Secomea maintains a Coordinated Vulnerability Disclosure process for confirmed security issues affecting supported products. As a CVE Numbering Authority, Secomea reserves CVE identifiers for eligible vulnerabilities once the issue is confirmed and a release window has been set. The issue is then fixed, included in a product release, and documented in the release notes with the relevant CVE reference.
Customers are normally informed approximately 14 days before public disclosure. This early notification gives customers time to assess the impact, plan updates, and apply mitigations before detailed vulnerability information is made public.
Security updates are communicated through release notes published on the Secomea Knowledge Base, where customers can subscribe to email notifications. Public advisories are published on Secomea’s cybersecurity advisory page and include a customer-facing summary with description, severity, affected releases, and mitigated releases. Link to our public Cybersecurity Advisory Process: Cybersecurity Advisory
Secomea's vulnerability handling and security update practices are governed by our secure product development lifecycle, are supported by our IEC 62443-4-1 certified development process, and align with the vulnerability handling requirements of Annex I, Part II of the EU Cyber Resilience Act (Regulation (EU) 2024/2847).