Silicon Motion Technology Corp. (NasdaqGS: SIMO) has completed the first stage of its compliance program for the European Union’s Cyber Resilience Act (CRA), aligning key product-security processes with new incident-reporting requirements.
The company said it has completed an internal assessment of its cybersecurity controls and processes ahead of the first CRA obligations taking effect on September 11, 2026.
The milestone comes as the EU prepares to introduce stricter cybersecurity requirements for products with digital elements. Silicon Motion said it has established vulnerability-handling processes covering key areas addressed by the legislation, while continuing preparations for the CRA’s full application on December 11, 2027.
The CRA establishes cybersecurity requirements for connected hardware and software products sold in the European Union, including obligations related to vulnerability management and the reporting of certain security incidents.
Silicon Motion, which develops NAND flash controllers for solid-state storage devices, said its initial compliance work has focused on strengthening post-market vulnerability management and incident-reporting procedures.
“As AI expands across data centers, edge devices and Physical AI applications, cybersecurity has become an essential part of product development,” said Wallace C. Kou, President and Chief Executive Officer of Silicon Motion.
The company said its updated processes include security management and due diligence covering third-party hardware and software components. It has also introduced continuous vulnerability monitoring, coordinated disclosure and remediation procedures.
Silicon Motion has established incident escalation and reporting procedures designed to align with the CRA’s notification requirements. It has also defined security support and vulnerability-handling processes covering the product lifecycle.
As part of the effort, the company has created a dedicated security vulnerability reporting channel on its website. Customers, end users and other stakeholders can use the channel to report suspected security issues directly to Silicon Motion for investigation and response.
The measures apply across the company’s product portfolio, including enterprise SSD controllers, enterprise boot-drive solutions, edge SSD controllers and embedded eMMC and UFS controllers.
The program also covers Silicon Motion’s Ferri solutions for automotive and Physical AI applications, as well as its display-interface products.
The company said the work is intended to provide customers with a foundation for meeting evolving cybersecurity requirements in the European market.
Silicon Motion’s announcement comes ahead of the CRA’s phased implementation. While some obligations begin in September 2026, the legislation will become fully applicable in December 2027. The company said it will continue updating its compliance program as additional implementing guidance and harmonized standards are developed and finalized.
The timing places greater emphasis on vulnerability management throughout the lifecycle of products that contain digital components. For semiconductor and storage-device suppliers, compliance increasingly extends beyond the security of individual products to the processes used to identify, disclose and address vulnerabilities after deployment.
Silicon Motion said its initial milestone demonstrates its focus on product security as customers increasingly deploy storage technologies across data centers, edge infrastructure, automotive systems and emerging Physical AI applications.
The company’s next steps will include continuing to adapt its cybersecurity practices as the EU’s regulatory framework develops.





