning CRA-related regulatory or procedural matters, please contact Zyxel's Product Compliance Management ("PCM") at pcm-cra@zyxel.com.tw.
Potential product security vulnerabilities should be reported to PSIRT rather than to the PCM contact address.