VicOne Co., Ltd., a subsidiary of Trend Micro Incorporated, which is expanding its efforts from automotive cybersecurity to the field of physical AI, will begin offering “CRA Studio,” a platform that centrally manages the tasks necessary to comply with the EU Cyber Resilience Act (CRA).
The CRA (Critical Risk Assessment) reporting obligation will be applied in advance from September 11, 2026, and will be fully implemented on December 11, 2027. As Japanese manufacturers providing products with digital elements to the EU market are required to comply, “CRA Studio” consolidates the tasks necessary for CRA compliance, such as risk analysis, documentation, and post-shipment vulnerability management, into a single platform, supporting everything from preparation to continuous operation.
Main features of “CRA Studio”
“CRA Studio” is a solution that integrates all the tasks necessary for CRA compliance into a single platform, from importing product information and existing documents to risk analysis and creating the technical documents required for CRA compliance. It automatically maps product information and analysis results to each clause of the CRA, providing consistent support from preparing for regulatory compliance to continuous operation.
Also Read: Driven Tech Launches AI Security Operations Platform
Centralized risk analysis and documentation from the design stage: CRA requires analyzing the cybersecurity risks of a product and documenting the countermeasures taken in technical documentation. “CRA Studio” performs threat modeling and risk analysis based on product information and existing documents, and organizes the results into technical documentation and evidence in accordance with CRA requirements.
Responding to obligations that continue after shipment: CRAs are required to monitor and address vulnerabilities throughout the support period defined for each product. The support period is generally at least 5 years, or the period exceeding the expected lifespan of the product if it is longer than 5 years. CRA Studio provides continuous support for organizing the information necessary to identify and report vulnerabilities in products that have already been shipped.
Responding to Phased Reporting Requirements: We streamline the reporting flow by supporting you from identifying affected products and organizing necessary information to creating reports, in preparation for the reporting requirements that will come into effect in September 2026.
Source: PRTimes


