Cybersecurity at EnOcean 

EnOcean is committed to the security of its products, software and related digital services. 

EnOcean operates an ISO/IEC 27001-certified information-security management system. Our Information Security Policy requires security to be integrated into products, software and services by design, supporting the protection of confidentiality, integrity, availability and authenticity throughout the lifecycle. 

Our information-security management system includes: 

  • formal risk assessment and risk-treatment processes; 
  • defined roles and responsibilities for security governance; 
  • documented controls covering, among other areas, access management, cryptography, supplier security and operational security; 
  • continuous monitoring, internal audits and management review. 

Cyber Resilience Act 

The Cyber Resilience Act, Regulation (EU) 2024/2847, establishes cybersecurity requirements for hardware and software products with digital elements placed on the EU market. It covers product planning, design, development, production, vulnerability handling, security updates and lifecycle support. 

The Regulation entered into force on 10 December 2024 and applies in phases: 

CRA milestone Date 
Member States may designate notified bodies 11 June 2026 
Vulnerability-reporting and incident-reporting obligations apply 11 September 2026 
Main CRA product cybersecurity requirements apply 11 December 2027 

EnOcean’s CRA compliance approach 

EnOcean is implementing the CRA in line with its phased application. 

For the requirements applying from September 2026, EnOcean has established and is maintaining processes for: 

  • receiving and assessing product-security vulnerability reports; 
  • communicating with reporters and, where appropriate, affected users; 
  • handling product vulnerabilities through a risk-based process; 
  • reporting actively exploited vulnerabilities and severe product-security incidents to the competent authorities where required; and 
  • maintaining supporting vulnerability-management, incident-management and documentation processes. 

These processes build on EnOcean’s existing ISO/IEC 27001-certified information-security management system. 

In parallel, EnOcean is continuing its preparation for the wider CRA requirements that apply from December 2027. Our CRA implementation programme is reviewed and developed as the remaining requirements become applicable and as relevant regulatory guidance and applicable standards mature. 

Report a security vulnerability 

In this regard, EnOcean welcomes good-faith reports of potential cybersecurity vulnerabilities affecting EnOcean products. We assess reported issues, provide relevant information and mitigation guidance to affected users where appropriate, and fulfil applicable regulatory-notification obligations. 

Email: cra@enocean.com 
Suggested subject line: Security vulnerability report 

Please provide, where available: 

  • the affected EnOcean product, model, hardware revision and firmware or software version; 
  • a clear description of the issue and its potential security impact; 
  • safe reproduction steps, logs, screenshots or proof-of-concept material; 
  • relevant configuration, access requirements or affected interfaces; and 
  • your contact details, where you would like to receive updates. 

For sensitive material, please contact us first without attaching the material. We will provide an appropriate secure-transfer method where needed. 

Please check the details in our Coordinated Vulnerability Disclosure Policy below. 

What happens after you report an issue 

EnOcean operates a risk-based vulnerability-management process. We assess whether a reported issue affects an EnOcean product in its actual configuration, whether the affected functionality is relevant or reachable, and whether the issue is exploitable in practice. 

Step Service target 
Receipt acknowledgement Within 3 business days 
Initial assessment Within 10 business days, where sufficient information is available 
Status updates for validated reports At least every 10 business days, unless another timeline is agreed or security, legal or operational considerations limit the detail that can be shared 

Reports indicating active exploitation, widespread exposure, or an immediate risk to confidentiality, integrity, authenticity or availability are prioritised for prompt assessment. 

These are service targets, not fixed remediation deadlines. The appropriate corrective action and timeline depend on factors such as severity, exploitability, user exposure, technical complexity and required validation. 

For further detail, please see our Coordinated Vulnerability Disclosure Policy below. 

Responsible disclosure 

Please act in good faith and avoid causing harm while investigating or reporting a potential issue. In particular, please do not: 

  • access, alter, delete or extract data that does not belong to you; 
  • disrupt EnOcean systems, customer environments or third-party services; 
  • use phishing, social engineering, physical intrusion, denial-of-service testing or extortion; or 
  • publicly disclose the issue before coordinating with EnOcean, unless disclosure is required by law. 

EnOcean will not seek legal action solely because a person reports a vulnerability in good faith and in line with these principles. This does not apply to conduct that causes harm, violates applicable law or goes beyond what is reasonably necessary to demonstrate the issue. 

Security advisories and customer information 

EnOcean does not publish every automated scanner finding or every third-party dependency notice. A vulnerability notice relating to a software component does not automatically mean that an EnOcean product is affected. 

Where a vulnerability affecting an EnOcean product has been fixed and a security update or other corrective measure is available, EnOcean will publish appropriate security information. Depending on the case, this may include the affected product and versions, impact, severity, available update or mitigation, and actions users should take. 

Where EnOcean becomes aware of an actively exploited vulnerability or a severe product-security incident, we will inform impacted users and, where appropriate, all users about the issue and available mitigation or corrective measures. 

Coordinated Vulnerability Disclosure Policy 

For full details on reporting, communication, confidentiality, coordinated disclosure, customer notifications and SBOM-related information, please read our: 

Product support and security updates 

Security-support information, product documentation and update instructions are provided through the relevant EnOcean product and support channels. Product-support questions that do not concern a cybersecurity vulnerability should be directed through the usual EnOcean support channels. 

Contact and enquiry routing 

For the fastest response, please use the contact channel that matches your request: 

Your enquiry Contact 
Report a potential cybersecurity vulnerability in an EnOcean product cra@enocean.com 
General questions about EnOcean’s regulatory compliance, certifications or sustainability/compliance topics compliance@enocean.com 
Technical product support, product functionality, documentation, configuration or general customer support support@enocean.com 
Quality issues, returns, repair or RMA procedures RMA@enocean.com 

Please use cra@enocean.com to report a potential cybersecurity vulnerability affecting an EnOcean product, software, firmware, application or related digital service. 

Examples may include: 

  • a possible way to gain unauthorised access to an EnOcean product, device, account, interface or related service; 
  • suspected weaknesses in authentication, authorisation, encryption, secure communication or access control; 
  • a vulnerability that could affect the confidentiality, integrity, authenticity or availability of product data or functions; 
  • a suspected security issue in EnOcean firmware, software, an application, a product interface or a remote data-processing service; 
  • evidence that a known third-party component vulnerability may be exploitable in an EnOcean product; or 
  • suspected active exploitation of a vulnerability affecting an EnOcean product. 

Please do not use this channel for matters that do not concern a potential cybersecurity vulnerability, such as: 

  • general product-operation, configuration or installation questions; 
  • requests for product documentation, manuals, software downloads or feature information; 
  • product returns, repair requests, warranty claims or RMA procedures; 
  • delivery, order, commercial or pricing enquiries; 
  • general quality feedback that does not involve a cybersecurity concern; or 
  • general compliance, certification or sustainability enquiries. 

For these matters, please use the relevant EnOcean support, RMA or compliance contact channels. 

Contact
us