CVD Policy

ErvoCom takes the security of its products seriously and is committed to identifying and addressing potential security vulnerabilities at an early stage. This Coordinated Vulnerability Disclosure (CVD) Policy describes how security vulnerabilities in ErvoCom products can be responsibly reported and how ErvoCom handles such reports.

1.1 ErvoCom markets hardware and software products that have been developed as components for integration into systems.

1.2 The products meet high quality standards in terms of their durability, range of functions and configuration options, as well as product security.

1.3 To review and update product security, ErvoCom establishes and optimises appropriate processes relating to both the products themselves and the development process.

1.4 To ensure the correct integration of the products into a system by an integrator, ErvoCom provides the relevant product documentation and integration specifications.

2.1 The policy on the coordinated disclosure of product security vulnerabilities was published on 1 September 2026.

2.2 ErvoCom reserves the right to amend the policy in accordance with the requirements of the Cyber Resilience Act (CRA) and standard industry implementation guidelines.

2.3 The current version will be replaced by a revised version by 1 September 2027 at the latest.

2.4 The policy is published on the ErvoCom website in German and English.

2.5 Reports submitted by users will be processed in accordance with the policy in force at the time of the report. This applies regardless of when the product was purchased or the system was placed on the market. 

3.1 Cases of actively exploited vulnerabilities and serious security incidents relating to the products may be reported by all users via the form presented on the ErvoCom homepage. 

3.2 Reports of security incidents relating to ErvoCom but not specifically linked to the product may be submitted by all users via the address ict@ervocom.ch

3.3 These designated accounts support the transmission of encrypted messages using ErvoCom’s public key 

4.1 ErvoCom reserves the right to reject reports if they breach the code of conduct relating to product security reports.

4.2 The following are defined as breaches of the Code of Conduct:

  • Lack of reference to the product
  • Lack of reference to the integrator and the system context of the integration
  • Bulk reports without specific verification
  • Reporting of a vulnerability that has already been published
  • The vulnerability was actively exploited by the reporter
  • An attack was carried out on the infrastructure of ErvoCom or its customers
  • Tools for exploiting vulnerabilities were offered by the reporter to third parties for the purpose of carrying out attacks

4.3 Specifically for products marketed as CRA-compliant, a report may also be rejected if:

  • The product was sold by ErvoCom but not launched onto the market by ErvoCom
  • The stated intended use of the product was clearly violated

5.1 In the context of the CVD Policy, ErvoCom distinguishes between the USER as a general term and the INTEGRATOR as a specific user group.

5.2 Integrators occupy a special position with regard to the handling of product security reports and the disclosure of vulnerabilities. This special status derives from the intended use of the product, which provides for integration into a system under certain integration conditions.

5.3 Integrators are typically ErvoCom’s contract customers who procure the components and integrate them into a higher-level product

5.4 The role of integrator may also be assigned to third parties in consultation with the contract customer

5.5 The role of integrator may be assumed by ErvoCom itself

5.6 The role of the integrator encompasses both the physical and functional aspects of integration and may be further subdivided under the integrator’s responsibility

6.1 Upon receipt of a report from a user by ErvoCom, an assessment is carried out jointly by ErvoCom, as the manufacturer, and the system’s INTEGRATOR. This assessment constitutes the point at which knowledge is acquired and serves as the starting point for the relevant time limits.

6.2 For this purpose, the Integrator must be identified, directly or indirectly, by the person making the report

6.3 Upon becoming aware of a report from a user regarding an exploited vulnerability, the following shall be provided to the competent authorities:

  • Within 24 hours of becoming aware: an early warning specifying the Member States where, to ErvoCom’s knowledge, the PDE has been made available
  • Within 72 hours of becoming aware: Information on the nature of the security incident, an initial assessment, measures already taken by the manufacturer, and steps users can take
  • No time limit: definition of the measures
  • Within 14 days of the measures being defined: final report

6.4 Upon becoming aware of a report of a serious security incident by a user, the following shall be submitted to the competent authorities:

  • Within 24 hours of becoming aware of the incident: an early warning stating whether there is a suspicion of unlawful or malicious acts, specifying, where applicable, the Member States in which the PDE was made available, to the best of ErvoCom’s knowledge
  • Within 72 hours of becoming aware of the incident: information on the nature of the security incident, an initial assessment and measures already taken by ErvoCom, and, where applicable, measures that users can take.
  • Within 1 month of providing the information: a final report

6.5 For the purpose of obtaining information, ErvoCom shall share the report, including the relevant details provided by the reporter, with the integrator.

6.6 If the role of integrator cannot be assigned, the owner of the system shall be regarded as the integrator

6.7 The competent authorities shall be the reporting office at ErvoCom’s registered office and the country in which the infrastructure is operated. For mobile infrastructure, such as rail vehicles, the report shall be made only in the country where the majority of operations take place.

6.8 The notification to the authorities is not made public in order to avoid the risk of attacks before protective measures are implemented on the systems.

7.1 ErvoCom publishes information on product vulnerabilities with the aim of ensuring that protective measures are implemented promptly on the product and/or on the system into which the product has been integrated.

7.2 Vulnerability Publishing is restricted to products offered and sold by ErvoCom as CRA compliant products

7.3 In view of the fact that the products are used as components of a system, ErvoCom may restrict publication to the group of product integrators or those responsible for operating the system infrastructure.

7.4 The publication is made without providing any details that would allow the identification of the infrastructure that was the target of an attack

7.5 This information includes:

  • Details of reports submitted to the authorities
  • The current product release
  • Vulnerabilities that are rectified in the current product release