Cyber Resilience Act (CRA)
The Cyber Resilience Act (CRA) introduces new EU requirements for the cybersecurity of products with digital elements. The regulation aims to improve security standards for devices and software across their entire lifecycle. The CRA obliges manufacturers to consider cybersecurity from the product development stage and to ensure it throughout the entire product lifecycle. This includes, among other things:
- assessing potential security risks
- providing security updates
- informing customers about known vulnerabilities
- support in the event of security incidents
We at Bluhm Weber Group are closely following the development of the Cyber Resilience Act and are already working on assessing our products as well as on the necessary organisational and technical measures. In doing so, we can build on existing structures and processes that we have already established under other regulatory requirements – for example, the Machinery Directive. These include, among other things:
- structured product documentation
- risk assessments
- clear development and approval processes
An important foundation is also our existing TISAX® certification, which demonstrates that our development and IT environments meet high requirements for information security. These established security structures support us in systematically implementing the future requirements of the Cyber Resilience Act.
Strengthening security together – Our PSIRT
Have you discovered a vulnerability or security incident in one of our products? Our Product Security Incident Response Team (PSIRT) is happy to receive your report. We take every report seriously, handle it confidentially and promptly, to ensure the security of all users quickly and transparently. Here is how the reporting process works:
- Fill in our form to report the vulnerability or security incident
- You will receive a prompt acknowledgement of receipt
- Our team reviews the report, reproduces it in an isolated test environment, and assesses the impact according to CVSS v3.1.
- You will be informed about the processing status and receive guidance and updates on resolving the issue
A shared foundation: Our Code of Conduct
Confidential communication and respectful interaction are the foundation of successful security work. That is why we have established clear agreements for both sides:
Our commitment to you- Prompt acknowledgement and feedback on your case
- Strict confidentiality of your identity and all report content
- Information exchange exclusively with authorised participants
- Allow us sufficient time for investigation and remediation before details are made public
- Do not impair or disrupt systems in production use during security checks, do not modify or delete data, and do not carry out denial-of-service attacks.
- Provide contact details
Standards & Compliance
Our processes are aligned with CRA requirements and are based on the BSI's Technical Guidelines (TR-03183 series). Using Software Bills of Materials (SBOM) and established monitoring tools, we ensure your protection. Our tool continuously checks official vulnerability databases for known security flaws in the components we use. This ensures that we can respond promptly when vulnerabilities are disclosed.