STDA050 October   2026 AM2431 , AM2432 , AM2434 , AM623 , AM625 , AM625-Q1 , AM625SIP , AM62A1-Q1 , AM62A3 , AM62A3-Q1 , AM62A7 , AM62A7-Q1 , AM62L , AM62P , AM62P-Q1 , AM6411 , AM6412 , AM6421 , AM6422 , AM6441 , AM6442 , AM67 , AM67A , AM68 , AM68A , AM69 , AM69A , DRA821U , DRA829J , DRA829V , TDA4AEN-Q1 , TDA4AH-Q1 , TDA4AL-Q1 , TDA4AP-Q1 , TDA4APE-Q1 , TDA4VE-Q1 , TDA4VEN-Q1 , TDA4VH-Q1 , TDA4VL-Q1 , TDA4VM , TDA4VM-Q1 , TDA4VP-Q1 , TDA4VPE-Q1 , TDA54-Q1

 

  1.   1
  2.   Abstract
  3. 1Introduction
  4. 2CRA Scope and the Component Supplier Question
    1. 2.1 What the Regulation Covers
    2. 2.2 How the CRA Classifies TI Products
    3. 2.3 The Integration Boundary
  5. 3Shared Responsibility Model
    1. 3.1 The Supply Chain Stack
    2. 3.2 Responsibility Allocation by CRA Requirement
    3. 3.3 The Tier 1 and SoM Vendor Layer
  6. 4TI's Security Capabilities Relevant to CRA
    1. 4.1 Hardware Security Capabilities
    2. 4.2 SDK and Software Security
    3. 4.3 Documentation and Lifecycle Artifacts
  7. 5Conclusion
  8. 6References

SDK and Software Security

TI provides SBOMs in SPDX and CycloneDX formats for all products for which public source code is available as part of SDK on ti.com. SBOMs for secure software components are available through TI's MySecure access program.

TI processor SDKs are scanned for known vulnerabilities before each release. TI manages the full vulnerability handling lifecycle through PSIRT: notification intake, triage, technical analysis, remediation, and coordinated public disclosure with CVSS v3.1 severity scoring and CVE assignment. The process aligns to ISO/IEC 30111 and ISO/IEC 29147. TI provides security patches free of charge with advisory messages.

TI delivers patches and advisories through the product security advisory portal (PSAP) at ti.com/psap. PSAP gives customers a structured channel to report vulnerabilities through myTI accounts, subscribe to advisory feeds scoped to the TI products in their designs, and access disclosures in CSAF v2.0 machine-readable format. CSAF v2.0 advisories reference the specific software components affected, enabling customers to automate correlation against their SBOMs and assess exposure within their CRA reporting timelines.

TI publishes a security.txt file at ti.com/.well-known/security.txt per BSI TR-03183-3 and RFC 9116. The text file contains the PSIRT contact address, CVD policy URI, and CSAF provider metadata. TI operates under German jurisdiction, and TI's designated national CSIRT for Article 14 reporting is CERT-Bund, operated by the German Federal Office for Information Security (BSI). TI submits incident notifications through the CRA Single Reporting Platform within the required timelines.

Article 14 requires manufacturers to notify the appropriate national CSIRT within 24 hours of "becoming aware" of an actively exploited vulnerability. The regulation does not define the moment awareness is established in a multi-person organization. Manufacturers define in advance what constitutes awareness in their organization, whether at intake acknowledgment or when the responsible technical team member first reviews the report, however, an undefined clock creates compliance risk. The 24-hour window starts at that defined moment, not when an individual engineer reviews the report. The automated deadline tracking from PSAP enforces this by escalating reports before the window closes. Any actively exploited vulnerability known to TI triggers this 24-hour deadline, whether the information arrives from a security researcher, a customer, or internal discovery. The 72-hour notification follows with a fuller assessment, submitted simultaneously to the national CSIRT and ENISA through the CRA Single Reporting Platform.