{"id":19658,"date":"2026-09-10T10:20:05","date_gmt":"2026-09-10T08:20:05","guid":{"rendered":"https:\/\/www.rhoss.it\/cyber-security\/"},"modified":"2026-09-10T10:35:09","modified_gmt":"2026-09-10T08:35:09","slug":"cyber-resilience-act","status":"publish","type":"page","link":"https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/","title":{"rendered":"Cyber Resilience Act"},"content":{"rendered":"<div>\n<h4><strong>CRA Incident Reporting Procedure<\/strong><\/h4>\n<p><em>Reference: Cyber Resilience Act (EU) 2024\/2847 &#8211; Article 14<\/em><\/p>\n<\/div>\n<div>\n<div><\/div>\n<div><strong>Report a vulnerability or cybersecurity incident<\/strong><\/div>\n<div><\/div>\n<div>Rhoss is committed to ensuring the security, integrity and resilience of its products and services.<\/div>\n<div>If you have identified a potential security vulnerability or cybersecurity weakness, or have observed an incident involving a Rhoss product, please report it to our Product Security Incident Response Team (PSIRT).<\/div>\n<div><\/div>\n<div>In accordance with the Cyber Resilience Act (CRA), our PSIRT team will assess the report and, if necessary, submit a notification to ENISA\u2019s Single Reporting Platform (SRP) within the following timeframes:<\/div>\n<div>\u2022 Early Warning (preliminary notification): within 24 hours of receipt<\/div>\n<div>\u2022 Full notification: within 72 hours of receipt<\/div>\n<div>The date and time this report is received constitute the legal starting point for calculating these deadlines<\/div>\n<div><\/div>\n<div><\/div>\n<div>Contacts<\/div>\n<div>Reports must be sent to:<\/div>\n<div>security@rhoss.com<\/div>\n<div><\/div>\n<div>What to report<\/div>\n<div>You can use this channel to report:<\/div>\n<div>\u2022Security vulnerabilities in Rhoss products.<\/div>\n<div>\u2022Suspected vulnerabilities requiring further investigation.<\/div>\n<div>\u2022Vulnerabilities that allow unauthorised access.<\/div>\n<div>\u2022Remote Code Execution (RCE) vulnerabilities.<\/div>\n<div>\u2022Cybersecurity incidents involving Rhoss products.<\/div>\n<div>\u2022Evidence that a vulnerability may be actively exploited.<\/div>\n<div>\u2022Any issue that may compromise the confidentiality, integrity or availability of the product.<\/div>\n<div><\/div>\n<div>Information to include in the report<\/div>\n<div>To enable the report to be properly assessed and managed, please provide as much detail as possible.<\/div>\n<div><\/div>\n<div>1. Reporter details<\/div>\n<div>Full name;<\/div>\n<div>Company or organisation (if applicable);<\/div>\n<div>Email address for correspondence;<\/div>\n<div>Telephone number (optional);<\/div>\n<div>Reporter&#8217;s role (customer, security researcher, supplier, partner or other).<\/div>\n<div><\/div>\n<div>EXAMPLE<\/div>\n<div>Name: Mario Rossi<\/div>\n<div>Company: XYZ Security<\/div>\n<div>Email: mario.rossi@example.com<\/div>\n<div>Role: Security researcher<\/div>\n<div><\/div>\n<div>2. Details of the affected product<\/div>\n<div><\/div>\n<div>Identify the product involved as precisely as possible.<\/div>\n<div><\/div>\n<div>Product name<\/div>\n<div>Model<\/div>\n<div>Hardware version<\/div>\n<div>Firmware version<\/div>\n<div>Software version<\/div>\n<div>Use or installation context (if known)<\/div>\n<div><\/div>\n<div>EXAMPLE<\/div>\n<div>Product: ABC supervisory control system<\/div>\n<div>Model: XYZ-100<\/div>\n<div>Firmware: 2.5.1<\/div>\n<div>Software: 4.2.0<\/div>\n<div>Environment: Installation at an end customer&#8217;s premises<\/div>\n<div><\/div>\n<div>3. Detailed description of the issue<\/div>\n<div><\/div>\n<div>Clearly describe:<\/div>\n<div>the observed behaviour;<\/div>\n<div>the expected behaviour;<\/div>\n<div>the conditions required for the issue to occur;<\/div>\n<div>the potential impact on the system.<\/div>\n<div><\/div>\n<div>EXAMPLE:<\/div>\n<div>An authenticated user with limited privileges<\/div>\n<div>can access features reserved for administrators<\/div>\n<div>by manually changing the browser URL.<\/div>\n<div>This gives the user access to the machine&#8217;s operating parameters.<\/div>\n<div><\/div>\n<div>4. Steps to reproduce the issue<\/div>\n<div><\/div>\n<div>Where possible, describe step by step how to reproduce the observed behaviour.<\/div>\n<div><\/div>\n<div>EXAMPLE:<\/div>\n<div>1. Log in as a standard user.<\/div>\n<div>2. Open the Dashboard page.<\/div>\n<div>3. Add &#8220;\/admin&#8221; to the URL.<\/div>\n<div>4. Verify access to the administrative functions.<\/div>\n<div><\/div>\n<div>5. Impact assessment<\/div>\n<div><\/div>\n<div>Indicate the potential consequences of the issue.<\/div>\n<div>If possible, also indicate whether the issue is:<\/div>\n<div>locally exploitable;<\/div>\n<div>remotely exploitable;<\/div>\n<div>accessible via the Internet;<\/div>\n<div>limited to the local network.<\/div>\n<div><\/div>\n<div>EXAMPLE:<\/div>\n<div>unauthorised access;<\/div>\n<div>configuration changes;<\/div>\n<div>data exposure;<\/div>\n<div>service disruption;<\/div>\n<div>loss of product availability;<\/div>\n<div>compromise of the physical security of the installation;<\/div>\n<div>other significant impacts.<\/div>\n<div><\/div>\n<div>6. Evidence of exploitation<\/div>\n<div><\/div>\n<div>If known, specify whether:<\/div>\n<div>the vulnerability has only been identified;<\/div>\n<div>it has been verified through controlled testing;<\/div>\n<div>there is evidence of actual exploitation;<\/div>\n<div>the exploit is publicly available (the code, tools or instructions required to exploit the vulnerability are publicly accessible).<\/div>\n<div><\/div>\n<div>EXAMPLE:<\/div>\n<div>There is no known evidence of active exploitation.<\/div>\n<div>The vulnerability has only been verified<\/div>\n<div>in a laboratory environment.<\/div>\n<div><\/div>\n<div>7. Attachments and supporting material<\/div>\n<div><\/div>\n<div>If available, attach:<\/div>\n<div>Screenshots<\/div>\n<div>Log files<\/div>\n<div>Network traffic captures (PCAP)<\/div>\n<div>Demonstration videos<\/div>\n<div>Relevant configurations<\/div>\n<div>Proof of Concept (PoC)<\/div>\n<div>Technical reports<\/div>\n<div><\/div>\n<div>8. Date of discovery<\/div>\n<div><\/div>\n<div>Indicate:<\/div>\n<div>the date on which the issue was identified;<\/div>\n<div>the date of any verification;<\/div>\n<div>the date of this report.<\/div>\n<div><\/div>\n<div>Responsible Disclosure<\/div>\n<div><\/div>\n<div>Rhoss appreciates the contribution of researchers, customers and partners who report vulnerabilities in good faith.<\/div>\n<div><\/div>\n<div>We therefore ask you to observe the following:<\/div>\n<div>Do not disrupt the operation of customers&#8217; systems.<\/div>\n<div>Do not access data without authorisation.<\/div>\n<div>Do not modify or delete information.<\/div>\n<div>Do not perform destructive testing.<\/div>\n<div>Keep the information confidential until the analysis and mitigation activities have been completed.<\/div>\n<div><\/div>\n<div>Reports received will be handled in accordance with Rhoss&#8217;s internal PSIRT procedures.<\/div>\n<div><\/div>\n<div>What happens after submitting a report<\/div>\n<div><\/div>\n<div>After a report is received:<\/div>\n<div>The report will be logged in Rhoss&#8217;s PSIRT process.<\/div>\n<div>A preliminary assessment will be carried out.<\/div>\n<div>Additional information may be requested.<\/div>\n<div>The issue will be analysed and classified.<\/div>\n<div>The need for any corrective action will be determined.<\/div>\n<div>The notification obligations under the applicable legislation will be assessed.<\/div>\n<div>The reporter may be contacted for updates or clarification.<\/div>\n<div><\/div>\n<div>Data confidentiality<\/div>\n<div><\/div>\n<div>Information submitted through this channel will be treated confidentially and used exclusively for:<\/div>\n<div>vulnerability management;<\/div>\n<div>cybersecurity incident response;<\/div>\n<div>improving product security;<\/div>\n<div>compliance with applicable regulatory obligations.<\/div>\n<div><\/div>\n<div>Thank you for your cooperation<\/div>\n<div><\/div>\n<div>Rhoss thanks its customers, partners, researchers and all stakeholders who contribute to the continuous improvement of product security by responsibly reporting vulnerabilities and cybersecurity incidents.<\/div>\n<div>For all security reports:<\/div>\n<div>security@rhoss.com<\/div>\n<div><\/div>\n<div>NOTE: This address must be used exclusively to report vulnerabilities and cybersecurity incidents. For sales enquiries, routine technical support or product information, please use the usual Rhoss contact channels.<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>CRA Incident Reporting Procedure Reference: Cyber Resilience Act (EU) 2024\/2847 &#8211; Article 14 Report a vulnerability or cybersecurity incident Rhoss is committed to ensuring the security, integrity and resilience of [&hellip;]<\/p>\n","protected":false},"author":21347,"featured_media":0,"parent":0,"menu_order":6,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"class_list":["post-19658","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyber Resilience Act | Rhoss<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber Resilience Act | Rhoss\" \/>\n<meta property=\"og:description\" content=\"CRA Incident Reporting Procedure Reference: Cyber Resilience Act (EU) 2024\/2847 &#8211; Article 14 Report a vulnerability or cybersecurity incident Rhoss is committed to ensuring the security, integrity and resilience of [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/\" \/>\n<meta property=\"og:site_name\" content=\"Rhoss\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/RhossOfficial\/\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-10T08:35:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.rhoss.it\/wp-content\/uploads\/2023\/02\/logo.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/cyber-resilience-act\\\/\",\"url\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/cyber-resilience-act\\\/\",\"name\":\"Cyber Resilience Act | Rhoss\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/#website\"},\"datePublished\":\"2026-09-10T08:20:05+00:00\",\"dateModified\":\"2026-09-10T08:35:09+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/cyber-resilience-act\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.rhoss.it\\\/es\\\/cyber-resilience-act\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/cyber-resilience-act\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber Resilience Act\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/#website\",\"url\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/\",\"name\":\"Rhoss\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/#organization\",\"name\":\"Rhoss\",\"url\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.rhoss.it\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cropped-Rhoss-Logo-Gruppo-COATED.png\",\"contentUrl\":\"https:\\\/\\\/www.rhoss.it\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cropped-Rhoss-Logo-Gruppo-COATED.png\",\"width\":563,\"height\":255,\"caption\":\"Rhoss\"},\"image\":{\"@id\":\"https:\\\/\\\/www.rhoss.it\\\/es\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/RhossOfficial\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/rhoss\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCX98b2XEhhnMo24OO3uzGbA\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyber Resilience Act | Rhoss","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/","og_locale":"es_ES","og_type":"article","og_title":"Cyber Resilience Act | Rhoss","og_description":"CRA Incident Reporting Procedure Reference: Cyber Resilience Act (EU) 2024\/2847 &#8211; Article 14 Report a vulnerability or cybersecurity incident Rhoss is committed to ensuring the security, integrity and resilience of [&hellip;]","og_url":"https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/","og_site_name":"Rhoss","article_publisher":"https:\/\/www.facebook.com\/RhossOfficial\/","article_modified_time":"2026-09-10T08:35:09+00:00","og_image":[{"width":1200,"height":675,"url":"https:\/\/www.rhoss.it\/wp-content\/uploads\/2023\/02\/logo.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Tiempo de lectura":"5 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/","url":"https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/","name":"Cyber Resilience Act | Rhoss","isPartOf":{"@id":"https:\/\/www.rhoss.it\/es\/#website"},"datePublished":"2026-09-10T08:20:05+00:00","dateModified":"2026-09-10T08:35:09+00:00","breadcrumb":{"@id":"https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.rhoss.it\/es\/cyber-resilience-act\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.rhoss.it\/es\/"},{"@type":"ListItem","position":2,"name":"Cyber Resilience Act"}]},{"@type":"WebSite","@id":"https:\/\/www.rhoss.it\/es\/#website","url":"https:\/\/www.rhoss.it\/es\/","name":"Rhoss","description":"","publisher":{"@id":"https:\/\/www.rhoss.it\/es\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.rhoss.it\/es\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/www.rhoss.it\/es\/#organization","name":"Rhoss","url":"https:\/\/www.rhoss.it\/es\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/www.rhoss.it\/es\/#\/schema\/logo\/image\/","url":"https:\/\/www.rhoss.it\/wp-content\/uploads\/2024\/09\/cropped-Rhoss-Logo-Gruppo-COATED.png","contentUrl":"https:\/\/www.rhoss.it\/wp-content\/uploads\/2024\/09\/cropped-Rhoss-Logo-Gruppo-COATED.png","width":563,"height":255,"caption":"Rhoss"},"image":{"@id":"https:\/\/www.rhoss.it\/es\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/RhossOfficial\/","https:\/\/www.linkedin.com\/company\/rhoss","https:\/\/www.youtube.com\/channel\/UCX98b2XEhhnMo24OO3uzGbA"]}]}},"_links":{"self":[{"href":"https:\/\/www.rhoss.it\/es\/wp-json\/wp\/v2\/pages\/19658","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rhoss.it\/es\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.rhoss.it\/es\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.rhoss.it\/es\/wp-json\/wp\/v2\/users\/21347"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rhoss.it\/es\/wp-json\/wp\/v2\/comments?post=19658"}],"version-history":[{"count":2,"href":"https:\/\/www.rhoss.it\/es\/wp-json\/wp\/v2\/pages\/19658\/revisions"}],"predecessor-version":[{"id":19667,"href":"https:\/\/www.rhoss.it\/es\/wp-json\/wp\/v2\/pages\/19658\/revisions\/19667"}],"wp:attachment":[{"href":"https:\/\/www.rhoss.it\/es\/wp-json\/wp\/v2\/media?parent=19658"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}