Cyber Resilience Act (Regulation (EU) 2024/2847)
AVT Audio Video Technologies GmbH
| Publisher | AVT Audio Video Technologies GmbH, Nürnberg, Germany |
|---|---|
| Applies to | All AVT products with digital elements |
| Legal basis | Annex I Part II(5); Article 13. Structure per BSI TR-03183-3 v1.0.0 |
| Document reference | AVT-CRA-CVD-006 |
| Version / date | 1.0 / 04-09-2026 — reviewed at least annually |
| Corresponding national CSIRT | CERT-Bund (operated by the BSI), Germany |
Note: This is a company-wide process document (not per product). It is published on the AVT website and referenced from each product's technical documentation.
AVT welcomes reports of potential security vulnerabilities in its products and services. This policy sets out how to report a vulnerability, what reporters can expect, and how AVT coordinates disclosure. In scope are cybersecurity vulnerabilities that, upon exploitation, negatively affect the confidentiality, integrity, availability, authenticity, non-repudiation or reliability of a product or component.
5C6808CA65DC0702FAA22ABA0862220CF3663A4E| Stage | Target |
|---|---|
| Simple, non-automated acknowledgement of receipt | Within 5 working days |
| Detailed feedback / initial assessment | Within 10 working days |
| Public disclosure after a fix/mitigation | Within 90 days (extendable once by a further 90 days in consultation with CERT-Bund; further extension only by the CSIRT on request) |
For actively exploited vulnerabilities and severe incidents affecting AVT products, AVT notifies the corresponding national CSIRT and ENISA simultaneously via the single reporting platform (Article 16), on the following timeline:
| Stage | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | Within 24 h of awareness; indicate affected Member States where known | Within 24 h; state if suspected unlawful/malicious; affected Member States |
| Notification | Within 72 h; product info, nature of the vulnerability/exploit, corrective/mitigating actions, user guidance | Within 72 h; equivalent detail |
| Final report | Within 14 days after a corrective/mitigating measure is available | Within 1 month after the incident notification |
Voluntary reports of other vulnerabilities, threats, incidents or near-misses may also be made to the CSIRT or ENISA (Article 15).
AVT considers the process complete when: the report is found unfounded; the vulnerability has been mitigated/fixed by an appropriate patch and publicly disclosed; a service vulnerability is fixed and disclosed; the reporter fails to respond to queries for at least 30 days; or, in consultation with CERT-Bund, it can no longer be assumed the vulnerability will be fixed. The reporter is informed without undue delay (unless the report was anonymous).