Press Release

We’re in This Together: Why Radical Transparency Makes CRA Reporting Easier

Sep 1, 2026
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
,
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
,
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
No items found.

On September 11, 2026, the EU Cyber Resilience Act (CRA) reporting mandate will go into effect. If a vulnerability in a product with digital elements is being actively exploited, or a severe security incident occurs, it now has to be disclosed fast, and to the right authorities. For anyone building hardware that ends up in the hands of real users, this isn't a distant policy footnote. It's a new baseline for how the industry is expected to behave when something goes wrong.

If you build on TROPIC01, this affects you too

We do not hide critical information about our products behind an NDA wall. We endeavor to provide you with usable information, on a timeline that respects the clock we both have to follow. Unfortunately, vulnerabilities that the CRA covers will come up. This is the reality for every hardware and software product on earth. The question that actually matters is what happens in the hours and days after they're found.

We've done this before

For us, here's what our reporting process actually looked like, when we sent TROPIC01 out for an independent audit. Earlier this year, the Ledger Donjon team ran an independent audit against TROPIC01 and found a vulnerability — a laser fault-injection attack capable of extracting a subset of protected secrets. Our engineering team went further, building on their work to identify an additional exploitation path.

We disclosed this episode publicly and in plain language; not buried in a private advisory shared only under NDA with only our top accounts. That's the version of "disclosure" the CRA is trying to make mandatory across the industry. We already do it, because it's the only version of security that our open-architecture philosophy allows for.

We're your partner in this, not just your supplier

Auditable design was never just a technical choice for us. It was grounded in our belief that transparency, not obscurity, is what actually keeps systems secure. The CRA is built on the same ideal. As the reporting mandate takes effect, our job isn't just to secure the silicon. It's to make sure that when something does surface, you're never the last to know, and never left to figure out your next move on your own.

That's what we mean when we say we're your partner.

Also read

Blogs
CRA: Beyond the Chip

Read more
Video
The Value of Transparent Security

Read more
Watch Video
Blogs
Reflections from TechWorks Semiconductor to Systems Summit: Why CRA Compliance Starts in Silicon

Read more
No items found.
Blogs
Reflections from TechWorks Semiconductor to Systems Summit: Why CRA Compliance Starts in Silicon

Read more
Blogs
Closing the CCS2 EV Charger Attack Surface

Read more
Blogs
Potential Bypass of Firmware Verification by Laser Fault Injection

Read more

Get Tropic Square updates, blogs, and resources right to your mailbox

Subscribe to Tropic Square newsletter

For Technical Support

Talk to Technical Team

Get TROPIC01 Devboard

Order Devboard / Samples