Scope
This CVD Policy applies exclusively to reports relating to the cybersecurity of our products. It is intended in particular for handling product-related vulnerabilities and cybersecurity incidents that affect the cybersecurity of our products in connection with the Cyber Resilience Act. Reports without a relevant product reference do not fall within the scope of this CVD Policy. Statutory, regulatory, or internal reporting procedures remain unaffected.
Identifying vulnerabilities and cybersecurity incidents
The security of our products is a high priority for us. We welcome reports of potential product-related vulnerabilities and cybersecurity incidents at any time. We review and process incoming reports carefully in accordance with a coordinated procedure.
- Please report such vulnerabilities and cybersecurity incidents via the reporting form. Reporting through our reporting form and providing the requested information helps ensure efficient processing of reports. Alternatively, reports may also be submitted via email to vulnerability(at)rovema.de.
- Please do not disclose any details before a coordinated disclosure has taken place or before we have informed you that processing has been completed.
Our handling process
- Receipt and Registration
We register reports submitted through our designated reporting channels. - Validation and Prioritization
We assess plausibility, completeness, affected products, and potential impact and provide an initial response. Prioritization takes into account, in particular, the severity, potential impact, and indications of active exploitation. - Analysis and Initial Measures
Our cybersecurity and product experts investigate the vulnerability or cybersecurity incident. Where necessary, we request additional information, initiate short-term protective or containment measures, and keep the reporting person informed of relevant interim results. - Remediation
Together with the responsible product development teams, we evaluate appropriate measures, such as configuration guidance, workarounds, updates, or patches. The time required for remediation depends on complexity, impact, and the product environment. - Reporting Obligations
Where legally required, we submit reports to the competent authorities within the applicable deadlines. Customer communication is carried out on a risk-based basis and coordinated through security advisories published on our website. Based on our risk assessment, we directly inform affected customers about identified vulnerabilities and cybersecurity incidents where the specific customer and an appropriate contact person are known. This applies only to customers for whom we know the concrete use of our products and where a direct critical impact exists.
Communication and confidentiality
Where appropriate, we keep the reporting person informed about significant steps during the handling process. Information relating to the vulnerability or cybersecurity incident is made available only to those parties who require it for analysis, remediation, legal reporting, or coordinated disclosure.
Data protection
For information regarding data protection, please refer to https://www.rovema.com/en/privacy/