GD32 MCU Builds Full-Lifecycle Security Capabilities to Help Customers Address EU CRA Compliance

2026-10-08

As the European Union's Cyber Resilience Act (CRA) moves toward implementation, cybersecurity is becoming an increasingly important requirement for digital products entering the EU market.

The CRA officially entered into force in December 2024, with mandatory requirements taking effect from December 2027. Starting in September 2026, vulnerability reporting and handling obligations have taken effect ahead of the broader requirements. The regulation introduces cybersecurity requirements covering the entire lifecycle of products with digital elements, from design and development to market placement, operation, and end-of-life, and establishes obligations for vulnerability response, reporting, and disclosure.

To meet these evolving requirements, GigaDevice has established a practical and verifiable CRA compliance framework for its GD32 MCU portfolio. GigaDevice adopts the Security Evaluation Standard for IoT Platforms (SESIP) methodology to evaluate the security capabilities of GD32 MCUs. These capabilities can help OEM and ODM customers more efficiently address the component security requirements of IEC 62443-4-2 for industrial automation and control systems.

For customers in critical application areas such as industrial control, this provides technical support aligned with internationally recognized component security standards, offering tangible and auditable measures for addressing the EU CRA, rather than relying solely on descriptions of security features.

Full-Lifecycle Approach Helps Customers Prepare for the CRA

GD32 MCU products fall under the scope of the CRA. GigaDevice has incorporated CRA requirements throughout the entire lifecycle of GD32 MCU products, covering design, manufacturing, and maintenance including vulnerability management.

Gigadevice continues to manage key areas including vulnerability response, long-term support, SBOM, security certification, and customer technical support.

Representative GD32 MCU products, such as GD32F50x, GD32H7, and GD32W51x, are currently undergoing compliance assessment and documentation update in collaboration with third-party compliance organizations. The compliance readiness covers the full product lifecycle, including product development, release, operation and maintenance, sales, and end-of-life management. For the GD32F50x series, the compliance documentation package is planned for completion by the end of 2026. Subsequent assessments and supporting compliance measures will be progressively extended to other GD32 MCU series within the scope of CRA compliance, with further integration of compliance processes into the product development workflow.

At the same time, GD32 MCUs provide at least 10 years of security update support, helping ensure continuous security protection throughout the long-term operation of customers' products.

PSIRT + SBOM: Strengthening Product Security

Product launch does not mark the end of cybersecurity efforts. In response to the CRA's requirements for vulnerability management and security updates, GigaDevice has established a Product Security Incident Response Team (PSIRT) to receive and respond to potential security vulnerability reports related to GigaDevice semiconductor products.

GD32 MCUs have established a comprehensive vulnerability management process covering vulnerability discovery and early warning, assessment and classification, incident response, remediation and verification, as well as disclosure and distribution. GigaDevice continues to enhance its product security response capabilities across organizational, procedural, and technical dimensions.

For software supply chain security, GD32 MCUs provide Software Bill of Materials (SBOM) documentation based on customer requirements. The solution supports two widely used formats, CycloneDX v1.5 and SPDX v2.3, covering firmware dependencies, third-party components, and open-source license declarations. This helps customers reduce duplicated assessment work and prepare more efficiently for their own CRA compliance requirements. Customers can contact the GigaDevice sales or FAE team for further information.

Advancing International Security Certifications to Provide Reusable Security Capabilities

In addition to building its CRA compliance framework, GigaDevice continues to pursue international security certifications and assessments to further strengthen the security capabilities of GD32 products.

The GD32F50x series has officially obtained SESIP Level 2 certification. The relevant evaluation results can serve as an important reference for customers pursuing industrial security certifications such as IEC 62443, helping reduce duplicated assessment efforts, shorten certification timelines, and lower associated costs.

In addition, GD32 MCUs have obtained relevant certifications or assessment results in areas including PSA, RED, ISO 21434, and TISAX, covering different aspects such as product-level security, vehicle cybersecurity, and automotive information security management systems. These achievements provide customers across different industries with a more comprehensive chain of security and compliance evidence.

Looking ahead, GD32 has planned the GD32H7 and GD32F527 series for SESIP Level 2 certification, further expanding its portfolio of international security certifications.

From "Chip Security" to "Customer Compliance": GD32 Helps Lower the Barrier to the EU Market

The implementation of the CRA is extending product security beyond individual technical capabilities to encompass vulnerability management, software supply chain security, long-term support, and full-lifecycle management.

For customers, choosing GD32 means gaining access to MCU security and compliance capabilities that can help shift a significant portion of compliance preparation upstream to the semiconductor supplier, reducing the compliance workload required on the customer side.

As one of the industry's early adopters in establishing and implementing CRA compliance, GigaDevice is strengthening its security framework to help customers efficiently address EU CRA requirements and support their expansion into the EU market.

By choosing GD32 MCUs, customers can benefit from:

  • Reduced compliance costs: Access to SBOMs, security documentation, vulnerability response, and related support, reducing the amount of work customers need to perform from scratch.

  • Shortened certification timelines: International security certifications and assessment results, including SESIP, PSA, and RED, can provide important references for customers pursuing relevant security certifications.

  • Reduced supply chain risks: A professional PSIRT framework and long-term product support provide ongoing security assurance throughout product operation.

  • Reusable security capabilities: Security capabilities backed by international certifications and assessments can provide a foundation for customers' own product security development.

  • Professional technical support: The GD32 MCU FAE team can provide tailored technical and compliance recommendations based on customers' specific product architectures and application requirements.

As global cybersecurity requirements continue to evolve, GigaDevice will continue to advance CRA compliance for GD32 MCUs, together with compliance frameworks for other regional requirements, while further strengthening product security, international certifications, and customer support capabilities.

By reinforcing full-lifecycle security assurance, GD32 MCUs provide customers with a reliable security foundation for the future, helping customers worldwide expand into the EU market with greater efficiency and confidence.

Visit our CRA webpage for more information.

TOP

Info

Please log in to submit your request and receive relevant materials and support.

Info

Please complete your profile to submit your request and receive relevant materials and support.

标题

简介
  • Accept

  • Decline