Product Cybersecurity Policy

1. Purpose
We are committed to ensuring the security and reliability of products with digital elements by implementing cybersecurity measures throughout the entire product lifecycle and complying with applicable regulations, including the EU Cyber Resilience Act (CRA).

2. Scope
This policy applies to all products and services with digital elements that we design, develop, manufacture, distribute, and maintain.

3. Principles
We ensure product security based on the following principles:
•Security by Design and by Default
•Lifecycle Risk Management
•Continuous Improvement and Audit
•Transparency and Disclosure

4. Product Security Organization (PSIRT)
We establish a Product Security Incident Response Team (PSIRT) responsible for:
•Collecting and analyzing vulnerability information
•Managing incident response
•Coordinating with internal and external stakeholders
•Reporting to authorities when required

5. Vulnerability Handling and Disclosure
We implement Coordinated Vulnerability Disclosure (CVD):
•Provide a public vulnerability reporting channel
•Assess and remediate vulnerabilities promptly
•Deliver security updates as needed
•Inform customers and stakeholders

6. Risk Management and Secure Development
We implement:
•Threat modeling and risk assessment
•Secure Software Development Lifecycle (Secure SDLC)
•Software component management (e.g., SBOM)
•Supply chain security controls

7. Incident Response and Reporting
When a significant vulnerability or incident is identified:
•Perform rapid response and impact analysis
•Report to authorities in accordance with applicable regulations
•Notify customers appropriately
•Implement corrective and preventive actions

8. Support and Updates
We provide appropriate security support during the product lifecycle:
•Security updates and patches
•Defined product support period
•Guidance at end-of-life

9. Compliance and Standards
We comply with:
•EU Cyber Resilience Act (CRA)
•ISO/IEC 29147 (Vulnerability Disclosure)
•ISO/IEC 30111 (Vulnerability Handling)
•Other applicable regulations and standards

10. Continuous Improvement
We continuously review and improve this policy and related processes.

Date of enactment : July 9, 2026

Vulnerability Reporting Contact

If you believe you have discovered a vulnerability in one of our products, please report it to:
psirt@optex.co.jp