top of page

Transparency Is Part of Security — A Channel for Reporting Vulnerabilities

Sep 11
2 min read
White shield-and-checkmark icon inside a circle of EU stars, overlaid on a blue-toned image of a robotic arm and Orfer-branded packaging line. Text reads "CRA – Cyber Resilience Act".

Connected automation systems bring efficiency to production, but they also open up a new risk surface. The EU is responding to this development with the Cyber Resilience Act (CRA) — a regulation that fundamentally changes how manufacturers of connected devices and software must handle and report discovered vulnerabilities.


Preparedness is a positive thing when security is built into products from the start. It lays the foundation for securing the entire supply chain.


What is the Cyber Resilience Act?


The CRA (Regulation 2024/2847) has been in force since 10 December 2024, and its obligations take effect in stages. Two dates are especially important:

  • 11 September 2026 — manufacturers must begin actively reporting actively exploited vulnerabilities and severe security incidents to ENISA, the EU Agency for Cybersecurity. An early-warning notification must be submitted within 24 hours of detection, followed by a more detailed report and a final report.

  • 11 December 2027 — the regulation becomes fully applicable, including CE marking and conformity assessment.

In practice, the CRA requires manufacturers to ship products free of known exploitable vulnerabilities, provide security updates throughout the product's entire lifecycle, and build a clear process for receiving and fixing vulnerabilities.


Why does this matter for industrial automation?


The automation and robotics systems Orfer delivers contain digital elements — control systems, network connections, and software — that fall within the scope of the CRA. This means responsibility doesn't end at system delivery; it continues throughout the system's entire operational life.


How can you report a vulnerability to Orfer?


We've built a clear channel for our customers and security researchers to report discovered vulnerabilities at orfer.com/security-advisories. On the page, you can describe the vulnerability found, its impact, and the possible attack vector (the route or method an attacker would use). Vulnerability reports are handled without delay and fixed as quickly as possible. As recognition for the report, we credit the finder by name in published materials, if they wish.


Security is a continuous process

Glowing teal padlock icon containing a shield with a keyhole and wireless signal symbol, set against a dark blue background.

The CRA's timeline gives the entire industry a clear target, but for Orfer, responsible vulnerability management isn't just about regulatory compliance — it's part of how we build automation solutions that can be trusted well into the future. If you notice anything unusual in your control systems, network connections, or software, please get in touch.


 
 
bottom of page