We’re in This Together: Why Radical Transparency Makes CRA Reporting Easier

On September 11, 2026, the EU Cyber Resilience Act (CRA) reporting mandate will go into effect. If a vulnerability in a product with digital elements is being actively exploited, or a severe security incident occurs, it now has to be disclosed fast, and to the right authorities. For anyone building hardware that ends up in the hands of real users, this isn't a distant policy footnote. It's a new baseline for how the industry is expected to behave when something goes wrong.
If you build on TROPIC01, this affects you too
We do not hide critical information about our products behind an NDA wall. We endeavor to provide you with usable information, on a timeline that respects the clock we both have to follow. Unfortunately, vulnerabilities that the CRA covers will come up. This is the reality for every hardware and software product on earth. The question that actually matters is what happens in the hours and days after they're found.
We've done this before
For us, here's what our reporting process actually looked like, when we sent TROPIC01 out for an independent audit. Earlier this year, the Ledger Donjon team ran an independent audit against TROPIC01 and found a vulnerability — a laser fault-injection attack capable of extracting a subset of protected secrets. Our engineering team went further, building on their work to identify an additional exploitation path.
We disclosed this episode publicly and in plain language; not buried in a private advisory shared only under NDA with only our top accounts. That's the version of "disclosure" the CRA is trying to make mandatory across the industry. We already do it, because it's the only version of security that our open-architecture philosophy allows for.
We're your partner in this, not just your supplier
Auditable design was never just a technical choice for us. It was grounded in our belief that transparency, not obscurity, is what actually keeps systems secure. The CRA is built on the same ideal. As the reporting mandate takes effect, our job isn't just to secure the silicon. It's to make sure that when something does surface, you're never the last to know, and never left to figure out your next move on your own.
That's what we mean when we say we're your partner.

