Cyber Resilience Act (CRA)
Security of our digital products
The security of our products and digital services is a priority.
In compliance with Regulation (EU) 2024/2847 – Cyber Resilience Act (CRA), we adopt processes and measures aimed at ensuring the security of products with digital elements throughout their entire lifecycle.
Vulnerability Management
We continuously monitor our products in order to identify and manage any security vulnerabilities.
Activities include:
- identification and assessment of vulnerabilities;
- analysis of security impacts;
- development and distribution of security updates;
- monitoring of publicly known vulnerabilities;
- management of vulnerabilities reported by users, researchers and third parties.
Vulnerability Reporting
If you have identified a potential security vulnerability in one of our products, you can report it to us using the following channel:
Security Team
Email: ti.spanys@ofni
Where possible, we ask you to include:
- affected product and version;
- description of the vulnerability;
- conditions required to reproduce the issue;
- any logs, evidence or useful technical information;
- contact information so that we can get back to you.
Coordinated Vulnerability Disclosure
We have adopted a Coordinated Vulnerability Disclosure (CVD) policy for managing security vulnerabilities reported by users, researchers and third parties.
Reports received are analyzed, assessed and managed according to a structured process aimed at diagnosing, mitigating and resolving vulnerabilities before their potential public disclosure.
Management and Reporting of Vulnerabilities and Security Incidents
In the event of an actively exploited vulnerability or a serious incident affecting the security of a product with digital elements, the company activates its internal incident management process and proceeds with the notifications required by the Cyber Resilience Act through the channels and within the timeframes established by the Regulation.
Notifications required under Article 14 of the CRA are submitted through the Single Reporting Platform (SRP) provided for by Article 16 of the Regulation, in accordance with the procedures and to the competent entities established by the CRA.
Reports relating to actively exploited vulnerabilities are managed according to the timeframes established by the CRA:
- within 24 hours of becoming aware of the actively exploited vulnerability, an early warning is submitted;
- within 72 hours of becoming aware of the vulnerability, the vulnerability notification is submitted;
- within 14 days of a corrective or mitigating measure becoming available, the final report is submitted, as required by the Regulation.
For serious incidents that have an impact on the security of the product with digital elements:
- within 24 hours of becoming aware of the incident, an early warning is submitted;
- within 72 hours of becoming aware of the incident, the incident notification is submitted;
- within one month of submitting the incident notification, the final report is submitted, as required by the Regulation.
The internal process also ensures the collection of the information necessary for the assessment, mitigation and communication of security events.
In the event of an actively exploited vulnerability or a serious incident that may have an impact on users, information concerning the event and the available corrective or mitigating measures is provided where necessary.
Security Updates
When a vulnerability requiring action is identified, we will assess the necessary actions and, where applicable, promptly make corrective or security updates available. Updates may be distributed through the product's standard update channels.
Product Information
For each product with digital elements, we provide information relating to:
- product identification and version;
- security features;
- update procedures;
- support period and corresponding end date;
- vulnerability reporting procedures;
- any published security advisories.
Contacts
For information relating to the security of our products or the Cyber Resilience Act:
Security Team
Email: ti.spanys@ofni
Last updated: 07/09/2026