The EU CRA introduces mandatory cybersecurity requirements for products with digital elements. Nuvoton is committed to fulfilling these obligations across our MCU / MPU portfolio, including related firmware, BSPs, and development tools. Our focus remains on secure-by-design development, software transparency, and robust vulnerability handling. This platform provides our partners with a clear view of Nuvoton’s compliance activities and software security assurance to ensure CRA readiness.
Nuvoton has established a Product Security Incident Response Team (PSIRT) process to receive, evaluate, coordinate, and disclose product security vulnerabilities. The PSIRT process is designed with reference to the CRA, ISO/IEC 29147, ISO/IEC 30111, and CVSS v3.1 principles.
Nuvoton has also established official web-based channels for receiving vulnerability reports and publishing product security information. These channels provide a formal route for security researchers, customers, and partners to report suspected vulnerabilities and to obtain product security advisories when applicable.
| Channel | Description |
|---|---|
| Security reporting email | security@nuvoton.com |
| Online vulnerability report page | https://www.nuvoton.com/support/security/report-security-vulnerability |
| Product security information page | https://www.nuvoton.com/security |
| Security advisory page | Used to publish publicly disclosed product security advisories when applicable. |
Nuvoton supports responsible disclosure and will coordinate with reporters, customers, and relevant stakeholders when handling validated security vulnerabilities. Security advisories are expected to include applicable information such as CVE identifiers, affected products and versions, vulnerability description, CVSS score, fixed versions or mitigation guidance, and acknowledgments where appropriate.
Nuvoton MCU / MPU products that provide security-related functions are generally being prepared under the CRA Class I product framework, subject to further review based on product characteristics, market placement, customer use cases, and applicable EU regulatory guidance.
Nuvoton is preparing the corresponding compliance materials in phases. The first phase focuses on products with higher relevance to customer CRA preparation and security-oriented product use cases.
| Product | Product Type | First-phase Preparation Focus |
|---|---|---|
| M2L31 | MCU | Secure development process, SBOM preparation, automated CVE scanning, and static analysis integration |
| M2354 | MCU | Secure development process, SBOM preparation, automated CVE scanning, and static analysis integration |
| M487 | MCU | Secure development process, SBOM preparation, automated CVE scanning, and static analysis integration |
| MA35D1 | MPU | Linux package SBOM, open-source component scanning, CVE monitoring, and CI/CD security checks |
Additional products will be added progressively according to product priority, customer demand, CRA implementation milestones, and product risk assessment results.
Nuvoton has established a software security development policy to integrate security activities into the software development life cycle. The objective is to ensure that software security is addressed during planning, design, development, testing, release, and maintenance, rather than treated only as a final release check.
| Development Stage | Customer-facing Description |
|---|---|
| Planning and requirements | Identify security requirements and the applicable security assurance scope based on product and software characteristics. |
| Design | Apply secure design principles and evaluate attack surfaces, third-party components, and architecture-level security considerations. |
| Development | Follow secure coding rules and introduce software composition analysis and static analysis where applicable. |
| Testing and verification | Perform SCA and SAST according to software security level; DAST or penetration testing may be applied for higher-risk software. |
| Release | Generate SBOM, perform final vulnerability and license checks, and maintain release records. |
| Maintenance | Monitor public vulnerability databases and provide security updates, mitigation guidance, or advisories when applicable. |
Nuvoton applies a software security classification model to determine the depth of security activities required for different types of software. This allows security efforts to be applied proportionally based on the software’s role in the final product, its exposure to untrusted input, and its potential security impact.
| Security Level | Typical Software Scope | Main Assurance Measures |
|---|---|---|
| Level 3 - High security impact | Secure boot, cryptography, trust-chain-related software, MCUboot examples, TF-A examples, MbedTLS, startup code, and vector table related code. | Full secure development process, SBOM, SCA, SAST, DAST where applicable, penetration testing where applicable, continuous vulnerability monitoring, and security update support. |
| Level 2 - Medium security impact | MCU BSPs, MPU Linux packages, communication-capable firmware, debugging-support firmware, and software with indirect security impact. | Standard secure development process, SBOM, SCA, SAST, CVE monitoring, and security update support. |
| Level 1 - Low security impact | Reference examples and non-security-critical development support utilities. | Basic SCA, SBOM, and best-effort security maintenance. |
The classification is reviewed dynamically. If a software component’s function, exposure, or use case changes, Nuvoton may reassess the applicable software security level and adjust the assurance measures accordingly.
Nuvoton regards the Software Bill of Materials (SBOM) as a key element of CRA software transparency. Nuvoton is preparing SBOMs for relevant software packages and plans to provide machine-readable SBOM information, primarily using the CycloneDX format where applicable.
The SBOM and component management approach is intended to cover:
For the first-phase CRA preparation products, Nuvoton is progressively preparing SBOMs, third-party component records, open-source license information, vulnerability scanning records, and product-specific security support information.
Nuvoton is progressively integrating security checks into development and release workflows. For first-phase CRA products and subsequently prioritized products, the following activities are being introduced into CI/CD or equivalent automated workflows where applicable.
| Security Activity | Description |
|---|---|
| Software Composition Analysis (SCA) | Identify third-party and open-source components, licenses, and known vulnerabilities. |
| SBOM generation | Generate machine-readable SBOM information for software releases where applicable. |
| Automated CVE matching | Compare released components against public vulnerability databases such as CVE, NVD, and OSV. |
| Static Application Security Testing (SAST) | Analyze source code for potential security weaknesses before release. |
| Pre-release security check | Confirm that high-risk findings have been remediated, mitigated, or formally assessed before release. |
Nuvoton monitors public vulnerability sources and third-party component security advisories to assess whether known vulnerabilities affect Nuvoton software packages or product deliverables. Vulnerability handling is performed based on applicability, severity, affected product versions, exploitability, and customer impact.
When a vulnerability is confirmed to affect a Nuvoton product or software package, Nuvoton will follow a coordinated handling process that may include:
For actively exploited vulnerabilities or severe incidents that meet CRA reporting conditions, Nuvoton will follow the applicable CRA reporting requirements and timelines through the required reporting channels once those obligations become applicable.
Nuvoton software, BSPs, Linux packages, reference examples, and development tools are typically components used by customers to build their own final products. The customer, as the final product manufacturer or integrator, remains responsible for evaluating the complete product design, use case, deployment environment, attack surface, and applicable regulatory obligations.
Nuvoton recommends that customers and partners:
Nuvoton will continue to improve its product and software security processes according to CRA implementation milestones, EU guidance, customer needs, industry standards, and product risk assessment results.
Current and planned improvement activities include: