The EU Cyber Resilience Act (CRA) entered into force on December 10, 2024. Its reporting obligations for actively exploited vulnerabilities and severe security incidents apply from September 11, 2026, while the CRA will become fully applicable from December 11, 2027.
Suprema is committed to complying with the EU Cyber Resilience Act (CRA) and operates a dedicated reporting channel for security vulnerabilities and incidents related to its products.
If you identify a suspected security vulnerability or security incident involving a Suprema product, please report it to the email address below. Please provide sufficient information to help us assess and respond to the issue. Suprema will review submitted reports and may contact the reporter for additional information if necessary.
To ensure that your report is successfully received and processed, the email subject line must include one of the following keywords:
SP-Vulnerability-Report – for reporting a suspected security vulnerability
SP-Incident-Report – for reporting a suspected security incident
Please note that emails without one of the above keywords in the subject line may not be accepted through this reporting channel.
※ Good Faith Reporting
Reports must be submitted in good faith and based on information reasonably believed to be accurate. Please do not submit intentionally false, misleading, or malicious reports, or use this reporting channel for purposes unrelated to security vulnerabilities or incidents.