News


Cyber Resilience Act: CEDES establishes PSIRT as central reporting point

09/18/2026
As of September 11, 2026, the first mandatory reporting obligations under the EU Cyber Resilience Act (CRA) come into effect. By introducing a Product Security Incident Response Team (PSIRT), CEDES has established the organizational framework to meet these requirements and further strengthen the security of our products.

The Cyber Resilience Act (CRA) is the first European regulation to establish a minimum level of cybersecurity for all connected products available on the EU market. Its objective is to enhance cybersecurity across the European Union. The new requirements apply in all EU Member States and are being implemented gradually. 

All products sold within the EU that contain "digital elements" must comply with the requirements of the CRA. This includes not only low-cost consumer products, but also B2B software and complex high-end industrial systems. Under the CRA, "products with digital elements" are defined as products, including their remote data processing solutions, that can be connected directly or indirectly to a device or network. Manufacturers of such products are required to report actively exploited vulnerabilities and severe security incidents through the centralized EU reporting platform operated by ENISA (European Union Agency for Cybersecurity). 

To comply with these regulatory obligations, CEDES has established a Product Security Incident Response Team (PSIRT). The PSIRT serves as the central point of contact for communicating product security-related vulnerabilities and security incidents with external stakeholders such as customers, suppliers, security researchers, and regulatory authorities. Its responsibilities include the intake, assessment, coordination, remediation, and communication of security vulnerabilities and security incidents affecting CEDES products. The PSIRT informs customers and suppliers about identified vulnerabilities, available security updates, workarounds, and other protective measures by publishing Security Advisories that provide guidance for mitigating potential risks. 

Detailed information and recommendations can be found on our PSIRT page . If you would like to report a potential vulnerability or security incident, a dedicated contact form is available. By reporting potential vulnerabilities at an early stage, you actively contribute to minimizing risks and continuously improving the security of our products.

Close