Elmdene and the Cyber Resilience Act (CRA)
Elmdene is committed to maintaining the highest standards of cybersecurity across its products and services. We continuously assess and improve the security of our products throughout their lifecycle, including the identification, management and remediation of cybersecurity vulnerabilities.
This commitment extends to our obligations under the European Union Cyber Resilience Act (CRA) (Regulation (EU) 2024/2847), which establishes cybersecurity requirements for products with digital elements placed on the EU market.
From September 2026, the CRA requires manufacturers to report actively exploited vulnerabilities and significant cybersecurity incidents affecting products with digital elements. Elmdene will comply with all applicable reporting obligations and will manage these responsibilities directly.
What is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) is European legislation designed to improve the cybersecurity of products with digital elements throughout their entire lifecycle. The regulation introduces requirements covering:
-
Secure product design and development
-
Vulnerability management
-
Security incident reporting
-
Security updates and support
-
Customer transparency regarding cybersecurity risks
The CRA aims to provide greater protection for consumers and businesses by ensuring connected products remain secure against evolving cyber threats.
Why This Matters
Cybersecurity is a fundamental requirement for modern connected products. Through compliance with the CRA, Elmdene demonstrates its commitment to:
-
Delivering secure products and services.
-
Managing vulnerabilities responsibly.
-
Providing timely security updates where required.
-
Supporting customers in maintaining secure deployments.
-
Meeting applicable regulatory obligations.
If you discover a potential cybersecurity or privacy vulnerability affecting an Elmdene product, service, software application or website, please report it using this process.








