Secure products in accordance with the CRA

From 11 December 2027, only CRA-compliant products may be placed on the market. INSEVIS has taken cybersecurity requirements into account in its developments from the outset. By developing SBOMs, conducting threat analyses, establishing a vulnerability reporting system and creating a security guideline in accordance with the requirements of the CRA for the secure use of the products, the path has been paved for the long-term use of all INSEVIS products.

Cooperation with other providers through CERT@VDE

INSEVIS works with CERT@VDE, the first platform for coordinating IT security issues specifically for companies in the industrial automation sector. It offers manufacturers, integrators, plant engineering companies and operators in the industrial automation sector the opportunity for intensive and trusted information exchange, as well as concrete support with cyber security.

In addition to its technical newsletters, INSEVIS communicates security-relevant updates, patches and recommended actions via CERT@VDE, the central coordination point, to you as a buyer or user of INSEVIS controllers. Stay informed and use the services and database of CERT@VDE to make and keep your systems secure.

Improve product security – report security vulnerabilities

Why report?

We cannot identify every vulnerability ourselves – that is why we rely on your support. Please contact psirt@insevis.de. Your information will be forwarded exclusively to the INSEVIS PSIRT team. Access by unauthorised employees or external third parties is excluded.

What happens to your report?

INSEVIS treats the identity and contact details of the reporter as strictly confidential. INSEVIS PSIRT carefully examines every reported vulnerability, contacts you as quickly as possible and keeps you informed about the further progress.

Current security advisories

Security-related notifications concerning INSEVIS products can be found on the website of CERT@VDE.

An RSS/Atom feed is also available here.

Questions about cyber security?

Do you have any further questions about security? Please contact us. Our PSIRT team will be happy to support and advise you: Email PSIRT

Report a security issue

If you suspect that you have discovered a potential security vulnerability in one of our products or services, please inform our PSIR team or CERT@VDE at:
https://cert.vde.com/de/more/report-a-vulnerability

INSEVIS PSIRT Public Keys

INSEVIS PSIRT Public Keys
For secure communication with our PSIR team at psirt@insevis.de we provide the public keys here. Our security team supports you in German and English. Where possible, we ask you to send us confidential information in encrypted form.

Encrypted email

CRA-relevant documents

Security Guideline

This document describes the CRA-compliant use and disposal of INSEVIS products, so that your solution can also be certified as compliant with the CRA requirements.

Vulnerability handling

This vulnerability handling and disclosure process includes the following points:

  1. Report: Receipt/registration
  2. Analysis: Risk assessment/root-cause investigation.
  3. Processing: Development, testing and
    provision of updates, patches, etc.
  4. Disclosure: Publication and assistance