PSIRT_UWS

Safe products in accordance with the CRA Act


From December 11, 2027, only CRA-compliant products may be placed on the market. INSEVIS has considered compliance with cybersecurity requirements in its development from the very beginning. With the development of SBOMs, threat analyses, and the establishment of a vulnerability reporting system and a security guideline in accordance with the CRA law for the secure use of products, the path to the long-term use of all INSEVIS products has been paved.

Cooperation with other providers at CERT@VDE


VDECERT

INSEVIS is collaborating with CERT@VDE, the first platform for coordinating IT security issues specifically for companies in the industrial automation sector. It offers manufacturers, integrators, plant engineers, and operators in the industrial automation field the opportunity for intensive and confidential information exchange and concrete support regarding cybersecurity.

In addition to its technical newsletters, INSEVIS communicates its security-related updates, patches, and guidelines to you, as a buyer or user of INSEVIS controllers, via CERT@VDE, the central coordination point. Stay informed and utilize the services and database of CERT@VDE to secure and maintain the safety of your systems.

Improve product security – Report security vulnerabilities



Why report vulnerabilities?

We cannot identify every vulnerability ourselves – therefore, we rely on your support. Please contact us. psirt@insevis.de. Your information will be forwarded exclusively to the INSEVIS PSIR team. Access by unauthorized employees or external third parties is impossible.


What happens to your report?

INSEVIS treats the identity and contact details of the reporter with strict confidentiality. INSEVIS PSIRT carefully reviews each reported vulnerability, contacts you as soon as possible, and keeps you informed of the progress.


Latest security news

Security-relevant messages about
INSEVIS products can be found on the website of the CERT@VDE.

An RSS/Atom feed is also available here.


Questions about cybersecurity?

Do you have further questions about security? Contact us. Our PSIRT team will be happy to assist and advise you. psirt@insevis.de


Report a security problem

If you suspect you have discovered a potential security vulnerability in one of our products or services, please inform our PSIR team or the CERT@VDE under:
https://cert.vde.com/de/more/report-a-vulnerability


INSEVIS PSIRT Public Keys

FFor secure communication with our PSIRT team at psirt@insevis.de We provide the public keys here. Our security team will support you on German and English. If possible, please send confidential information to us in encrypted form. https://www.insevis.de/.well-known/csaf/openpgp/psirt@insevis.de-0xDF6AA6CE9942F0B7-public.asc

CRA-relevant documents



Cybersecurity Guideline

This document describes the CRA-compliant use and disposal of INSEVIS products so that your solution can also be certified as compliant with CRA requirements.
-> Document name.PDF


Treatment of weaknesses

This vulnerability treatment and disclosure process includes the following points:
1. Notification: Receipt/Registration
2. Analysis: Risk assessment/root cause analysis.
3. Processing: Development, testing and

   Provision of updates, patches, etc.
4. Disclosure: Publication and assistance