CES takes the security of its products and services seriously. We value the work of security researchers and the wider community in helping us identify and address vulnerabilities. In line with the requirements of the EU Cyber Resilience Act (CRA), we provide a clear and accessible channel for reporting security vulnerabilities in our products.
We are committed to working with reporters in good faith to investigate, verify, and remediate vulnerabilities in a timely and coordinated manner.
If you have identified a potential security vulnerability in any CES product or associated service, please report it to us immediately using the contact point below.
cybersecurity@ces.eu
Please do not disclose the vulnerability publicly or to third parties before we have had the opportunity to assess and address it. We are committed to coordinated vulnerability disclosure and will work with you to agree on an appropriate disclosure timeline.
Reports may be submitted in German or English.
To help us assess and resolve the issue quickly, please provide the following information:
- Product or service name and version affected by the vulnerability
- A clear description of the vulnerability, including its type (e.g. buffer overflow, authentication bypass, insecure communication)
- Steps to reproduce the issue, including any proof-of-concept code, scripts, or configuration details
- Potential impact of the vulnerability (e.g. data exposure, denial of service, remote code execution)
- Your contact details, if you wish to be kept informed of progress (reports may also be submitted anonymously)
- Any suggested mitigation or remediation you may have identified
If your report contains sensitive information, please indicate this clearly and we will treat it with appropriate confidentiality.
1. Acknowledgment — We will acknowledge receipt of your report within 3 business days.
2. Assessment — Our security team will assess the report to confirm the vulnerability, determine its severity, and identify affected products.
3. Regulatory notification — If a report confirms an actively exploited vulnerability or a severe incident affecting one of our products, we are legally required under the CRA to notify ENISA and the coordinating CSIRT within strict statutory deadlines. This runs alongside, and does not replace, our direct communication with you as the reporter. The information we share is limited to the technical details necessary to assess and remediate the issue, and we do not disclose your identity or contact details as part of this notification unless required by law.
4. Status Updates — From this point on, we will keep you informed of progress at reasonable intervals until resolution.
5. Remediation — We will develop and validate a fix or mitigation. Where relevant, this may include coordination with component or dependency suppliers.
6. Disclosure — Once a fix or mitigation is available, we will coordinate an appropriate public disclosure with you, the reporter, crediting your contribution unless you prefer to remain anonymous.
This policy applies to all CES products and solutions. If you are unsure whether an issue falls within scope, please report it anyway — we would rather review a report that turns out to be out of scope than miss a genuine issue.
To keep testing safe for you, for us, and for our users, please:
- Only test products or services you own or have explicit authorisation to test — never production systems belonging to third parties or other customers.
- Do not perform denial-of-service (DoS/DDoS) testing.
- Do not engage in physical intrusion, social engineering, or phishing against CES employees, contractors, or customers.
- Do not access, modify, or delete data that does not belong to you. If your testing unintentionally exposes nonpublic or personal data, stop immediately, do not save or share it, and report the exposure to us right away.
- Limit automated scanning to a reasonable rate that will not degrade the availability of any service.
Testing conducted in line with these rules and within the scope above is authorised and welcome.
We will not pursue legal action against researchers who:
- Act in good faith and comply with this policy,
- Avoid privacy violations, data destruction, or service disruption,
- Do not exploit a vulnerability beyond what is necessary to demonstrate it, and
- Give us reasonable time to investigate and remediate before any public disclosure.
Email: cybersecurity@ces.eu
A machine-readable version of this contact point is also published at `/.well-known/security.txt` on our domain, in line with RFC 9116, to make it easier for automated tools and researchers to discover.
Information on how we process personal data submitted as part of a vulnerability report is available in our [Privacy Policy], section "Vulnerability Reporting and Disclosure".
We appreciate your effort in helping us keep our products and users safe.
---
This policy is maintained in accordance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847) and reflects our obligations regarding vulnerability handling and reporting.
Last updated: 15.09.2026