CRA-Compliance at Schmid Elektronik

Coordinated Vulnerability Disclosure Policy

Introduction

We take the security of our products seriously. This Coordinated Vulnerability Disclosure (CVD) Policy describes how security researchers, customers, and third parties can report potential security vulnerabilities in our products or services. This policy is established in accordance with the EU Cyber Resilience Act (CRA) requirements for coordinated vulnerability disclosure.

Scope

The policy applies to products or components of products manufactured or maintained by Schmid Elektronik AG.

This includes:

  • Firmware
  • Software
  • Cloud services
  • Web interfaces
  • APIs

Reports concerning vulnerabilities in third-party components incorporated into our products are also welcome. Where appropriate, we will coordinate with the relevant component supplier or maintainer.

Reporting a Vulnerability

If you discover a potential security vulnerability, please report it to us using one of the following channels:

Please include the following information where possible:

  • Product name and version
  • Software version
  • Description of the vulnerability
  • Steps to reproduce
  • Your contact information

Reporters may request an embargo period (typically up to 90 days)

We may request extensions if a fix requires more time

Guidelines

We ask that you:

  • Do not publicly disclose the vulnerability before coordination
  • Avoid accessing personal data unnecessarily
  • Avoid disrupting services or damaging systems
  • Do not conduct social engineering, spam, or phishing attacks (unless mutually agreed)
  • Act in good faith

We will not take legal action against researchers who follow this policy, act in good faith and respect applicable laws.

Our Commitments

When you report a vulnerability, we commit to:

  • Acknowledge receipt within 5 working days
  • Keep you informed about remediation progress
  • Coordinate public disclosure where appropriate

Contact

Primary contact: https://schmid-elektronik.ch/security-vulnerability-report-form/

Policy Updates

We may update this policy periodically.

Last updated: 11.08.2026