Products Security and Cyber Resilience Act
What is the Cyber Resilience Act
The Cyber Resilience Act (Regulation (EU) 2024/2847) is the European regulation that introduces mandatory cybersecurity requirements for all products with digital elements placed on the EU market — not only software, but also connected machinery, automation components, IoT devices, and industrial electronics.
The regulation has been in force since December 2024, though its application is being phased in over time. As of September 11, 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents affecting their products to the competent authorities (ENISA and national CSIRTs), following specific channels and timelines. The essential cybersecurity requirements set out in the regulation, including CE marking, will become fully applicable starting December 2027.
To meet these obligations — and more broadly, to strengthen the security of its products for the benefit of its customers — Metal Work S.p.A has set up a dedicated channel for receiving reports of vulnerabilities and security incidents, described in the policy below.
Vulnerability and Incident Disclosure Policy
Introduction
Since security is of critical importance to us and to our customers, we at Metal Work S.p.A are committed to ensuring the safety and security of our products and services. Metal Work S.p.A supports coordinated vulnerability disclosure and encourages responsible vulnerability testing, we take any reports of security issues seriously.
To report a potential security issue, please follow the steps described in the “Reporting procedure” section
Report a vulnerability or security incident
Send your Security Report to our dedicated email address, encrypting any attachments and sensitive data with our PGP public key.
Reporting procedure
To submit a Security Report to us, please follow these steps:
- Submit the Security Report at psirt@metalwork.it
- Use our PGP public key to encrypt any email submissions
- Write the Security Report in English
- Provide sufficient contact information, such as:
- your e-mail address;
- the name of the person who found the security issue
- Specify whether you are reporting:
- a potential vulnerability for which exploitation is not suspected, or
- a security incident or suspected active exploitation
- Provide the following information:
- date when the vulnerability or incident has been detected;
- details about how it has been discovered;
- a technical description of the issue
- Provide as much information as you can on the product or service affected, such as:
- Product code
- version number (hardware and software);
- configuration of the setup used
- If you wrote specific proof-of-concept or exploit code of the vulnerability, please provide a copy. Please ensure all submitted code is clearly marked as such and is encrypted with our PGP key.
- If you have identified specific threats related to the root cause of the vulnerability or the incident, assessed the risk, or have seen the vulnerability being exploited in other products, please provide that information.
Internal assessment and action
- Metal Work S.p.A will acknowledge receiving your Security Report within three working days.
- If the Security Report contains all the required information, Metal Work S.p.A will provide a unique tracking number and a contact person;
- If the Security Report is not complete (more information is needed Metal Work S.p.A will request the missing information, and no more action will be taken.
- Metal Work S.p.A will start an internal management process to manage the reported security issue:
- Receipt;
- Triage;
- Verification;
- Remediation.
- Metal Work S.p.A will monitor the status of the management process, and you will receive a communication at the end of each stage.
- Metal Work S.p.A will use existing customer notification processes to manage the release of patches or security fixes, which may include without limitation and at Metal Work S.p.A’s sole discretion, direct customer notification or public release of an advisory notification on our website.
- If the vulnerability or the incident source is in a third-party component or service which is part of our product/service, Metal Work S.p.A will notify the Security Report to that third party and advise you of that notification. To that end, please inform us in your email whether it is permissible in such cases to provide your contact information to the third party.
Notice
If you share any information with Metal Work S.p.A in the context of responsible disclosure, you agree that the information you submit will be considered as non-proprietary and non-confidential.
Metal Work S.p.A is allowed to use shared information, or part of it, without any restriction. You agree that submitting information does not create any rights for you or any obligation for Metal Work S.p.A.
Personal data is processed by Metal Work S.p.A based on the privacy policy.