SBOM, vulnerability monitoring, and patches for cybersecure operations

Wherever software is in use, vulnerabilities can arise. This also applies to hardware-related software that is essential for the operation of our hardware solutions. We therefore continuously monitor our standard products in accordance with the requirements of the Cyber Resilience Act (CRA):
- Create an SBOM (Software Bill of Materials)
- Continuously monitor the SBOM for potential vulnerabilities
- Assess identified vulnerabilities in terms of their risk
- Inform the notified body and customers
- Provide patches for exploitable vulnerabilities throughout the regular product lifecycle (typically 10–15 years)
For hardware products and software components that we manufacture specifically to meet customer requirements, we naturally also offer this service upon request. In addition to continuous monitoring, you can also rely on prioritized patch development for security-critical systems. This ensures that your customized hardware solutions meet CRA requirements and are optimally equipped for long-term cyber-secure operation.
We recommend discussing with your duagon contact person or our sales team—ideally during the initial phase of project planning—whether you’d like to handle vulnerability monitoring for your custom hardware solution on your own or if you’d like us to assist you. Of course, we’re also happy to take on this task for existing products.