EU Cyber Resilience Act
Cybersecurity Vulnerability Reporting
FFE takes the cybersecurity of its products seriously.
If you believe you have identified a cybersecurity vulnerability affecting an FFE product with digital elements, please report it to FFE as soon as possible using the Coordinated Vulnerability Disclosure process described below.
The information you provide will help FFE investigate and assess the suspected vulnerability and, where necessary, take appropriate corrective or mitigating action in a timely and responsible manner. This process also supports FFE in determining whether the reported vulnerability gives rise to vulnerability-handling, user-notification or statutory reporting obligations under Regulation (EU) 2024/2847, the EU Cyber Resilience Act.
How to Report a Vulnerability
Please complete the Cybersecurity Vulnerability Report here.
Notes for completing the report:
-
Please provide your contact information so that FFE can contact you if further information is required about the reported vulnerability and keep you informed of relevant progress, where appropriate.
-
To support our investigation, please provide as much of the following information as possible:
-
- The product name, model and part number
-
- Software or firmware version, if known
- The date on which the suspected vulnerability was first observed
- A description of the suspected vulnerability, including its type and how it was identified
- Clear, step-by-step instructions for reproducing the issue
- Any relevant proof-of-concept information or supporting evidence
Please act responsibly and avoid publicly disclosing information about the suspected vulnerability that could facilitate exploitation until FFE has had a reasonable opportunity to investigate the reported issue and, where appropriate, develop and communicate corrective or mitigating measures.
Our Commitment and Process
Upon receipt of a report concerning a suspected cybersecurity vulnerability, FFE will:
- Acknowledge receipt, normally within 1 business day, as part of FFE’s Coordinated Vulnerability Disclosure process.
- Review and validate the information provided, and assess the severity and potential impact of the reported vulnerability.
- Investigate the issue and determine appropriate corrective or mitigating measures.
- Keep you informed, where appropriate, of relevant investigation and remediation progress.
- Coordinate any security advisory or public vulnerability disclosure, where appropriate, following remediation.
-
Where applicable, publish a Technical Notice or other customer communication describing the issue, any corrective actions taken, and any actions required by affected customers.
Statutory Reporting under the EU Cyber Resilience Act
From 11 September 2026, where FFE becomes aware of an actively exploited vulnerability contained in an FFE product with digital elements, or of a severe incident having an impact on the security of such a product, FFE will submit the applicable notifications through the single reporting platform using the electronic notification endpoint of the relevant CSIRT designated as coordinator. The notifications will also be made available to ENISA in accordance with the Cyber Resilience Act.
The required reporting stages include:
- an early warning, without undue delay and in any event within 24 hours of FFE becoming aware of the actively exploited vulnerability or severe incident;
- a vulnerability or incident notification, without undue delay and in any event within 72 hours of awareness; and
- the applicable final report required under Article 14 of Regulation (EU) 2024/2847, the EU Cyber Resilience Act.
For an actively exploited vulnerability, the final report must be submitted no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report must be submitted within one month after submission of the 72-hour incident notification.
FFE will also inform impacted users and, where appropriate, all users of the affected product of the actively exploited vulnerability or severe incident and, where necessary, of any corrective or risk-mitigation measures that users can take.
Not sure what you need?
Let our experts guide you.
Whether you need expert advice, a tailored quote, or want to explore the right solution for your site
— our team is here to help you take the next step in fire safety.