Premio Product Security & Cyber Resilience

Built Rugged. Built Ready. Built Secure.


Premio is committed to delivering secure, reliable, and lifecycle-managed industrial edge computing platforms designed for long-term deployment and operational resilience. As part of this commitment, Premio is certified to IEC 62443-4-1, reinforcing our secure product development lifecycle and cybersecurity foundation.

Vulnerability Handling & PSIRT Process

Premio is establishing a product security vulnerability handling process to support customers, partners, suppliers, and security researchers who identify potential vulnerabilities in Premio products.

CVD Policy & Vulnerability Reporting

We follow a coordinated vulnerability disclosure process to ensure security issues are handled responsibly, transparently, and in partnership with security researchers.

How to Report

  • Product model
  • Firmware or software version
  • Vulnerability description
  • Impact
  • Reproduction steps, if available

Use PGP Key for Encryption

-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEapjY5RYJKwYBBAHaRw8BAQdA23FQBpeSyAkbGsOjKH+2YxjO91aKMfJwFIKR
MD/pEZ+0G3BzaXJ0IDxwc2lydEBwcmVtaW9pbmMuY29tPoi1BBMWCgBdFiEEubNL
lyHlxPX7TChPbOjjrWLGIOEFAmqY2OUbFIAAAAAABAAObWFudTIsMi41KzEuMTIs
MiwxAhsDBQkFpIVLBQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheAAAoJEGzo461i
xiDhro4BAMSjp+LXuszCFSI59DFWWcpxM52TLCO+bZErY/AL1HlEAP9IQzYEEl9l
5pY3cHRXO94YEQvVkr4muc9CEmrRnAehCrg4BGqY2OUSCisGAQQBl1UBBQEBB0Cs
Ga3rPYb+EE6GAqsqVmbkYHWHCmMNRCF3qB/4qc4rTAMBCAeImgQYFgoAQhYhBLmz
S5ch5cT1+0woT2zo461ixiDhBQJqmNjlGxSAAAAAAAQADm1hbnUyLDIuNSsxLjEy
LDIsMQIbDAUJBaSFSwAKCRBs6OOtYsYg4arhAQDLdXV47etJh8LxFaCk3LPJCkws
2YW4gzXgv9wNOEdkLgEAoujfMPiUzzrJspUuZvHPylIOrc8Fw0veeB/Lg+2jSwA=
=nEwO
-----END PGP PUBLIC KEY BLOCK-----
          

Our Response Timeframes

Acknowledgement of receipt: Within 72 hours
Initial triage: Within 5 business days
Validation and impact assessment: Based on issue complexity
Status updates: Periodically during investigation
Mitigation, patch, or advisory: Based on severity and patch availability

1. Report

Submit vulnerability details to psirt@premioinc.com.

2. Triage

We acknowledge and triage the report.

3. Assess

We validate and assess the impact.

4. Remediate

We develop and test a fix or mitigation.

5. Advise

We share updates and publish advisory.

Security Advisories

Advisory ID CVE ID Advisory Title Severity Status Affected Product Last Updated Downloads

Advancing Product Security for CRA Readiness

As cybersecurity requirements continue to evolve, Premio is actively preparing for the European Union Cyber Resilience Act, CRA, and strengthening our product security practices across secure development, vulnerability handling, software component visibility, security updates, and customer-facing documentation.

Our goal is to help customers deploy Premio industrial computers with greater confidence, transparency, and long-term cyber resilience.

Key CRA Milestones

December 10th, 2024

CRA entered into force

January 23rd, 2026

Premio certified to
IEC 62443-4-1:2018

September 11th, 2026

Vulnerability and incident reporting begins

December 11th, 2027

Full CRA compliance and CE marking requirements apply

Premio Product Security Foundation

IEC 62443-4-1 Certified SDL

Premio’s secure development lifecycle is certified to IEC 62443-4-1, reinforcing our cybersecurity foundation for industrial edge computing platforms.

SSDLC Practices

Premio applies secure software development practices across firmware, OS images, drivers, utilities, and software components to reduce product security risk.

PSIRT & Vulnerability Handling

Premio strengthens product security response processes for CVE / KEV assessment, mitigation planning, patch coordination, and security advisories.

SBOM & CRA Readiness

Premio is reviewing SBOM management, software component visibility, and lifecycle documentation to support Cyber Resilience Act readiness.

Premio’s CRA Readiness & Cyber Resilience Framework

Explore how the Cyber Resilience Act is reshaping product security expectations and how Premio is strengthening its secure development, lifecycle security, vulnerability readiness, and customer transparency practices for industrial edge computing platforms.

Understanding the Cyber Resilience Act

The Cyber Resilience Act, CRA, is a European Union regulation that introduces cybersecurity requirements for hardware and software products with digital elements placed on the EU market.

The CRA is designed to strengthen the cybersecurity of connected products throughout their lifecycle, from planning and design to development, production, maintenance, vulnerability handling, and security updates.

For manufacturers, CRA introduces a shift from one-time product compliance to continuous lifecycle cybersecurity management.

Main Objectives of the Cyber Resilience Act

Product Lifecycle Security

Strengthen cybersecurity from design and development through deployment, maintenance, vulnerability handling, and security updates.

Digital Supply Chain Resilience

Establish a unified EU cybersecurity framework to reduce risk across connected hardware, software, and product ecosystems.

Transparency and Customer Confidence

Provide clearer security information, vulnerability reporting processes, update guidance, and user documentation to support safer product deployment.

Premio’s CRA Readiness Foundation

Premio’s quality, environmental, medical, and cybersecurity management foundations ensure our products are built to the highest global standards – ready for today and resilient for tomorrow.

Among these, IEC 62443-4-1 is especially relevant to cybersecurity readiness because it supports a secure product development lifecycle. This provides a process foundation for secure product design, vulnerability handling, security verification, and product lifecycle management

Premio’s Core Focus Areas for CRA Readiness

Secure Development Lifecycle

SDL and secure-by-design practices

Risk Assessment

Threat Analysis and Risk Assessment, TARA

SBOM Visibility

SBOM management and software component visibility

Vulnerability Management

Vulnerability handling, CVE / KEV monitoring, and security updates

Security Documentation

Product security documentation and customer-facing guidance

Conformity Planning

CRA product classification and conformity assessment planning

Premio’s Cybersecurity Commitment

Premio develops rugged industrial computers and edge AI systems for long-lifecycle deployments in demanding environments. These systems are often deployed in distributed, remote, and operational technology environments where security, reliability, and lifecycle support are critical.

Premio’s cybersecurity commitment is built around four key pillars:

1. Secure Development Foundation

Integrating cybersecurity considerations into product planning, design, development, validation, and maintenance.

2. Vulnerability Handling and Response

Establishing processes to identify, assess, mitigate, and communicate product security vulnerabilities.

3. Lifecycle Security Support

Supporting customers with security updates, product documentation, and guidance during the applicable product support period.

4. Customer Transparency

Providing clearer access to security advisories, product security contact points, and security-related documentation.

CRA Documentation and EU Declaration of Conformity

Premio is reviewing CRA-related documentation requirements for applicable products with digital elements.

As CRA implementation progresses, Premio will continue to evaluate product classification, conformity assessment requirements, technical documentation, security support information, vulnerability handling evidence, and EU Declaration of Conformity requirements where applicable.

Premio will make relevant compliance documentation available according to product scope, market requirements, and regulatory timelines.

Frequently Asked Questions

The Cyber Resilience Act, CRA, is a European Union regulation that introduces cybersecurity requirements for products with digital elements placed on the EU market. It is designed to improve product security across the full lifecycle, including design, development, production, vulnerability handling, security updates, and customer documentation.

Industrial edge computers are increasingly connected to operational technology networks, AI workloads, remote management systems, and distributed infrastructure. The CRA reinforces the need for secure product development, software component visibility, vulnerability management, security updates, and lifecycle documentation for connected hardware and software products.

The timeline for compliance is structured as follows:

  • December 10, 2024: The Cyber Resilience Act officially entered into force.
  • September 11, 2026: Reporting obligations begin to apply. From this date forward, manufacturers are required to report actively exploited vulnerabilities and severe security incidents.
  • December 11, 2027: The main obligations introduced by the CRA become fully applicable

Premio is actively preparing for CRA requirements. Full CRA product compliance obligations apply from 11 December 2027. Product-level CRA conformity will depend on the applicable product scope, configuration, classification, documentation, and assessment requirements.

Premio is strengthening product security practices across secure development, vulnerability handling, SBOM management, security updates, product security documentation, and conformity assessment planning. Premio’s existing IEC 62443-4-1 certification provides a strong secure development lifecycle foundation for CRA readiness.

Premio currently maintains ISO 9001:2015, ISO 13485:2016, ISO 14001:2015, and IEC 62443-4-1 certifications. Among these, IEC 62443-4-1 is especially relevant because it supports secure product development lifecycle processes.

No. IEC 62443-4-1 supports Premio’s secure product development lifecycle, but CRA also requires product-level assessment, vulnerability handling, documentation, security update management, and conformity evaluation based on the applicable product category and configuration.

PSIRT stands for Product Security Incident Response Team. Premio’s PSIRT process coordinates the review, assessment, mitigation, and communication of potential product security vulnerabilities. For PSIRT inquiries, please contact psirt@premioinc.com.

If you believe you have identified a potential security vulnerability affecting a Premio product, please contact Premio’s Product Security Incident Response Team, PSIRT, at psirt@premioinc.com. To help us review the report efficiently, please include the product model, software or firmware version, vulnerability description, potential impact, and reproduction steps where available.

When reporting a vulnerability to psirt@premioinc.com, please include as much relevant information as possible, such as product model, serial number if applicable, BIOS or firmware version, OS image version, driver or software version, system configuration, vulnerability description, potential impact, reproduction steps, supporting logs or screenshots, and CVE ID if available.

Premio will review the submitted information, validate whether the issue may affect Premio products, assess the potential impact, coordinate with internal teams or suppliers as needed, and determine appropriate mitigation, patch, documentation, or customer communication steps.

Premio is establishing a product security advisory process to communicate relevant vulnerabilities, affected products, mitigation steps, update availability, and customer actions where appropriate.

Premio will provide security advisories through its official product security resources. For questions related to a specific advisory or suspected vulnerability, please contact psirt@premioinc.com.

CVE, Common Vulnerabilities and Exposures, is a public identifier for a known cybersecurity vulnerability. KEV, Known Exploited Vulnerability, refers to a vulnerability that has been observed being actively exploited in the real world. Premio is reviewing processes to monitor CVEs and KEVs that may affect supported product configurations.

SBOM stands for Software Bill of Materials. It is a structured inventory of software and firmware components included in a product configuration. SBOM management helps identify affected components when vulnerabilities are discovered and supports vulnerability analysis, patch planning, and lifecycle security documentation.

Premio is reviewing SBOM management processes for supported product configurations. SBOM availability may depend on product family, software configuration, customer requirement, and applicable regulatory requirement.

Premio security updates may vary by product and affected component. Updates may include BIOS updates, firmware updates, OS image updates, driver updates, software utility updates, OOB management firmware updates, configuration guidance, temporary mitigations, or updated documentation.

Security support periods may vary by product family, product lifecycle status, software configuration, supplier support, and applicable regulatory requirements. Premio is reviewing how to provide clearer product security support period information for applicable products.

CRA applicability depends on product scope, configuration, intended use, and how the product is placed on the EU market. Premio is reviewing product classification and conformity assessment requirements across applicable product families.

For potential product security vulnerabilities or PSIRT-related inquiries, please contact Premio PSIRT at psirt@premioinc.com. For general CRA, compliance, sales, or technical support questions, please contact Premio through the appropriate sales or support channel.