
Hsinchu, Taiwan — September 09, 2026 — Wincomm Corporation is a leading industrial and medical computing solution provider based in Taiwan. As computing platforms become increasingly connected, Wincomm recognizes that cybersecurity is foundational to product reliability, safety, and lifecycle management. Proactively preparing for the EU Cyber Resilience Act (CRA), we are strengthening our defense framework and embedding stringent security standards directly into our product development and lifecycle processes.
Commitment to a Systematic CRA Compliance Framework
Wincomm recognizes that cybersecurity is not only a technical consideration, but also an integral part of responsible product development and lifecycle management. The CRA introduces cybersecurity requirements covering various stages of the lifecycle of products with digital elements, including cybersecurity risk management, secure product development, vulnerability handling, security updates, technical documentation, post-market cybersecurity activities, vulnerability and incident reporting, and customer communication.
To address these requirements, Wincomm is working with professional cybersecurity and regulatory consultants to assess the CRA requirements applicable to its products and establish a systematic CRA compliance framework. This framework will progressively define and integrate the necessary responsibilities, procedures, controls, documentation, and operational practices into Wincomm's existing quality management, product development, and product lifecycle processes.
Establishing Readiness for CRA Article 14 Reporting Obligations
As an immediate priority, Wincomm is establishing the internal procedures and operational mechanisms required to address the reporting obligations under CRA Article 14. The Article 14 readiness program focuses on establishing a systematic process for the identification, assessment, escalation, documentation, and communication of relevant cybersecurity vulnerabilities and severe cybersecurity incidents. Wincomm is establishing appropriate internal responsibilities and escalation mechanisms to ensure that potentially reportable cybersecurity events can be identified and evaluated in a timely manner, and that applicable regulatory reporting and customer communication activities can be initiated within the required regulatory timeframes. In particular, Wincomm is preparing processes for handling actively exploited vulnerabilities and severe cybersecurity incidents that may affect the security of products with digital elements.
Establishing Article 14 reporting readiness represents an important initial step in Wincomm's broader CRA compliance program. Wincomm will continue to validate, refine, and operationalize these processes through internal implementation, training, review, and ongoing consultation.
Integrating Cybersecurity into the Product Development Process
Building upon Wincomm's established quality management and product development practices, the company is progressively incorporating cybersecurity requirements and risk considerations into its product development processes. Depending on the applicable product, product configuration, intended use, and cybersecurity risk, Wincomm's cybersecurity activities will progressively address areas including:
- Cybersecurity risk assessment and security requirements
- Secure product development practices
- Product security architecture and design considerations
- Vulnerability identification, assessment, and remediation
- Security update and vulnerability management
- Software component management and Software Bills of Materials (SBOM)
- Cybersecurity verification and validation
- Technical documentation and cybersecurity records
- Post-market cybersecurity monitoring and support
- Vulnerability disclosure and regulatory reporting
- Customer communication regarding relevant cybersecurity issues
Through these activities, Wincomm aims to ensure that cybersecurity considerations are incorporated throughout the product lifecycle, from design and development through verification, release, maintenance, support, and end-of-life.
Extending Cybersecurity Management Throughout the Product Lifecycle
For Wincomm, cybersecurity is not a one-time certification or regulatory compliance exercise. It is an ongoing commitment that extends throughout the entire product lifecycle. Wincomm will continue to strengthen its capabilities for monitoring cybersecurity vulnerabilities, assessing potential risks and impacts, coordinating remediation activities, maintaining appropriate cybersecurity documentation, and communicating relevant security information to customers and other stakeholders.
Wincomm will also continue to collaborate with suppliers and technology partners to improve the transparency and traceability of software and other components incorporated into its products. Where applicable, Software Bills of Materials (SBOMs) and related component information will support vulnerability identification, risk assessment, and effective cybersecurity.
From Article 14 Readiness Toward Comprehensive CRA Compliance
The CRA Article 14 represents only one part of Wincomm's broader CRA compliance program. Wincomm's overall objective is to progressively address the full scope of applicable CRA requirements and to integrate these requirements into its product development and lifecycle management processes. With the continued support of professional cybersecurity and regulatory consultants, Wincomm will progressively evaluate and implement applicable CRA requirements, including cybersecurity risk management, vulnerability handling, security updates, technical documentation, post-market cybersecurity activities, and other relevant obligations.
Working Together Across the Technology Supply Chain
Wincomm recognizes that product cybersecurity is a shared responsibility across the technology supply chain. As part of its CRA readiness program, Wincomm will continue to strengthen communication and collaboration with suppliers and technology partners concerning cybersecurity information, software and component transparency, vulnerability management, and security-related documentation.
Commitment to Secure, Reliable, and Resilient Computing Solutions, and products
Wincomm is committed to continuously improving the cybersecurity, reliability, safety, and resilience of its products throughout their lifecycle.
Looking ahead, Wincomm will continue to monitor the development and implementation of the EU Cyber Resilience Act, related standards, regulatory guidance, and international cybersecurity best practices. As the CRA framework continues to evolve, Wincomm will progressively enhance its product development processes, cybersecurity management framework, vulnerability management capabilities, and customer support processes.
Through these ongoing efforts, Wincomm aims to deliver secure, reliable, and resilient industrial and medical computing solutions for mission-critical applications, while supporting customers and technology partners in addressing their evolving cybersecurity and regulatory requirements.
Disclaimer: The applicability of the Cyber Resilience Act (CRA) and the specific conformity assessment and compliance requirements may vary depending on product type, product configuration, software, intended use, cybersecurity characteristics, and the role of each Economic Operator in the relevant supply chain. Wincomm's CRA readiness and compliance activities are ongoing. The processes, assessments, implementations, and compliance milestones described herein are subject to applicable regulatory requirements and the successful completion of relevant internal and external assessment, implementation, review, and validation activities. This statement is provided for general informational purposes only and should not be construed as a certification, warranty, guarantee, or legal representation that any specific Wincomm product is currently compliant with the Cyber Resilience Act (CRA).
About Wincomm Corporation
Founded in 1993 and headquartered in Hsinchu, Taiwan, Wincomm Corporation is a leading designer and manufacturer of medical and industrial computing solutions. Its product portfolio includes medical-grade touch computers, monitors, and peripherals, as well as rugged industrial systems designed for harsh environments. Wincomm serves global markets in smart healthcare, factory automation, transportation, and petrochemical industries, with a commitment to innovation, reliability, and compliance with international standards including ISO 9001, ISO 13485, ISO 14001 and IECEx, ATEX, C1D2/C2D2 certification. For more information, visit www.wincomm.com.tw or follow Wincomm on LinkedIn and YouTube.