Policy 06
EU Cyber Resilience Act Policy
About the Cyber Resilience Act
The EU Cyber Resilience Act (Regulation (EU) 2024/2847, the “CRA”) sets mandatory cybersecurity requirements for products with digital elements placed on the EU market. It entered into force on 10 December 2024; manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, and the main obligations apply in full from 11 December 2027. The CRA complements the NIS2 Directive.
Our approach
WinguSuite treats the CRA as part of its wider security programme, alongside ISO/IEC 27001:2022, NIS2 and the EU AI Act. As the requirements phase in, we align our development and maintenance of the WinguSuite platform and applications to the Act’s essential cybersecurity requirements.
Secure by design
We design and develop the platform to reduce cybersecurity risk: minimising the attack surface, applying least-privilege access, encrypting data in transit and encrypting backups with AES-256, and protecting endpoints with Acronis EDR and MDR.
Vulnerability handling
- We identify, triage and remediate vulnerabilities across the product lifecycle through managed patching.
- We apply emergency maintenance where a condition is likely to cause severe degradation.
- We maintain the means to distribute security updates to keep the service protected.
Incident & vulnerability reporting
In line with the CRA’s reporting regime, we operate processes to report actively exploited vulnerabilities and severe incidents on the Act’s escalating timeline — an early warning within 24 hours, a fuller notification within 72 hours, and a final report within the required period — to the relevant national CSIRT and ENISA. Report a security concern to [email protected].
Support & documentation
We maintain security support for the service and keep the documentation and records needed to demonstrate conformity as the Act’s obligations take effect.