Product Security

Cyber Security

Security does not end at delivery. We monitor our products and the third-party components we use across the entire product lifecycle, assess reported vulnerabilities in a structured process and inform you in a way that keeps you able to act in your plant - traceable, timely and in a format that can be integrated into your own vulnerability management.

Our vulnerability handling meets the requirements of Regulation (EU) 2024/2847 (Cyber Resilience Act, CRA).

Security Advisories

As soon as an actively exploited vulnerability in one of our products has been confirmed and a corrective measure or mitigation is available, we publish a Security Advisory.

 

Contacting our PSIRT (Product Security Incident Response Team)

Reporting a severe incident or an actively exploited vulnerability in a SIGMATEK product.

Would you like to report a severe incident having an impact on the security of a SIGMATEK product (as defined in CRA Article 3(44)), or a vulnerability (as defined in CRA Article 3(42)) that is being actively exploited in a SIGMATEK product? Please contact our PSIRT (Product Security Incident Response Team) by email using our PGP key. This is the fastest way to reach our Product Security team. Only we can provide an update. Please state explicitly in the subject line that exploitation is ongoing, for example with [ACTIVELY EXPLOITED] or [SEVERE SECURITY INCIDENT]

EMail: product-security(xmsAt)sigmatek(xmsDot)at

Subject: e.g. [ACTIVELY EXPLOITED] or [SEVERE SECURITY INCIDENT]

PGP key: PGP-File

Languages: German, English

Please encrypt your report with our PGP key if it contains technical details, proof-of-concept code or information on affected installations. Please do not send us any personal data of third parties and no customer data. Where possible, avoid attachments, as scanning them may cause delays.

What helps us
  • affected product, article number, hardware and firmware or software version
  • description of the vulnerability and its assumed impact
  • clearly documented steps to reproduce the issue, ideally with a PoC, log extract or network capture
  • whether, to your knowledge, the vulnerability is already being exploited or is publicly known.
  • configuration and environment in which you observed the effect
  • your contact details
Alternatively 

If you would prefer not to contact us directly, or wish to involve an independent body, you can also report via a coordinating body (the ENISA single reporting platform (SRP)) or via your national CSIRT.

Note:

Vulnerability reports can only be handled in a CRA-compliant manner if they are submitted via one of the reporting channels stated above (PGP email or SRP). Please do not send reports of this kind to any other department at SIGMATEK (such as Support, Applications, Office, etc.).

Out of scope:

Our corporate IT, web shop and marketing websites, phishing and social engineering attempts against our employees, as well as load-peak and DoS testing.

Actively exploited vulnerabilities: our reporting channels

From 11 September 2026, the Cyber Resilience Act (Regulation (EU) 2024/2847) obliges manufacturers to report actively exploited vulnerabilities in their products, as well as severe security incidents, to the authorities. This obligation rests with the manufacturer — that is, with us, not with you as the user.

The notification is submitted once via the ENISA-operated single reporting platform (SRP) and is forwarded from there simultaneously to ENISA and to the CSIRT designated as coordinator.

In parallel with the notification to the authorities, we inform you through the established channels.

Single Point of Contact

Sigmatekstraße 1
5112 Lamprechtshausen
Österreich

We MaxUp Your Automation
© 2026 SIGMATEK GmbH & Co KG