Security Contact Page under the Cyber Resilience Act (CVD contact point)
Responsible handling of security vulnerabilities
SHF Communication Technologies AG (SHF) develops and distributes measurement instruments, modules and laboratory amplifiers that contain firmware and/or come with downloadable control software. The security of our products is a high priority for us. We take our obligations under the Cyber Resilience Act (Regulation (EU) 2024/2847) seriously and therefore provide a central contact point for reporting security vulnerabilities (Coordinated Vulnerability Disclosure, CVD).
If you have discovered a vulnerability in one of our products, in the associated firmware or in our control software, we ask you to report it to us through the channels listed below before making the information public.
Scope
This reporting point covers:
- all measurement instruments, modules, and laboratory amplifiers including their integrated firmware distributed by SHF Communication Technologies AG
- the control software provided by us (both the download version and bundled versions)
How to report a vulnerability
Please send your report to:
- Email:
- Optional – encrypted communication
PublicKey: SMIME
Fingerprint: SHA-256 3F:1E:E7:1E:6A:1E:AD:30:D4:9F:94:7F:0A:6E:21:60:E1:39:C5:67:19:65:18:6D:13:46:AD:C3:4A:2F:74:8B
To help us process your report quickly, please include the following information:
- Affected product/model and, if known, the firmware/software version
- As precise a description of the vulnerability as possible
- Steps to reproduce (proof of concept, if available)
- Possible impact (e.g. unauthorised access, outage, manipulation of the control interface)
- Your contact details for follow-up questions (optional)
What you can expect from us
| Step | Timeframe |
| Acknowledgement of receipt of your report | within 5 working days |
| Initial assessment / status update | within 10 working days |
| Information on planned remediation and schedule | on an ongoing basis, depending on severity |
| Publication of security advisories after remediation | see section “Coordinated disclosure” |
If the report concerns an actively exploited vulnerability or a severe security incident, we are additionally obliged to notify the competent CSIRT and ENISA within the statutory deadlines pursuant to Art. 14 CRA. This notification to the authorities does not replace our communication with you as the reporting party.
Coordinated disclosure
We ask you not to make details of a reported vulnerability public before:
- we have confirmed the vulnerability and, where possible, provided an update or mitigation measure, or
- a mutually agreed period (as a rule 90 days from receipt of the report) has elapsed.
Once a security update is available, we will – provided the risk situation permits – publish a security advisory containing information on the remediated vulnerability, the affected versions and recommended measures.
Good faith / safe harbour
We consider security research carried out in good faith and in accordance with this policy to be authorised. In particular, this means:
- You test only on devices/systems that you own yourself or for which you have explicit permission.
- You avoid disrupting the ongoing operations of third parties, causing data loss or breaching data protection.
- You give us a reasonable period to remediate before publishing details (see above).
If you comply with these principles, we will not initiate legal action against you.
Support period
For our products we provide security updates for a period of 5 years from the placing on the market of the respective device.
Last updated: September 2026. This page is reviewed and updated regularly.
