At SACI, we work to integrate cybersecurity into our products and solutions with digital elements, from its design and development to its maintenance and support.
Cyber Resilience Act (CRA)
The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, It establishes cybersecurity requirements for products with digital elements marketed in the European Union.
The regulations cover aspects such as the safe design of products, the assessment of risks, the management of vulnerabilities, security updates, and the information provided to users.
SACI is working on adapting its processes and products to the applicable requirements of the CRA., By incorporating cybersecurity as part of its life cycle.


Managing vulnerabilities
SACI has a procedure in place to communicate, analyze, and manage potential vulnerabilities that may affect its products, systems, or services.
The reported vulnerabilities are evaluated to determine their scope, impact, and the necessary measures to mitigate or correct them.
Customers, users and security researchers can report potential vulnerabilities through:
The conditions and the complete communication procedure are available here:
Frequently asked questions about CRA and cybersecurity
The Cyber Resilience Act (CRA) It is the European regulation that establishes cybersecurity requirements for products with digital elements marketed in the European Union.
The CRA applies, with certain exceptions, to products that incorporate digital elements and can be connected directly or indirectly to other devices or networks.
Possible vulnerabilities related to SACI products, systems or services can be reported to:
infociber@saci.es
It is recommended to indicate the affected product, model or reference, firmware or software version, description of the problem and steps to reproduce it.
SACI analyzes the received information to verify the problem, assess its impact, and determine the necessary measures, which may include recommendations, mitigations, corrections, or updates.