Product Security Center

Wincomm Product Security and Coordinated Vulnerability Disclosure Policy

The New Age of Cybersecurity: Are You Ready?

As digital transformation accelerates, cybersecurity threats are evolving fast—forcing tighter regulations and proactive defense strategies. The EU’s latest mandates, including NIS2, the Cyber Resilience Act (CRA), and the Radio Equipment Directive Delegated Act (RED DA), mark a global shift toward strict security governance. To stay ahead, organizations must adopt robust security frameworks and align with mandatory industry standards.

Regulation Who is affected? Which products/sectors matter? Penalties
CRA Manufacturers, distributors and importers of products with digital elements Software and hardware products with a direct or indirect data connection to another device or network
  • Up to 15 million Euros or 2.5% of annual turnover
  • Product recalls

Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) is an EU regulation designed to strengthen the security of products with digital elements. It applies to both hardware and software capable of direct or indirect network connections. To comply, manufacturers must build quality and security into their products before release—which includes providing secure and timely security updates, including automatic security updates where applicable, and adhering to mandatory incident reporting.

Wincomm Corporation Coordinated Vulnerability Disclosure Policy

Wincomm corporation is committed to the cybersecurity of its products. We welcome security researchers, customers, and partners to responsibly report security vulnerabilities discovered in our products.

Effective Date: 

Two-phase implementation

  • Vulnerability-Disclosure Obligations, Sep. 11, 2026
  • Full implement, Dec. 11, 2027

Scope

  • Products with digital elements, encompassing both hardware and software, that are connected to a network or device. 
  • This policy is established pursuant to the EU Cyber Resilience Act, Regulation (EU) 2024/2847, and ISO/IEC 29147:2018.

References

  • Regulation (EU) 2024/2847, Cyber Resilience Act
  • Article 13, Obligations of manufacturers
  • Article 30, CE marking
  • Annex II, Information and instructions to the user
  • Annex V / Annex VI, EU Declaration of Conformity
  • Annex VII, Technical Documentation
  • EN ISO/IEC 29147:2020, Vulnerability Disclosure
  • EN ISO/IEC 30111:2020, Vulnerability Handling Processes

Disclaimer: The technical architecture, compliance strategies, projected timelines, and future objectives set forth in this announcement are provided for informational purposes only and do not constitute any legal, commercial, or contractual guarantee. Product functional specifications, methods for providing Software Bill of Materials (SBOM), cybersecurity update policies, and post-sales support services shall be governed exclusively by the executed agreements, product specifications, and official technical documentation executed by both parties.

Single Point of Contact for Product Security

Security vulnerabilities affecting Wincomm products please reported to:

Report a Vulnerability

Advisory Category
Advisories
CVE
Date
111 qq qqq 2026-08-27
vvv 222 222 2026-08-27
aaa 111 111 2026-08-27