
Cybersecurity at EnOcean
EnOcean is committed to the security of its products, software and related digital services.
EnOcean operates an ISO/IEC 27001-certified information-security management system. Our Information Security Policy requires security to be integrated into products, software and services by design, supporting the protection of confidentiality, integrity, availability and authenticity throughout the lifecycle.
Our information-security management system includes:
- formal risk assessment and risk-treatment processes;
- defined roles and responsibilities for security governance;
- documented controls covering, among other areas, access management, cryptography, supplier security and operational security;
- continuous monitoring, internal audits and management review.
Cyber Resilience Act
The Cyber Resilience Act, Regulation (EU) 2024/2847, establishes cybersecurity requirements for hardware and software products with digital elements placed on the EU market. It covers product planning, design, development, production, vulnerability handling, security updates and lifecycle support.
The Regulation entered into force on 10 December 2024 and applies in phases:
| CRA milestone | Date |
| Member States may designate notified bodies | 11 June 2026 |
| Vulnerability-reporting and incident-reporting obligations apply | 11 September 2026 |
| Main CRA product cybersecurity requirements apply | 11 December 2027 |
EnOcean’s CRA compliance approach
EnOcean is implementing the CRA in line with its phased application.
For the requirements applying from September 2026, EnOcean has established and is maintaining processes for:
- receiving and assessing product-security vulnerability reports;
- communicating with reporters and, where appropriate, affected users;
- handling product vulnerabilities through a risk-based process;
- reporting actively exploited vulnerabilities and severe product-security incidents to the competent authorities where required; and
- maintaining supporting vulnerability-management, incident-management and documentation processes.
These processes build on EnOcean’s existing ISO/IEC 27001-certified information-security management system.
In parallel, EnOcean is continuing its preparation for the wider CRA requirements that apply from December 2027. Our CRA implementation programme is reviewed and developed as the remaining requirements become applicable and as relevant regulatory guidance and applicable standards mature.
Report a security vulnerability
In this regard, EnOcean welcomes good-faith reports of potential cybersecurity vulnerabilities affecting EnOcean products. We assess reported issues, provide relevant information and mitigation guidance to affected users where appropriate, and fulfil applicable regulatory-notification obligations.
Email: cra@enocean.com
Suggested subject line: Security vulnerability report
Please provide, where available:
- the affected EnOcean product, model, hardware revision and firmware or software version;
- a clear description of the issue and its potential security impact;
- safe reproduction steps, logs, screenshots or proof-of-concept material;
- relevant configuration, access requirements or affected interfaces; and
- your contact details, where you would like to receive updates.
For sensitive material, please contact us first without attaching the material. We will provide an appropriate secure-transfer method where needed.
Please check the details in our Coordinated Vulnerability Disclosure Policy below.
What happens after you report an issue
EnOcean operates a risk-based vulnerability-management process. We assess whether a reported issue affects an EnOcean product in its actual configuration, whether the affected functionality is relevant or reachable, and whether the issue is exploitable in practice.
| Step | Service target |
| Receipt acknowledgement | Within 3 business days |
| Initial assessment | Within 10 business days, where sufficient information is available |
| Status updates for validated reports | At least every 10 business days, unless another timeline is agreed or security, legal or operational considerations limit the detail that can be shared |
Reports indicating active exploitation, widespread exposure, or an immediate risk to confidentiality, integrity, authenticity or availability are prioritised for prompt assessment.
These are service targets, not fixed remediation deadlines. The appropriate corrective action and timeline depend on factors such as severity, exploitability, user exposure, technical complexity and required validation.
For further detail, please see our Coordinated Vulnerability Disclosure Policy below.
Responsible disclosure
Please act in good faith and avoid causing harm while investigating or reporting a potential issue. In particular, please do not:
- access, alter, delete or extract data that does not belong to you;
- disrupt EnOcean systems, customer environments or third-party services;
- use phishing, social engineering, physical intrusion, denial-of-service testing or extortion; or
- publicly disclose the issue before coordinating with EnOcean, unless disclosure is required by law.
EnOcean will not seek legal action solely because a person reports a vulnerability in good faith and in line with these principles. This does not apply to conduct that causes harm, violates applicable law or goes beyond what is reasonably necessary to demonstrate the issue.
Security advisories and customer information
EnOcean does not publish every automated scanner finding or every third-party dependency notice. A vulnerability notice relating to a software component does not automatically mean that an EnOcean product is affected.
Where a vulnerability affecting an EnOcean product has been fixed and a security update or other corrective measure is available, EnOcean will publish appropriate security information. Depending on the case, this may include the affected product and versions, impact, severity, available update or mitigation, and actions users should take.
Where EnOcean becomes aware of an actively exploited vulnerability or a severe product-security incident, we will inform impacted users and, where appropriate, all users about the issue and available mitigation or corrective measures.
Coordinated Vulnerability Disclosure Policy
For full details on reporting, communication, confidentiality, coordinated disclosure, customer notifications and SBOM-related information, please read our:
Product support and security updates
Security-support information, product documentation and update instructions are provided through the relevant EnOcean product and support channels. Product-support questions that do not concern a cybersecurity vulnerability should be directed through the usual EnOcean support channels.
Contact and enquiry routing
For the fastest response, please use the contact channel that matches your request:
| Your enquiry | Contact |
| Report a potential cybersecurity vulnerability in an EnOcean product | cra@enocean.com |
| General questions about EnOcean’s regulatory compliance, certifications or sustainability/compliance topics | compliance@enocean.com |
| Technical product support, product functionality, documentation, configuration or general customer support | support@enocean.com |
| Quality issues, returns, repair or RMA procedures | RMA@enocean.com |
Please use cra@enocean.com to report a potential cybersecurity vulnerability affecting an EnOcean product, software, firmware, application or related digital service.
Examples may include:
- a possible way to gain unauthorised access to an EnOcean product, device, account, interface or related service;
- suspected weaknesses in authentication, authorisation, encryption, secure communication or access control;
- a vulnerability that could affect the confidentiality, integrity, authenticity or availability of product data or functions;
- a suspected security issue in EnOcean firmware, software, an application, a product interface or a remote data-processing service;
- evidence that a known third-party component vulnerability may be exploitable in an EnOcean product; or
- suspected active exploitation of a vulnerability affecting an EnOcean product.
Please do not use this channel for matters that do not concern a potential cybersecurity vulnerability, such as:
- general product-operation, configuration or installation questions;
- requests for product documentation, manuals, software downloads or feature information;
- product returns, repair requests, warranty claims or RMA procedures;
- delivery, order, commercial or pricing enquiries;
- general quality feedback that does not involve a cybersecurity concern; or
- general compliance, certification or sustainability enquiries.
For these matters, please use the relevant EnOcean support, RMA or compliance contact channels.