{"id":19022,"date":"2026-09-07T10:36:43","date_gmt":"2026-09-07T01:36:43","guid":{"rendered":"https:\/\/www.japanunix.com\/en\/?page_id=19022"},"modified":"2026-09-07T10:48:33","modified_gmt":"2026-09-07T01:48:33","slug":"vulnerability-disclosure-policy","status":"publish","type":"page","link":"https:\/\/www.japanunix.com\/en\/corporate\/cra_vulnerability-disclosure-policy\/","title":{"rendered":"Vulnerability Disclosure Policy"},"content":{"rendered":"<p><!-- Vulnerability Disclosure Policy --><\/p>\n<div class=\"c-box\">\n<div class=\"container\">\n<div class=\"row\">\n<div class=\"col-md-10 col-md-offset-1 col-sm-12 col-xs-12\">\n<div class=\"cra-policy-content\">\n<p class=\"cra-policy-title\">Vulnerability Disclosure Policy based on the EU Cyber Resilience Act (CRA)<\/p>\n<p class=\"cra-policy-section\">1. Purpose<\/p>\n<p class=\"cra-policy-text\">This policy defines the processes for receiving, handling, and disclosing security vulnerabilities in our products to ensure timely risk mitigation and to protect users and the digital ecosystem in compliance with the EU Cyber Resilience Act.<\/p>\n<p class=\"cra-policy-section\">2. Scope<\/p>\n<p class=\"cra-policy-text\">This policy applies to all hardware and software products with digital elements that we provide within the EU market.<\/p>\n<p class=\"cra-policy-section\">3. Reporting Vulnerabilities<\/p>\n<ul class=\"cra-policy-list\">\n<li>Vulnerabilities can be reported through a dedicated vulnerability reporting form on our website.<\/li>\n<li>Reporters are encouraged to provide detailed information such as the product name and version, a description of the vulnerability, proof of concept or reproduction steps, and potential impacts.<\/li>\n<\/ul>\n<p class=\"cra-policy-section\">4. Vulnerability Handling Process and Timeline<\/p>\n<ul class=\"cra-policy-list\">\n<li>We will promptly execute the initial vulnerability assessment and classification.<\/li>\n<li>We will comply with the CRA reporting schedule:\n<ul class=\"cra-policy-list\">\n<li>Actively exploited vulnerabilities will be reported to the designated ENISA within 24 hours of detection.<\/li>\n<li>The first detailed notification will be sent within 72 hours.<\/li>\n<li>A comprehensive vulnerability description and mitigation plan will be provided within 14 days after mitigation measures become available. (Within one month in the event of an incident.)<\/li>\n<\/ul>\n<\/li>\n<li>We will coordinate with relevant authorities and stakeholders regarding vulnerabilities that affect multiple member states.<\/li>\n<\/ul>\n<p class=\"cra-policy-section\">5. Disclosure and Communication<\/p>\n<ul class=\"cra-policy-list\">\n<li>We will coordinate the limits of information disclosure with the reporter, allowing them to maintain anonymity if desired.<\/li>\n<li>Through appropriate communication channels, we will notify affected users and partners about verified vulnerabilities and recommended mitigation measures.<\/li>\n<li>Unless there is explicit agreement and coordination, we will ensure that vulnerability details are not disclosed before a remediation measure becomes available.<\/li>\n<\/ul>\n<p class=\"cra-policy-section\">6. Reporter Protection and Confidentiality<\/p>\n<ul class=\"cra-policy-list\">\n<li>We are committed to respecting the good-faith discovery and reporting of vulnerabilities without any legal repercussions.<\/li>\n<li>Highly sensitive vulnerability information will be treated as confidential and shared securely in accordance with applicable data protection regulations.<\/li>\n<\/ul>\n<p class=\"cra-policy-section\">7. Update and Patch Distribution<\/p>\n<ul class=\"cra-policy-list\">\n<li>We will provide timely security updates to address identified vulnerabilities, ensuring that they are accessible and available free of charge throughout the defined support period.<\/li>\n<li>We will provide secure update mechanisms that align with CRA requirements.<\/li>\n<\/ul>\n<p class=\"cra-policy-section\">8. Policy Review<\/p>\n<ul class=\"cra-policy-list\">\n<li>This policy will be reviewed and updated regularly to maintain alignment with the latest CRA updates, industry best practices, and regulatory guidance.<\/li>\n<\/ul>\n<p class=\"cra-policy-section\">9. Contact Information<\/p>\n<ul class=\"cra-policy-list\">\n<li>Vulnerability reporting form on our website<\/li>\n<li>Address: 2-21-25 Akasaka, Minato-ku, Tokyo<\/li>\n<li>Website: https:\/\/www.japanunix.com<\/li>\n<\/ul>\n<p class=\"cra-policy-section\">10. Continuous Support<\/p>\n<ul class=\"cra-policy-list\">\n<li>We will continue to monitor vulnerabilities, respond, and provide corrective updates for at least 5 years after product shipment.<\/li>\n<li>We will regularly conduct security testing and reviews to maintain product safety.<\/li>\n<\/ul>\n<p class=\"cra-policy-section\">11. Miscellaneous<\/p>\n<ul class=\"cra-policy-list\">\n<li>This policy applies to the entire product lifecycle and will be operated systematically, including the establishment of contracts and cooperative frameworks among stakeholders.<\/li>\n<li>We will create a SBOM (Software Bill of Materials) to manage the software components included in the products and their vulnerabilities.<\/li>\n<\/ul>\n<div class=\"cra-policy-actions\" style=\"display:flex;flex-wrap:wrap;justify-content:center;align-items:stretch;gap:12px;\">\n<a class=\"btn-primary btn-icon-next\" href=\"https:\/\/forms.gle\/VQRvBGBCNc2awGap7\" target=\"_blank\" rel=\"noopener noreferrer\" style=\"flex:1 1 0;min-width:200px;max-width:310px;display:inline-flex;align-items:center;justify-content:center;text-align:center;white-space:nowrap;box-sizing:border-box;padding-left:28px;padding-right:48px;\">Report a Vulnerability<\/a><br \/>\n<a class=\"btn-secondary btn-icon-next\" href=\"https:\/\/www.japanunix.com\/en\/corporate\/product_security_policy\/\" target=\"_blank\" rel=\"noopener\" style=\"flex:1 1 0;min-width:200px;max-width:310px;display:inline-flex;align-items:center;justify-content:center;text-align:center;white-space:nowrap;box-sizing:border-box;padding-left:28px;padding-right:48px;\">Product Security Policy<\/a><br \/>\n<a class=\"btn-secondary btn-icon-next\" href=\"https:\/\/www.japanunix.com\/en\/corporate\/cra_vulnerability-disclosure-policy\/security_update\/\" target=\"_blank\" rel=\"noopener\" style=\"flex:1 1 0;min-width:200px;max-width:310px;display:inline-flex;align-items:center;justify-content:center;text-align:center;white-space:nowrap;box-sizing:border-box;padding-left:28px;padding-right:48px;\">Security Updates<\/a>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Vulnerability Disclosure Policy based on the EU Cyber Resilience Act (CRA) 1. Purpose This policy defines the processes for receiving, handling, and disclosing security vulnerabilities in our products to ensure timely risk mitigation and to protect users and the digital ecosystem in compliance with the EU Cyber Resilience Act. 2. Scope This policy applies to [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":0,"parent":33,"menu_order":2,"comment_status":"closed","ping_status":"closed","template":"page-default.php","meta":{"_themeisle_gutenberg_block_has_review":false},"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.japanunix.com\/en\/wp-json\/wp\/v2\/pages\/19022"}],"collection":[{"href":"https:\/\/www.japanunix.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.japanunix.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.japanunix.com\/en\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/www.japanunix.com\/en\/wp-json\/wp\/v2\/comments?post=19022"}],"version-history":[{"count":3,"href":"https:\/\/www.japanunix.com\/en\/wp-json\/wp\/v2\/pages\/19022\/revisions"}],"predecessor-version":[{"id":19025,"href":"https:\/\/www.japanunix.com\/en\/wp-json\/wp\/v2\/pages\/19022\/revisions\/19025"}],"up":[{"embeddable":true,"href":"https:\/\/www.japanunix.com\/en\/wp-json\/wp\/v2\/pages\/33"}],"wp:attachment":[{"href":"https:\/\/www.japanunix.com\/en\/wp-json\/wp\/v2\/media?parent=19022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}