Robustel Publishes CRA Article 14 Reporting & User Protection Statement

Strengthening transparency, accountability and user protection through clear cybersecurity reporting and response under the EU Cyber Resilience Act.
Robustel is compliant with the reporting obligations of Article 14 of the EU Cyber Resilience Act (CRA), which became applicable to manufacturers on 11 September 2026.
To provide customers, partners and security researchers with clear visibility into how these obligations are implemented, Robustel has published a dedicated Cyber Resilience Act (CRA) Article 14 Reporting & User Protection resource within the Robustel Security Centre.
The resource outlines the processes Robustel has established for identifying, assessing, escalating and reporting qualifying product security events, together with the arrangements used to communicate relevant risk information and available guidance to affected users.
For organisations deploying connected infrastructure, effective cybersecurity response requires more than regulatory reporting. It depends on clear accountability, timely technical assessment, structured escalation and practical communication with users when action may be required.
Robustel’s Article 14 arrangements are coordinated through its Product Security Incident Response Team (PSIRT), bringing together security, engineering and product teams. Regulatory reporting, technical investigation, remediation and user communication are managed as parallel activities, helping ensure that affected users can receive relevant risk information and available guidance without waiting for every stage of an investigation or remediation process to be completed.
The new resource also provides greater transparency around how potential security concerns can be reported to Robustel. Customers and security researchers do not need to determine the severity of an issue or whether it meets CRA reporting criteria before submitting a concern. Assessment, classification and escalation form part of Robustel’s established security triage process.
This publication forms part of Robustel’s wider approach to product security and transparency. The Robustel Security Centre brings together vulnerability reporting, security advisories, firmware and software updates, hardening guidance, independent security assessment summaries and information relating to Robustel’s IEC 62443-4-1 certified secure development process.
By making these processes and supporting resources publicly accessible, Robustel aims to give customers clearer visibility into how product security issues are identified, assessed, escalated and communicated throughout the product lifecycle.
The new resource specifically addresses Robustel’s compliance with the reporting obligations of CRA Article 14. It does not constitute an EU Declaration of Conformity or a statement of full CRA product conformity.
Read the full Cyber Resilience Act Article 14 Reporting & User Protection information in the Robustel Security Centre
