
At Sungrow, we maintain a robust global compliance framework that aligns with international standards and regional regulatory requirements across key markets.
The Cyber Resilience Act (Regulation (EU) 2024/2847) is the European Union's horizontal cybersecurity regulation for products with digital elements. It entered into force on 10 December 2024. Its incident and vulnerability reporting obligations under Article 14 have applied since 11 September 2026, and its remaining main obligations will apply from 11 December 2027. The CRA requires manufacturers to operate a risk-based secure development lifecycle, handle vulnerabilities throughout the defined support period, provide security updates on an ongoing basis, and publicly disclose information on fixed vulnerabilities once a security update becomes available. Sungrow has established an internal reporting process in accordance with the CRA's reporting obligations, and operates a coordinated vulnerability disclosure process in line with ISO/IEC 29147 and ISO/IEC 30111. For the remaining obligations under the CRA, Sungrow has set up a dedicated CRA task force to drive capability development, and maintains an ongoing tracking and compliance mechanism for the Cyber Resilience Act.