{"id":36434,"date":"2026-09-14T10:31:13","date_gmt":"2026-09-14T08:31:13","guid":{"rendered":"https:\/\/acconeer.com\/?page_id=36434"},"modified":"2026-09-14T10:31:14","modified_gmt":"2026-09-14T08:31:14","slug":"coordinated-vulnerability-disclosure-policy","status":"publish","type":"page","link":"https:\/\/acconeer.com\/sv\/coordinated-vulnerability-disclosure-policy\/","title":{"rendered":"Coordinated Vulnerability Disclosure Policy"},"content":{"rendered":"\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p>Version 1.0 &#8211; September 2026<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p><strong>1.&nbsp; Purpose<\/strong>&nbsp;<\/p>\n\n\n\n<p>Acconeer&nbsp;AB designs and manufactures radar sensor modules and ICs. We take the security of our products seriously and welcome reports from security researchers, customers, and the public about potential vulnerabilities in any product we place on the market.&nbsp;<\/p>\n\n\n\n<p>This policy describes how to report a potential vulnerability to&nbsp;Acconeer, what you can expect from us in return, and how we will handle the report through to resolution and public disclosure. It is published in fulfilment of Regulation (EU) 2024\/2847 (Cyber Resilience Act), Annex I \u00a72(1), and complements our obligations under Article 14.&nbsp;<\/p>\n\n\n\n<p><strong>2.&nbsp; Scope<\/strong>&nbsp;<\/p>\n\n\n\n<p>This policy applies to security vulnerabilities in:&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Acconeer&nbsp;radar sensor modules and ICs placed on the EU market (A111, A121, A212, XM122, XM123, XM124, XM125, XM126, XM131, XM132)&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Firmware, bootloaders, and software delivered by&nbsp;Acconeer&nbsp;as part of those products&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Acconeer&nbsp;SDK components and libraries shipped in product deliveries&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>acconeer.com and developer.acconeer.com web properties&nbsp;<\/p>\n\n\n\n<p>Out of scope:&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Vulnerabilities in third-party products or services that&nbsp;Acconeer&nbsp;does not control&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Vulnerabilities in development hardware (XA, XB, XC, XE, XV series)&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Social engineering, phishing, or physical attacks against&nbsp;Acconeer&nbsp;staff&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Denial-of-service attacks against&nbsp;Acconeer&nbsp;infrastructure&nbsp;<\/p>\n\n\n\n<p><strong>3.&nbsp; How to report a vulnerability<\/strong>&nbsp;<\/p>\n\n\n\n<p>Send your report by email to security@acconeer.com. Please include as much of the following as possible:&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>The affected product, firmware version, or software&nbsp;component&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>A description of the vulnerability and its potential impact&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Step-by-step instructions to reproduce the issue&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Any proof-of-concept code, screenshots, or supporting material&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Your contact details and preferred communication method&nbsp;<\/p>\n\n\n\n<p>If you would like to encrypt your report, please request our PGP public key at security@acconeer.com before sending sensitive details.&nbsp;<\/p>\n\n\n\n<p><strong>Please do not&nbsp;<\/strong>report security vulnerabilities through public GitHub issues, forum posts, or social media. Doing so may put other users at risk before a fix is available.&nbsp;<\/p>\n\n\n\n<p><strong>4.&nbsp; What you can expect from us<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Timeline<\/strong>&nbsp;<\/td><td><strong>Our commitment<\/strong>&nbsp;<\/td><\/tr><tr><td><strong>Within 5 business days<\/strong>&nbsp;<\/td><td>Acknowledge receipt of your report and confirm we have received it&nbsp;<\/td><\/tr><tr><td><strong>Within 14 days<\/strong>&nbsp;<\/td><td>Provide&nbsp;an initial&nbsp;assessment: confirm whether the issue is valid, the affected products, and a severity rating&nbsp;<\/td><\/tr><tr><td><strong>Within 90 days<\/strong>&nbsp;<\/td><td>Aim to have a fix available or a mitigation in place. We will keep you informed of our progress. If more time is&nbsp;needed&nbsp;we will tell you why and agree an extended timeline&nbsp;<\/td><\/tr><tr><td><strong>At resolution<\/strong>&nbsp;<\/td><td>Notify you&nbsp;when the fix is released and coordinate the timing of public disclosure with you&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>5.&nbsp; Our commitments to reporters<\/strong>&nbsp;<\/p>\n\n\n\n<p>When you report in good faith and follow this policy,&nbsp;Acconeer&nbsp;commits to:&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Not pursue legal action against you for the discovery or reporting of the vulnerability&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Keep your report confidential and not share your identity with third parties without your permission&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Work with you cooperatively and keep you informed throughout the process&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Credit you in our security advisory if you wish &#8211; let us know your preferred name or handle&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Not require you to keep the vulnerability confidential beyond the 90-day resolution period&nbsp;<\/p>\n\n\n\n<p><strong>6.&nbsp; Disclosure policy<\/strong>&nbsp;<\/p>\n\n\n\n<p>Acconeer&nbsp;follows a coordinated disclosure model. We ask that you give us 90 days from your&nbsp;initial&nbsp;report to develop and release a fix before&nbsp;disclosing&nbsp;publicly. We will coordinate the timing and content of any public disclosure with you.&nbsp;<\/p>\n\n\n\n<p>If we cannot resolve the issue within 90&nbsp;days&nbsp;we will&nbsp;contact&nbsp;you to explain why and&nbsp;agree&nbsp;an extended timeline. We will not ask for extensions beyond what is genuinely needed.&nbsp;<\/p>\n\n\n\n<p>If a vulnerability is being actively exploited in the wild, we may accelerate disclosure and notify relevant authorities (ENISA and CERT-SE)&nbsp;in accordance with&nbsp;our obligations under Article 14 of Regulation (EU) 2024\/2847.&nbsp;<\/p>\n\n\n\n<p><strong>7.&nbsp; Regulatory reporting obligations<\/strong>&nbsp;<\/p>\n\n\n\n<p>Acconeer&nbsp;is subject to mandatory incident reporting obligations under Article 14 of the Cyber Resilience Act (Regulation (EU) 2024\/2847) from 11 September 2026. Where a reported vulnerability&nbsp;constitutes&nbsp;an actively exploited vulnerability or a severe incident, we&nbsp;are required to&nbsp;notify ENISA&nbsp;and CERT-SE (Swedish national CSIRT) within the following timelines:&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Within 24 hours: early warning to ENISA and CERT-SE&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Within 72 hours: detailed vulnerability notification&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Within 14 days: final report including root cause and remediation&nbsp;<\/p>\n\n\n\n<p>We will inform you if your report triggers these obligations.&nbsp;Regulatory notifications describe the vulnerability; your identity is not shared without consent.&nbsp;<\/p>\n\n\n\n<p><strong>8.&nbsp; Conduct outside this policy<\/strong>&nbsp;<\/p>\n\n\n\n<p>The following actions are not covered by this policy and may result in legal action:&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Accessing,&nbsp;modifying, or&nbsp;deleting&nbsp;data belonging to&nbsp;Acconeer&nbsp;or its customers&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Performing denial-of-service attacks&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Exfiltrating data beyond what is necessary to&nbsp;demonstrate&nbsp;the vulnerability&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Disclosing vulnerability details publicly before the 90-day period expires without agreement&nbsp;<\/p>\n\n\n\n<p><strong>\u2022&nbsp;&nbsp;<\/strong>Demanding payment in exchange for vulnerability information (we do not&nbsp;operate&nbsp;a bug bounty&nbsp;programme)&nbsp;<\/p>\n\n\n\n<p><strong>9.&nbsp; Contact and further information<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Security&nbsp;email<\/strong>&nbsp;<\/td><td>security@acconeer.com&nbsp;<\/td><\/tr><tr><td><strong>Security&nbsp;page<\/strong>&nbsp;<\/td><td>acconeer.com\/security&nbsp;<\/td><\/tr><tr><td><strong>Postal&nbsp;address<\/strong>&nbsp;<\/td><td>Acconeer&nbsp;AB, V\u00e4stra&nbsp;Varvsgatan&nbsp;19, 211 77 Malm\u00f6, Sweden&nbsp;<\/td><\/tr><tr><td><strong>Company&nbsp;registration<\/strong>&nbsp;<\/td><td>Acconeer&nbsp;AB&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>This policy is reviewed annually. The latest version is always available at acconeer.com\/security.<\/p>\n<\/div>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Version 1.0 &#8211; September 2026 1.&nbsp; Purpose&nbsp; Acconeer&nbsp;AB designs and manufactures radar sensor modules and ICs. We take the security of our products seriously and welcome reports from security researchers, customers, and the public about potential vulnerabilities in any product we place on the market.&nbsp; This policy describes how to report a potential vulnerability to&nbsp;Acconeer, [&hellip;]<\/p>\n","protected":false},"author":30,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"_acc_breadcrumb_crumbs":[],"_acc_breadcrumb_override":false,"_acc_hide_title":"","footnotes":""},"class_list":["post-36434","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Coordinated Vulnerability Disclosure Policy - Acconeer<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/acconeer.com\/coordinated-vulnerability-disclosure-policy\/\" \/>\n<meta property=\"og:locale\" content=\"sv_SE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Coordinated Vulnerability Disclosure Policy - Acconeer\" \/>\n<meta property=\"og:description\" content=\"Version 1.0 &#8211; September 2026 1.&nbsp; Purpose&nbsp; Acconeer&nbsp;AB designs and manufactures radar sensor modules and ICs. We take the security of our products seriously and welcome reports from security researchers, customers, and the public about potential vulnerabilities in any product we place on the market.&nbsp; This policy describes how to report a potential vulnerability to&nbsp;Acconeer, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/acconeer.com\/coordinated-vulnerability-disclosure-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"Acconeer\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-14T08:31:14+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Ber\u00e4knad l\u00e4stid\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minuter\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/acconeer.com\\\/coordinated-vulnerability-disclosure-policy\\\/\",\"url\":\"https:\\\/\\\/acconeer.com\\\/coordinated-vulnerability-disclosure-policy\\\/\",\"name\":\"Coordinated Vulnerability Disclosure Policy - Acconeer\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/acconeer.com\\\/#website\"},\"datePublished\":\"2026-09-14T08:31:13+00:00\",\"dateModified\":\"2026-09-14T08:31:14+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/acconeer.com\\\/coordinated-vulnerability-disclosure-policy\\\/#breadcrumb\"},\"inLanguage\":\"sv-SE\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/acconeer.com\\\/coordinated-vulnerability-disclosure-policy\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/acconeer.com\\\/coordinated-vulnerability-disclosure-policy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/acconeer.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Coordinated Vulnerability Disclosure Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/acconeer.com\\\/#website\",\"url\":\"https:\\\/\\\/acconeer.com\\\/\",\"name\":\"Acconeer\",\"description\":\"EXPLORE THE NEXT SENSE\",\"publisher\":{\"@id\":\"https:\\\/\\\/acconeer.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/acconeer.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"sv-SE\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/acconeer.com\\\/#organization\",\"name\":\"Acconeer\",\"url\":\"https:\\\/\\\/acconeer.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"sv-SE\",\"@id\":\"https:\\\/\\\/acconeer.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/New-Logo-2.png\",\"contentUrl\":\"\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/New-Logo-2.png\",\"width\":2048,\"height\":767,\"caption\":\"Acconeer\"},\"image\":{\"@id\":\"https:\\\/\\\/acconeer.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Coordinated Vulnerability Disclosure Policy - Acconeer","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/acconeer.com\/coordinated-vulnerability-disclosure-policy\/","og_locale":"sv_SE","og_type":"article","og_title":"Coordinated Vulnerability Disclosure Policy - Acconeer","og_description":"Version 1.0 &#8211; September 2026 1.&nbsp; Purpose&nbsp; Acconeer&nbsp;AB designs and manufactures radar sensor modules and ICs. We take the security of our products seriously and welcome reports from security researchers, customers, and the public about potential vulnerabilities in any product we place on the market.&nbsp; This policy describes how to report a potential vulnerability to&nbsp;Acconeer, [&hellip;]","og_url":"https:\/\/acconeer.com\/coordinated-vulnerability-disclosure-policy\/","og_site_name":"Acconeer","article_modified_time":"2026-09-14T08:31:14+00:00","twitter_card":"summary_large_image","twitter_misc":{"Ber\u00e4knad l\u00e4stid":"4 minuter"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/acconeer.com\/coordinated-vulnerability-disclosure-policy\/","url":"https:\/\/acconeer.com\/coordinated-vulnerability-disclosure-policy\/","name":"Coordinated Vulnerability Disclosure Policy - Acconeer","isPartOf":{"@id":"https:\/\/acconeer.com\/#website"},"datePublished":"2026-09-14T08:31:13+00:00","dateModified":"2026-09-14T08:31:14+00:00","breadcrumb":{"@id":"https:\/\/acconeer.com\/coordinated-vulnerability-disclosure-policy\/#breadcrumb"},"inLanguage":"sv-SE","potentialAction":[{"@type":"ReadAction","target":["https:\/\/acconeer.com\/coordinated-vulnerability-disclosure-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/acconeer.com\/coordinated-vulnerability-disclosure-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/acconeer.com\/"},{"@type":"ListItem","position":2,"name":"Coordinated Vulnerability Disclosure Policy"}]},{"@type":"WebSite","@id":"https:\/\/acconeer.com\/#website","url":"https:\/\/acconeer.com\/","name":"Acconeer","description":"EXPLORE THE NEXT SENSE","publisher":{"@id":"https:\/\/acconeer.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/acconeer.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"sv-SE"},{"@type":"Organization","@id":"https:\/\/acconeer.com\/#organization","name":"Acconeer","url":"https:\/\/acconeer.com\/","logo":{"@type":"ImageObject","inLanguage":"sv-SE","@id":"https:\/\/acconeer.com\/#\/schema\/logo\/image\/","url":"\/wp-content\/uploads\/2026\/05\/New-Logo-2.png","contentUrl":"\/wp-content\/uploads\/2026\/05\/New-Logo-2.png","width":2048,"height":767,"caption":"Acconeer"},"image":{"@id":"https:\/\/acconeer.com\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/acconeer.com\/sv\/wp-json\/wp\/v2\/pages\/36434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/acconeer.com\/sv\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/acconeer.com\/sv\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/acconeer.com\/sv\/wp-json\/wp\/v2\/users\/30"}],"replies":[{"embeddable":true,"href":"https:\/\/acconeer.com\/sv\/wp-json\/wp\/v2\/comments?post=36434"}],"version-history":[{"count":3,"href":"https:\/\/acconeer.com\/sv\/wp-json\/wp\/v2\/pages\/36434\/revisions"}],"predecessor-version":[{"id":36619,"href":"https:\/\/acconeer.com\/sv\/wp-json\/wp\/v2\/pages\/36434\/revisions\/36619"}],"wp:attachment":[{"href":"https:\/\/acconeer.com\/sv\/wp-json\/wp\/v2\/media?parent=36434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}