On 11 September 2026, new vulnerability and incident reporting requirements under the EU Cyber Resilience Act (CRA) came into effect.
The new requirements are an important step towards improving the cybersecurity of products with digital elements throughout their lifecycle. Manufacturers must now have processes in place to assess security vulnerabilities and incidents and, where required, report actively exploited vulnerabilities and severe security incidents within strict regulatory timelines.
As a manufacturer of RFID and NFC readers and modules, Eccel Technology has introduced dedicated product security and vulnerability handling procedures to support these requirements.
Our process:
- a dedicated channel for reporting potential security vulnerabilities,
- technical assessment and triage of reported issues,
- identification of potentially affected products and firmware versions,
- defined internal responsibilities and escalation procedures,
- corrective and mitigating actions where appropriate,
- communication with affected customers where required,
- regulatory reporting in accordance with the Cyber Resilience Act where the applicable reporting criteria are met.
We have also established a dedicated security contact at security@eccel.co.uk.
Reporting a security vulnerability
Customers, integrators and security researchers who identify a potential security vulnerability affecting an Eccel Technology product, firmware or software can report it through our dedicated Product Security page.
Our security reporting process is intended to provide a clear point of contact and allow potential vulnerabilities to be assessed and addressed in a structured and coordinated manner.
For more information or to report a potential security vulnerability, please visit:
The introduction of these procedures forms part of Eccel Technology’s ongoing preparations for the Cyber Resilience Act and our commitment to maintaining the security of our products throughout their lifecycle.
