Version 1.0 – September 2026
1. Purpose
Acconeer AB designs and manufactures radar sensor modules and ICs. We take the security of our products seriously and welcome reports from security researchers, customers, and the public about potential vulnerabilities in any product we place on the market.
This policy describes how to report a potential vulnerability to Acconeer, what you can expect from us in return, and how we will handle the report through to resolution and public disclosure. It is published in fulfilment of Regulation (EU) 2024/2847 (Cyber Resilience Act), Annex I §2(1), and complements our obligations under Article 14.
2. Scope
This policy applies to security vulnerabilities in:
• Acconeer radar sensor modules and ICs placed on the EU market (A111, A121, A212, XM122, XM123, XM124, XM125, XM126, XM131, XM132)
• Firmware, bootloaders, and software delivered by Acconeer as part of those products
• Acconeer SDK components and libraries shipped in product deliveries
• acconeer.com and developer.acconeer.com web properties
Out of scope:
• Vulnerabilities in third-party products or services that Acconeer does not control
• Vulnerabilities in development hardware (XA, XB, XC, XE, XV series)
• Social engineering, phishing, or physical attacks against Acconeer staff
• Denial-of-service attacks against Acconeer infrastructure
3. How to report a vulnerability
Send your report by email to security@acconeer.com. Please include as much of the following as possible:
• The affected product, firmware version, or software component
• A description of the vulnerability and its potential impact
• Step-by-step instructions to reproduce the issue
• Any proof-of-concept code, screenshots, or supporting material
• Your contact details and preferred communication method
If you would like to encrypt your report, please request our PGP public key at security@acconeer.com before sending sensitive details.
Please do not report security vulnerabilities through public GitHub issues, forum posts, or social media. Doing so may put other users at risk before a fix is available.
4. What you can expect from us
| Timeline | Our commitment |
| Within 5 business days | Acknowledge receipt of your report and confirm we have received it |
| Within 14 days | Provide an initial assessment: confirm whether the issue is valid, the affected products, and a severity rating |
| Within 90 days | Aim to have a fix available or a mitigation in place. We will keep you informed of our progress. If more time is needed we will tell you why and agree an extended timeline |
| At resolution | Notify you when the fix is released and coordinate the timing of public disclosure with you |
5. Our commitments to reporters
When you report in good faith and follow this policy, Acconeer commits to:
• Not pursue legal action against you for the discovery or reporting of the vulnerability
• Keep your report confidential and not share your identity with third parties without your permission
• Work with you cooperatively and keep you informed throughout the process
• Credit you in our security advisory if you wish – let us know your preferred name or handle
• Not require you to keep the vulnerability confidential beyond the 90-day resolution period
6. Disclosure policy
Acconeer follows a coordinated disclosure model. We ask that you give us 90 days from your initial report to develop and release a fix before disclosing publicly. We will coordinate the timing and content of any public disclosure with you.
If we cannot resolve the issue within 90 days we will contact you to explain why and agree an extended timeline. We will not ask for extensions beyond what is genuinely needed.
If a vulnerability is being actively exploited in the wild, we may accelerate disclosure and notify relevant authorities (ENISA and CERT-SE) in accordance with our obligations under Article 14 of Regulation (EU) 2024/2847.
7. Regulatory reporting obligations
Acconeer is subject to mandatory incident reporting obligations under Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847) from 11 September 2026. Where a reported vulnerability constitutes an actively exploited vulnerability or a severe incident, we are required to notify ENISA and CERT-SE (Swedish national CSIRT) within the following timelines:
• Within 24 hours: early warning to ENISA and CERT-SE
• Within 72 hours: detailed vulnerability notification
• Within 14 days: final report including root cause and remediation
We will inform you if your report triggers these obligations. Regulatory notifications describe the vulnerability; your identity is not shared without consent.
8. Conduct outside this policy
The following actions are not covered by this policy and may result in legal action:
• Accessing, modifying, or deleting data belonging to Acconeer or its customers
• Performing denial-of-service attacks
• Exfiltrating data beyond what is necessary to demonstrate the vulnerability
• Disclosing vulnerability details publicly before the 90-day period expires without agreement
• Demanding payment in exchange for vulnerability information (we do not operate a bug bounty programme)
9. Contact and further information
| Security email | security@acconeer.com |
| Security page | acconeer.com/security |
| Postal address | Acconeer AB, Västra Varvsgatan 19, 211 77 Malmö, Sweden |
| Company registration | Acconeer AB |
This policy is reviewed annually. The latest version is always available at acconeer.com/security.
