What does the Cyber Resilience Act concern? (CRA)
With the Cyber Resilience Act, the EU has laid down binding cybersecurity requirements. Manufacturers must demonstrate that their products containing digital components comply with these cybersecurity requirements. The CRA applies to all products with digital components that are manufactured, distributed or imported into the EU.
Consequently, the uninterruptible power supplies from J. Schneider Elektrotechnik and the associated software also fall under this legislation.

When does the Cyber Resilience Act come into force?
Following the entry into force of the Cyber Resilience Act on 10 December 2024, the reporting obligation for manufacturers will come into force on 11 September 2026. To fulfil this obligation, the reporting form below is available with immediate effect.
This reporting form can be used to report an actively exploited security vulnerability or a serious security incident relating to one of our products. You can provide your contact details so that we can get in touch with you, or you can submit the report anonymously.

Report concerning the Cyber Resilience Act (CRA)
actively exploited vulnerability / serious security incident
Explanations
x1 Actively exploited vulnerability
A vulnerability in our product for which there is reliable evidence that a malicious actor has exploited it in a system without the owner’s permission.
x2 Serious security incident:
An incident that compromises, or may compromise, the product’s ability to protect the availability, authenticity, integrity or confidentiality of data or functions.
