
Cybersecurity is a top priority for Bender. We therefore continuously monitor relevant developments and threats in the cybersecurity landscape and incorporate these findings into our development processes. Any vulnerabilities identified are investigated promptly and, where necessary, rectified through security updates.
As a member of the Computer Emergency Response Team (CERT) of the German Electrical Engineering Association (CERT@VDE.CERT)), Bender benefits from the measures, the exchange and the solutions found together with partners. The expert group of IT specialists, which is geared to the interests and requirements of medium-sized companies, reports security gaps, develops solution approaches and provides these to the partners.
We are thus notified of potential vulnerabilities at the earliest possible stage and can react immediately.
Furthermore, Bender is a member of the Allianz für Cybersicherheit (ACS) at the Federal Office for Information Security (BSI). Regular penetration tests and IT audits are used to check the security standard. They are carried out at regular intervals within the framework of security certifications that reflect the respective level of knowledge. Internal systems are always sealed off according to the current state of the art in order to prevent external access. This prevents malicious code from reaching the devices in all phases of product development.
We welcome collaboration with the security community to identify and address vulnerabilities in our products and systems. The Coordinated Vulnerability Disclosure Policy sets out how we handle reports of security vulnerabilities and what we expect from those who report them.
The Cyber Resilience Act (CRA) establishes new mandatory requirements for the cybersecurity of products with digital components. As a manufacturer of solutions for electrical safety and energy availability, we at Bender are committed to implementing these requirements early on and in a sustainable manner.
Starting December 11, 2027, affected products may only be made available in the EU if they have demonstrated CRA compliance. The first reporting requirements for actively exploited vulnerabilities will take effect on September 11, 2026.
For existing products, the CRA means that cybersecurity must be ensured not only at the time of market launch, but throughout the entire product lifecycle. This includes the continuous assessment of risks, the provision of security updates, and the structured handling of vulnerabilities during operation. Our processes are therefore designed to ensure that products can be operated securely over the long term and that we can respond to new threats even after they are in the field.
Even without fully harmonized standards, we already adhere to the fundamental principles of the CRA as well as established best practices. These include, in particular:
This ensures that our products already meet high safety standards today and that future regulatory requirements can be efficiently incorporated.
With this holistic approach, Bender aims to permanently embed cybersecurity in its products while fostering transparency and trust among its customers.

Vulnerabilities can be reported via the e-mail address psirt@bender.de.
If you want to communicate with us in encrypted form, please use this PGP key.
Published Vulnerability Reports