CVD Policy
Vulnerability reporting
If you have identified a potential vulnerability in FRIEM products, we encourage you to report it to us promptly, in accordance with Regulation (EU) 2024/2847 (Cyber Resilience Act – CRA), following the procedure described below.
Vulnerability reporting procedure
To report a potential vulnerability in FRIEM products, please complete the Vulnerability Reporting Form, accessible via the link provided at the bottom of this page.
Please provide all the requested information and, where possible, include sufficient detail to enable the report to be assessed and handled effectively and promptly.
All reports received will be handled by FRIEM in accordance with its Vulnerability Handling Process.
Vulnerability handling
The reporter will receive an acknowledgement of receipt within 5 business days and, where applicable, will subsequently be informed of the progress made in handling the report, in accordance with internal vulnerability handling procedure of FRIEM.
FRIEM takes measures to ensure the confidentiality of the reporter’s identity and contact information. Such information will be treated confidentially and will not be disclosed in public communications.
Reports received will be analysed and assessed by personnel responsible for vulnerability management, who will determine their relevance and potential impact on FRIEM products and will contact the reporter, where necessary, to request additional information or provide updates on the status of the report.
Vulnerability disclosure
FRIEM reviews reports concerning security issues and, where applicable, will communicate validated vulnerabilities to potentially affected users or customers.
Depending on the nature, severity and potential impact of the vulnerability, information may be communicated through direct communications to affected customers, dedicated cybersecurity newsletters, or other appropriate channels.
The method and timing of such communications will be determined based on the nature, severity and impact of the vulnerability, as well as any applicable legal or regulatory communication and notification requirements.