Wincomm Product Security and Coordinated Vulnerability Disclosure Policy
The New Age of Cybersecurity: Are You Ready?
As
digital transformation accelerates, cybersecurity threats are evolving
fast—forcing tighter regulations and proactive defense strategies. The EU’s
latest mandates, including NIS2, the Cyber Resilience Act (CRA), and the Radio
Equipment Directive Delegated Act (RED DA), mark a global shift toward strict
security governance. To stay ahead, organizations must adopt robust security
frameworks and align with mandatory industry standards.
| Regulation | Who is affected? | Which products/sectors matter? | Penalties |
|---|---|---|---|
| CRA | Manufacturers, distributors and importers of products with digital elements | Software and hardware products with a direct or indirect data connection to another device or network |
|
Cyber Resilience Act (CRA)
The Cyber Resilience Act (CRA) is an EU regulation designed to strengthen the security of products with digital elements. It applies to both hardware and software capable of direct or indirect network connections. To comply, manufacturers must build quality and security into their products before release—which includes providing secure and timely security updates, including automatic security updates where applicable, and adhering to mandatory incident reporting.
Wincomm Corporation Coordinated Vulnerability Disclosure Policy
Wincomm corporation is committed to the cybersecurity of its products. We welcome security researchers, customers, and partners to responsibly report security vulnerabilities discovered in our products.
Effective Date:
Two-phase implementation
- Vulnerability-Disclosure Obligations, Sep. 11, 2026
- Full implement, Dec. 11, 2027
Scope
- Products with digital elements, encompassing both hardware and software, that are connected to a network or device.
- This policy is established pursuant to the EU Cyber Resilience Act, Regulation (EU) 2024/2847, and ISO/IEC 29147:2018.
References
- Regulation (EU) 2024/2847, Cyber Resilience Act
- Article 13, Obligations of manufacturers
- Article 30, CE marking
- Annex II, Information and instructions to the user
- Annex V / Annex VI, EU Declaration of Conformity
- Annex VII, Technical Documentation
- EN ISO/IEC 29147:2020, Vulnerability Disclosure
- EN
ISO/IEC 30111:2020, Vulnerability Handling Processes
Disclaimer: The technical architecture, compliance strategies, projected timelines, and future objectives set forth in this announcement are provided for informational purposes only and do not constitute any legal, commercial, or contractual guarantee. Product functional specifications, methods for providing Software Bill of Materials (SBOM), cybersecurity update policies, and post-sales support services shall be governed exclusively by the executed agreements, product specifications, and official technical documentation executed by both parties.
Single Point of Contact for Product Security
Security vulnerabilities affecting Wincomm products please reported to: