Cyber Resilience Act at Qlar

The Cyber Resilience Act is setting new standards for the security of digital products across Europe. At Qlar, we see these requirements not only as a regulatory obligation, but as an opportunity to strengthen security, quality, and trust in a sustainable way. Through clear processes, technical excellence, and a holistic approach to cybersecurity, we are committed to making our products and solutions CRA-compliant and future-ready.

Qlar PSIRT Contact Information

Our Product Security Incident Response Team (PSIRT) is the central point of contact for reports of cybersecurity incidents and potential vulnerabilities in our products. If you discover a security vulnerability or suspect that a vulnerability is being exploited, you can report it to us at any time through our designated reporting channel. We review every report confidentially, evaluate it promptly, and take appropriate action as needed.

Email: cra@qlar.com

Report Handling

Upon receiving a report, a confirmation mail will be sent within 3 business days. Our PSIRT investigates the matter, assesses the potential impact, and prioritizes the next steps. Confirmed vulnerabilities are handled on a risk-based basis and addressed without undue delay, while you receive an informed professional response within 10 business days.

If there are indications of an actively exploited vulnerability, we comply with the legal reporting requirements of the Cyber Resilience Act, specifically the 24-hour early warning, 72-hour notification, and 14-day final report for Actively Exploited Vulnerabilities or 1 month final report for Severe Incidents respectively. Affected customers and relevant stakeholders are informed promptly, as necessary.

PSIRT Process

Support Periods of CRA-related Qlar solutions

[Placeholder; Relevant by Dec. 2027]

Overview List of CRA-related Qlar solutions including support periods, lastest software versions, history of vulnerabilities, SL-vectors et. al.: LINK