The EU Cyber Resilience Act (Regulation (EU) 2024/2847, the “CRA”) entered into force on 10 December 2024. It aims to establish cybersecurity requirements for products with digital elements, including software and hardware products. The manufacturers must meet cybersecurity requirements throughout the product lifecycle, provide security updates, and address vulnerabilities. Products that comply with the CRA will bear the CE marking.  

The main obligations of the CRA apply from 11 December 2027, while the vulnerability and incident reporting obligations take effect on 11 September 2026.

If you identify a vulnerability in, or an incident involving a Shimadzu product, please report the following details to us at the email address: product_security_scj@group.shimadzu.co.jp

  • Product details: Product name, Product Number, version number and Serial Number
  • Issue details: Results or the impact of the vulnerability/incident
  • Your contact information: Organisation name, department, contact person's name, and email address

 

We accept reports in English.