Y Soft Opens Vulnerability Reporting Channel Under the EU Cyber Resilience Act

From 11th September 2026, anyone — customers, partners, or independent security researchers — can report a suspected vulnerability in a Y Soft product directly to us. It's part of Y Soft's response to the EU Cyber Resilience Act (CRA), which took effect on 11th September 2026: when a vulnerability is being actively exploited, Y Soft must now report it to ENISA, the EU's cybersecurity agency, within 24 hours of finding out, followed by a full report within 72 hours. We built the process to meet that deadline — and opened it to everyone, not just regulators.

What is the Cyber Resilience Act?

The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for hardware and software sold in the EU. It covers any product with a digital component that connects to a network or another device — which puts SAFEQ Cloud, SAFEQ 6, and YSoft HARDWARE, including card readers, in scope. For decades, the cost of insecure software has landed on customers and society while vendors faced few consequences. The CRA changes that: it makes security a legal obligation for manufacturers, not a competitive extra.

What triggers a report

The obligation that starts September 11 (Article 14 of the CRA) covers one specific case: a vulnerability that's being actively exploited in the wild — not an ordinary bug, and not a theoretical risk with no evidence of exploitation. When that trigger is met, Y Soft reports it to ENISA on a fixed timeline: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days to a month after a fix is available.

What this means for customers and partners

This is Y Soft's obligation, not customers' or partners'. Nothing changes about how you use SAFEQ Cloud, SAFEQ 6, or YSoft HARDWARE today. A new reporting requirement is not a sign that Y Soft products have new vulnerabilities, and it doesn't change commercial terms or support agreements. What it does give you is legal certainty: if a real-world exploit affects a Y Soft product, Y Soft has to disclose it — not at its own discretion, but by law — and ENISA keeps a public record you can check.

Part of Y Soft's Long-Standing Security Posture

Y Soft's ENISA reporting process is live and operational. It builds on security work the company has invested in for years, including ISO 27001 certification and SOC 2 compliance, with FedRAMP and IRAP assessments now in progress. CRA compliance isn't a new initiative for Y Soft — it's the latest chapter in a security posture the company has built for years.

What comes next

Today's requirement is the first of two CRA milestones for Y Soft. The second lands on December 11, 2027, when full product conformity requirements — CE marking, technical documentation, and declared security support periods — apply to new SAFEQ placements.

Report a security issue

Customers, partners, and independent researchers who find or suspect a security issue in a Y Soft product can report it directly.

About Y Soft

For 25+ years, Y Soft has cleared the path for businesses of all sizes to embrace better ways of working, including 38% of the Global Fortune 500. They help SMBs and enterprises enhance productivity, support hybrid and remote workforces, and scale without constraints.

Their suite of office solutions includes SAFEQ® (on-prem and native cloud SaaS printing), AIVA (test automation), CLERBO® (digital employee experience), in-house manufactured hardware (including card readers and OMNI Bridge®), and Manufacturing as a Service. With customers in 190 countries, Y Soft is on a mission to help businesses simplify and automate everyday work.

The company is headquartered in Brno, Czech Republic, with offices in NALA, EMEA, and APAC regions. For more information, visit  www.ysoft.com.