EU CRA Website Compliance Statement and Security Reporting Mechanism-English Version
EU CRA Website Compliance Statement and Security Reporting Mechanism-English Version
EU Cyber Resilience Act Compliance and Product Security Reporting
Protech is committed to managing cybersecurity risks throughout the product lifecycle. Based on the nature and intended use of each product and the applicable legal requirements, we maintain risk assessment, vulnerability handling, security update and incident response processes for products with digital elements placed on the European Union market under Regulation EU 2024 2847, the Cyber Resilience Act or CRA.
Our Commitment
- Apply risk-appropriate cybersecurity measures during design, development, production and maintenance.
- Identify, document and address product vulnerabilities and provide patches, firmware or other mitigations when required.
- Maintain relevant product and software component records and monitor vulnerabilities in accordance with applicable requirements.
- Inform affected customers or users of known matters impacting product security when required by risk and applicable law.
- From 11 September 2026, notify qualifying actively exploited vulnerabilities and severe incidents through the ENISA CRA Single Reporting Platform to the appropriate CSIRT and ENISA as required by the CRA.
Report a Product Security Issue
If you identify a suspected vulnerability, unauthorised access, abnormal data or product behaviour, evidence of malicious exploitation, or another issue that may affect the confidentiality, integrity, availability or authenticity of our product, please contact us through one of the channels below.
| Channel | Contact |
|---|---|
| Security e-mail | 〔security e-mail〕 |
| Security reporting form | Based on the RMA Sheet |
Do not disclose directly exploitable technical details, credentials, personal data or customer-confidential information through public comments, social media or unsecured communications. If the issue may pose an immediate risk to personal safety or critical operations, mark the subject line “URGENT SECURITY INCIDENT”.
Information to Include
- Product name, model and serial number
- Firmware, BIOS, operating system, driver or software version.
- Discovery time, reproduction steps, affected scope and observed behaviour.
- Relevant logs, packet captures, screenshots or proof of concept, with unnecessary personal or confidential data removed.
- Reporter name, organisation and contact details.
CRA Regulatory Notification Timelines
The timelines below run from the time the company becomes aware that the applicable reporting threshold is met. They are regulatory obligations of the company and do not mean that every customer report will be submitted to authorities. The company will classify and assess reports promptly, and an internal investigation must not delay a required notification.
| Event or Stage | Deadline |
|---|---|
| Actively exploited vulnerability or severe incident | Early warning within 24 hours of awareness |
| Same event | Full notification and initial assessment within 72 hours of awareness |
| Actively exploited vulnerability | Early warning within 24 hours of awareness |
| Severe incident | Full notification and initial assessment within 72 hours of awareness |
Responsible Disclosure and Confidentiality
We welcome good-faith, lawful security research conducted in a manner that avoids harm. Reporters should avoid unnecessary access to data, service disruption, alteration or deletion of information, malware deployment, or publication of exploitable details before the company has had a reasonable opportunity to remediate. Reports are handled on a need-to-know basis, and personal data is processed under our 〔Privacy Policy URL〕. This statement is not an authorisation for unlawful activity, a promise of reward or a waiver of rights.
Version and Notice
This page provides Protech’s public product security contact and CRA readiness statement. The applicability of the CRA, a particular conformity assessment route or product-specific obligation must be determined from the product functions, intended purpose, supply model and formal technical documentation. This page does not replace a contract, statutory declaration of conformity, user instructions or security update notice. Last updated: 〔YYYY MM DD〕.