Everpure Statement on the European Union Cyber Resilience Act (EU-CRA)

Security Bulletins

Audience
Public
Product
FlashBlade
FlashArray
FlashBlade > Purity//FB
FlashArray > Purity//FA
Portworx
Source Type
Documentation

Website Statement

The EU Cyber Resilience Act (EU-CRA) establishes cybersecurity requirements for products with digital elements sold in the European Union, including requirements for secure design, development, vulnerability handling, and support across the product lifecycle.

Everpure is actively aligning its products, practices and processes with the EU-CRA's phased requirements, including those taking effect on September 11, 2026, and December 11, 2027.

For customers, this offers continued assurance that Everpure solutions are developed and maintained to meet evolving EU cybersecurity standards— simplifying deployment across the EU and EEA, particularly within regulated and security-sensitive environments.

Continue reading for more technical details.

Everpure and the EU Cyber Resilience Act

Everpure recognizes the importance of the European Union Cyber Resilience Act (EU CRA) in establishing a common cybersecurity baseline for products with digital elements. Everpure is actively aligning its products, development practices, and security processes with the regulations requirements as they take effect. This effort spans our engineering, product security, legal, compliance, and product management organizations.

Why the EU-CRA Matters To You

The EU-CRA establishes mandatory cybersecurity requirements for products with digital elements across their full lifecycle. These requirements include:

  • Secure design and development by integrating security mechanisms from inception.

  • Ongoing vulnerability handling through proactive disclosure, tracking, and remediation.

  • Timely security updates.

  • Customer documentation.

Our goal is to help customers deploy Everpure solutions with confidence across the EU and EEA, including in regulated and security-sensitive environments.

Vulnerability Reporting and Disclosure

Everpure operates a coordinated vulnerability disclosure process through its Product Security Incident Response Team (PSIRT). We provide:

  • A public reporting channel and security contact

  • A customer-visible CVE database

  • Security advisories and bulletins

  • Interim mitigation guidance when appropriate

  • Processes that support applicable EU-CRA reporting obligations

Stay Updated: Customers can subscribe to security notifications via the EverpureEverpure Product Security page to receive updates when newly published advisories are available.

Evidence and Documentation:

Supporting compliance documentation is available through the Everpure Trust Center, including:

  • Software Bills of Materials (SBOMs)

  • Declarations of conformity

  • Certifications

  • Security advisories

Secure Software Development Framework

Everpure follows a Security by Design philosophy that integrates security into every phase of the Software Development Life Cycle (SDLC). Everpure's secure software development practices align with the NIST Secure Software Development Framework (NIST SP 800-218)

Our secure development practices include:

Secure by Design & Architecture

  • Risk-based secure software development

  • Security Design

  • Threat modeling

Secure Implementation & Testing
  • Peer code reviews

  • Automated and continuous security testing

Software Supply Chain Security
  • Software supply chain integrity verification

  • Dependency and provenance management

  • Third-party component validation

Vulnerability Handling & Lifecycle Management
  • Continuous vulnerability management

  • Secure release governance

These practices are designed to reduce software supply chain risk while improving overall product security and resilience.

For more information on Everpure's Secure Software Development Framework, please review the Security and Compliance Assurance Packet.

Product Security

Security capabilities are built into Everpure platforms by default. Enterprise-class security controls (encryption at rest/in transit, RBAC, SAML/AD, audit logging, FIPS 140-3, and Common Criteria) are built into all product families, both on-premise and cloud-based products and services.

Everpure employs robust encryption technologies throughout our enterprise products and cloud services.

Data in Transit

Communications are protected using TLS 1.2 or higher to ensure confidentiality and integrity.

Data at Rest

Customer data is protected using always-on AES-256 encryption across supported storage platforms.

Our cryptographic implementations are independently validated through recognized certification programs including FIPS 140-3.

Everpure's product security details and Certificates of Compliance can be found within the Security and Compliance Assurance Packet.

Cloud Security

Everpure cloud services, including the Pure1® platform and Portworx cloud services, employ enterprise-grade security controls designed to protect customer information.

Our cloud security program aligns with internationally recognized standards including:

  • SOC 2 Type II

  • ISO/IEC 27001

  • CSA STAR Level 2

Our cloud services leverage AWS infrastructure, which maintains independent SOC 2, ISO, and NIST certifications.

Our Commitment

Cybersecurity continues to evolve, and so do customer expectations and regulatory requirements.

Everpure remains committed to continuously enhancing the security of our products, strengthening our secure software development practices, increasing transparency around product vulnerabilities, and supporting our customers as cybersecurity regulations -including the European Union Cyber Resilience Act - continue to evolve.

We will continue to monitor regulatory developments, engage with industry best practices, and update our products, processes, and customer guidance as appropriate to help customers confidently deploy Everpure solutions in regulated and security-sensitive environments.