Cyber Resilience Act (CRA)
Our tools help protect people working in some of the most dangerous environments. To ensure this protection, it is essential that the products and systems they rely on are also safe.
If you believe you have identified a cybersecurity vulnerability in a Sensitron product—whether related to hardware, firmware, or software—we invite you to report it to us promptly using the Coordinated Vulnerability Disclosure (CVD) procedure described below.
This process complies with the principles of the European Union’s Cyber Resilience Act (CRA) and with industry standards for vulnerability reporting and handling, including ISO/IEC 29147 and ISO/IEC 30111. The reports we receive help us safeguard the security of all customers using our equipment and meet the obligations set out in European regulations.
Important: This procedure is intended exclusively for reporting potential cybersecurity vulnerabilities. For technical support requests, malfunctions, or other product-related issues, please use the standard support and service channels.
Please do not make the vulnerability public until we have had a reasonable amount of time to resolve it. We are committed to collaborating with you in accordance with standard CVD timelines.
What we will do once we receive your report
- We will acknowledge receipt of your report within 3 business days.
- We will review the issue and prioritize its resolution based on severity.
- We will keep you updated as we proceed.
- We will coordinate with you regarding the timing of any public communication once the solution is ready.
- We will publish a notice for affected customers outlining the changes made and the actions they need to take.
If a vulnerability is being actively exploited, or is linked to an incident that seriously compromises the product’s cybersecurity, the Cyber Resilience Act requires us to notify ENISA and the relevant national CSIRT.
IN 2026, SENSITRON
TURNS 38
Founded in 1988 in the province of Milan, Sensitron became part of the Halma plc group in 2021.