QNAP has introduced new security reporting procedures and a dedicated reporting platform as the European Union’s Cyber Resilience Act (CRA) begins imposing incident-reporting obligations on connected-product makers. The company says the process covers its portfolio of NAS systems, routers and switches, but it does not amount to full compliance with the regulation.

The CRA entered into force in December 2024, while reporting obligations for actively exploited vulnerabilities and severe security incidents began applying on September 11, 2026. The wider regulation is scheduled to become fully applicable on December 11, 2027.

Under the reporting rules, a manufacturer that becomes aware of an actively exploited vulnerability or severe incident must issue an early warning within 24 hours and follow it with a main notification within 72 hours. The 24-hour deadline concerns notification, not a requirement to fix the issue within a day.

  • For an actively exploited vulnerability, a final report is due no later than 14 days after a remediation measure becomes available.
  • For a severe incident, the final report is due within one month of the 72-hour notification.

QNAP’s new Security Reporting Platform lets users and security researchers submit evidence to the company’s Product Security Incident Response Team, including the affected product and version, observed impact, logs, indicators of compromise and any CVE identifier. QNAP says its team will determine whether a report meets the CRA’s legal reporting threshold.

The QNAP platform is not a replacement for the EU reporting system administered by ENISA. It is a route for researchers and customers to notify QNAP; the manufacturer remains responsible for submitting qualifying cases through ENISA’s Single Reporting Platform to the relevant authorities.

A process certification, not product-wide CRA approval

QNAP also received DEKRA verification for its development process under IEC 62443-4-1 in September. The standard addresses how security is incorporated throughout a development lifecycle, from requirements and design to testing and maintenance. It may support CRA readiness, but it is not a certification that automatically makes every QNAP product compliant with the CRA.

The emphasis on reporting comes after past security incidents affecting internet-exposed QNAP NAS devices, including DeadBolt ransomware campaigns that encrypted data through exploited vulnerabilities. In 2022, QNAP advised customers to update QTS promptly and avoid direct internet exposure of NAS hardware. That history does not indicate a current vulnerability, but it illustrates why formal reporting and response workflows matter for storage systems holding backups and business data.

QNAP’s current business-oriented lineup includes the 1U rackmount TS-432XeU with 10GbE, while QuTS hero h6.0 adds immutable snapshots and High Availability features. For systems used to store company projects, backups or AI data volumes, the interval between discovering an exploited flaw and the vendor response can be consequential.

The announcement does not bring a new end-user feature or a special CRA software update. Instead, it establishes a formal workflow for actively exploited vulnerabilities and serious incidents. Full CRA application remains more than a year away, with December 11, 2027 the next key regulatory milestone for QNAP and other connected-device manufacturers selling in Europe.

SOURCEdigital-strategy.ec.europa.eu
Previous articleSamsung Display Smart Glasses Surface in FCC Filings Ahead of Reported November Debut
Next articleiQOO Pad Ultra launches in China with 165Hz OLED display and active cooling