Axiomtek – a world-renowned leader relentlessly devoted to the research, development, and manufacture of innovative, highly efficient, and reliable industrial computer products – has long recognized cybersecurity as a fundamental requirement for industrial computing systems deployed in connected, mission-critical, and infrastructure-related environments. Before the EU Cyber Resilience Act (CRA) was officially adopted, Axiomtek had already obtained IEC 62443-4-1 Maturity Level 2 certification. This achievement reflects Axiomtek’s long-standing commitment to secure-by-design development, demonstrating that cybersecurity is a core principle of our approach to building secure, reliable, and resilient industrial computing platforms.

Extending Cybersecurity from Development Processes to Product-Level Design
Building on its certified secure development lifecycle, Axiomtek is extending its cybersecurity focus from process governance to product-level security. Axiomtek has already incorporated IEC 62443-4-2 security requirements into our product roadmap and is preparing to pursue its first IEC 62443-4-2 SL2 product certification in line with the CRA implementation timeline. Looking ahead, Axiomtek will continue to apply IEC 62443-4-2 as an important reference for future product design, helping customers build more secure and regulation-ready systems for industrial, transportation, energy, and critical infrastructure applications.
Aligning Product Security and Lifecycle Management with CRA Requirements
The EU Cyber Resilience Act establishes cybersecurity requirements across both product design and lifecycle management. On the lifecycle management side, Axiomtek is in the process of formalizing its vulnerability management and incident response procedures in alignment with CRA Article 13 and Article 14 obligations. These efforts include improving firmware component tracking and progressively expanding SBOM-related coverage across applicable platforms, depending on chipset and firmware vendors’ roadmaps and support from upstream suppliers.
On the product side, Axiomtek continues to strengthen secure-by-design and secure-by-default principles across applicable platforms, with product-dependent security features such as TPM 2.0, Secure Boot, BIOS and firmware protection, and other security mechanisms designed to enhance system integrity and resilience. Axiomtek aims to align future platforms with IEC 62443-4-2 SL2 requirements and use these requirements as key criteria for product-level cybersecurity design.
Supporting Customers Through Long-Term Cybersecurity Alignment
“The EU Cyber Resilience Act reinforces what Axiomtek has long believed: cybersecurity must be built into products from the beginning and supported throughout the product lifecycle. Our goal is to help customers move forward with greater confidence as regulatory and cybersecurity expectations continue to evolve, while supporting faster integration and smoother market deployment for long-term mutual success.”
— Tab, head of the Firmware Development Department