Nuvoton EU CRA Compliance Statement

The EU CRA introduces mandatory cybersecurity requirements for products with digital elements. Nuvoton is committed to fulfilling these obligations across our MCU / MPU portfolio, including related firmware, BSPs, and development tools. Our focus remains on secure-by-design development, software transparency, and robust vulnerability handling. This platform provides our partners with a clear view of Nuvoton’s compliance activities and software security assurance to ensure CRA readiness.

  • PSIRT
  • Product Classification
  • DevSecOps
  • Security Classification
  • SBOM
  • CI/CD Integration
  • Security Advisories
  • Customer & Partner Responsibilities
  • Continuous Improvement & Roadmap

PSIRT

Nuvoton has established a Product Security Incident Response Team (PSIRT) process to receive, evaluate, coordinate, and disclose product security vulnerabilities. The PSIRT process is designed with reference to the CRA, ISO/IEC 29147, ISO/IEC 30111, and CVSS v3.1 principles.

Nuvoton has also established official web-based channels for receiving vulnerability reports and publishing product security information. These channels provide a formal route for security researchers, customers, and partners to report suspected vulnerabilities and to obtain product security advisories when applicable.

Channel Description
Security reporting email security@nuvoton.com
Online vulnerability report page https://www.nuvoton.com/support/security/report-security-vulnerability
Product security information page https://www.nuvoton.com/security
Security advisory page Used to publish publicly disclosed product security advisories when applicable.

Nuvoton supports responsible disclosure and will coordinate with reporters, customers, and relevant stakeholders when handling validated security vulnerabilities. Security advisories are expected to include applicable information such as CVE identifiers, affected products and versions, vulnerability description, CVSS score, fixed versions or mitigation guidance, and acknowledgments where appropriate.

Product Classification

Nuvoton MCU / MPU products that provide security-related functions are generally being prepared under the CRA Class I product framework, subject to further review based on product characteristics, market placement, customer use cases, and applicable EU regulatory guidance.

Nuvoton is preparing the corresponding compliance materials in phases. The first phase focuses on products with higher relevance to customer CRA preparation and security-oriented product use cases.

Product Product Type First-phase Preparation Focus
M2L31 MCU Secure development process, SBOM preparation, automated CVE scanning, and static analysis integration
M2354 MCU Secure development process, SBOM preparation, automated CVE scanning, and static analysis integration
M487 MCU Secure development process, SBOM preparation, automated CVE scanning, and static analysis integration
MA35D1 MPU Linux package SBOM, open-source component scanning, CVE monitoring, and CI/CD security checks

Additional products will be added progressively according to product priority, customer demand, CRA implementation milestones, and product risk assessment results.

DevSecOps

Nuvoton has established a software security development policy to integrate security activities into the software development life cycle. The objective is to ensure that software security is addressed during planning, design, development, testing, release, and maintenance, rather than treated only as a final release check.

Development Stage Customer-facing Description
Planning and requirements Identify security requirements and the applicable security assurance scope based on product and software characteristics.
Design Apply secure design principles and evaluate attack surfaces, third-party components, and architecture-level security considerations.
Development Follow secure coding rules and introduce software composition analysis and static analysis where applicable.
Testing and verification Perform SCA and SAST according to software security level; DAST or penetration testing may be applied for higher-risk software.
Release Generate SBOM, perform final vulnerability and license checks, and maintain release records.
Maintenance Monitor public vulnerability databases and provide security updates, mitigation guidance, or advisories when applicable.

Security Classification

Nuvoton applies a software security classification model to determine the depth of security activities required for different types of software. This allows security efforts to be applied proportionally based on the software’s role in the final product, its exposure to untrusted input, and its potential security impact.

Security Level Typical Software Scope Main Assurance Measures
Level 3 - High security impact Secure boot, cryptography, trust-chain-related software, MCUboot examples, TF-A examples, MbedTLS, startup code, and vector table related code. Full secure development process, SBOM, SCA, SAST, DAST where applicable, penetration testing where applicable, continuous vulnerability monitoring, and security update support.
Level 2 - Medium security impact MCU BSPs, MPU Linux packages, communication-capable firmware, debugging-support firmware, and software with indirect security impact. Standard secure development process, SBOM, SCA, SAST, CVE monitoring, and security update support.
Level 1 - Low security impact Reference examples and non-security-critical development support utilities. Basic SCA, SBOM, and best-effort security maintenance.

The classification is reviewed dynamically. If a software component’s function, exposure, or use case changes, Nuvoton may reassess the applicable software security level and adjust the assurance measures accordingly.

SBOM

Nuvoton regards the Software Bill of Materials (SBOM) as a key element of CRA software transparency. Nuvoton is preparing SBOMs for relevant software packages and plans to provide machine-readable SBOM information, primarily using the CycloneDX format where applicable.

The SBOM and component management approach is intended to cover:

  • Component name, version, supplier, and license information.
  • Component hash values and unique identifiers such as PURL or CPE where applicable.
  • Dependency relationships for software packages.
  • Known vulnerability information and related CVE references where applicable.
  • Supporting vulnerability exploitability or advisory information when applicable.

For the first-phase CRA preparation products, Nuvoton is progressively preparing SBOMs, third-party component records, open-source license information, vulnerability scanning records, and product-specific security support information.


SBOM Ready:M2354、M2L31、M487

CI/CD Integration

Nuvoton is progressively integrating security checks into development and release workflows. For first-phase CRA products and subsequently prioritized products, the following activities are being introduced into CI/CD or equivalent automated workflows where applicable.

Security Activity Description
Software Composition Analysis (SCA) Identify third-party and open-source components, licenses, and known vulnerabilities.
SBOM generation Generate machine-readable SBOM information for software releases where applicable.
Automated CVE matching Compare released components against public vulnerability databases such as CVE, NVD, and OSV.
Static Application Security Testing (SAST) Analyze source code for potential security weaknesses before release.
Pre-release security check Confirm that high-risk findings have been remediated, mitigated, or formally assessed before release.

Security Advisories

Nuvoton monitors public vulnerability sources and third-party component security advisories to assess whether known vulnerabilities affect Nuvoton software packages or product deliverables. Vulnerability handling is performed based on applicability, severity, affected product versions, exploitability, and customer impact.

When a vulnerability is confirmed to affect a Nuvoton product or software package, Nuvoton will follow a coordinated handling process that may include:

  • Assessing whether the vulnerability applies to Nuvoton products, software versions, and use cases.
  • Identifying affected products, package versions, and software components.
  • Preparing a fix, workaround, configuration guidance, or mitigation where appropriate.
  • Publishing security advisory information through official channels when applicable.
  • Submitting mandatory CRA reports when the relevant CRA reporting conditions are met.

For actively exploited vulnerabilities or severe incidents that meet CRA reporting conditions, Nuvoton will follow the applicable CRA reporting requirements and timelines through the required reporting channels once those obligations become applicable.

Customer and Partner Responsibilities

Nuvoton software, BSPs, Linux packages, reference examples, and development tools are typically components used by customers to build their own final products. The customer, as the final product manufacturer or integrator, remains responsible for evaluating the complete product design, use case, deployment environment, attack surface, and applicable regulatory obligations.

Nuvoton recommends that customers and partners:

  • Subscribe to or regularly review Nuvoton product security advisories.
  • Use the latest applicable BSP, SDK, Linux package, firmware, or security update released by Nuvoton.
  • Review SBOM and third-party license information as part of their own compliance process.
  • Perform product-level security assessment and testing after integrating Nuvoton software.
  • Report suspected product security vulnerabilities through Nuvoton’s official vulnerability reporting channels.

Continuous Improvement and Roadmap

Nuvoton will continue to improve its product and software security processes according to CRA implementation milestones, EU guidance, customer needs, industry standards, and product risk assessment results.

Current and planned improvement activities include:

  • Continuing to refine the PSIRT vulnerability intake, analysis, reporting, and advisory process.
  • Preparing CRA Class I-related technical and software security materials according to product priority.
  • Completing first-phase SBOM, CVE scanning, and static analysis preparation for M2L31, M2354, M487 and MA35D1.
  • Expanding CI/CD security checks to additional MCU / MPU software packages.
  • Tracking updates to CRA, ENISA guidance, CSIRT reporting practices, IEC 62443, ISO/IEC 29147, and ISO/IEC 30111.
  • Maintaining product security updates and advisory mechanisms throughout the applicable software support period.