Home Support Non-disclosure reporting

Non-disclosure Reporting

This page describes RTX’s process for reporting and handling security vulnerabilities according to the Cybersecurity Resilience Act (CRA).

Introduction

The RTX PSIRT (Product Security Incident Response Team) is responsible for managing security issues, including vulnerabilities and incidents, affecting RTX products.

RTX is committed to proactively addressing potential security vulnerabilities. As part of this commitment, we provide a dedicated product security point of contact to ensure efficient handling, coordination, and resolution of reported issues.

Vulnerability Disclosure Policy

RTX publishes security advisories for affected products in alignment with CERT’s Coordinated Vulnerability Disclosure (CVD) framework. This approach ensures that vulnerabilities are responsibly managed, risks are mitigated, and users receive sufficient information to assess potential impacts on their systems.

Security advisories do not represent a comprehensive list of all reported incidents, as disclosures are coordinated and published in accordance with CVD principles.

RTX aims to comply with applicable regulations and legislation. To support this, a structured PSIRT reporting mechanism has been established to collect, evaluate, and act on vulnerability information submitted to RTX.

Policy Scope

Purpose & Scope

This policy defines the process for reporting vulnerabilities affecting RTX-branded systems, products, solutions, and services.

The following are out of scope and not covered by this policy:

  • Vulnerabilities in products or services licensed to or managed by third parties
  • Non-technical issues such as social engineering or manipulation
  • Cybersecurity incidents or attacks, including Denial of Service (DoS) vulnerabilities

Step-by-step Process

Reporting a Vulnerability

If you believe you have identified a security vulnerability, please report it to RTX at: security@rtx.dk

Please ensure your report includes sufficient detail to allow validation and reproduction.

Required information:

  • Hardware/software product name with any version or revision number in RTX
  • Proof-of-concept code (if available)
  • Detailed description of the vulnerability
  • Detailed description of potential exploitation scenarios
  • Date of discovery
  • Method of discovery
  • Reproduction steps to confirm the potential vulnerability
  • Technical details (e.g., system configuration, logs, traces, exploit code, sample packet capture)
  • Tools/software name/version used for validation
  • Potential impact of the vulnerability
  • References to any public disclosures (e.g., CVE, research papers)
  • Common Vulnerability Scoring System (CVSS) V3 or V4 score (if available)

Your contact information:

  • Name
  • Organization/Company
  • Department/Role
  • Email Address
  • Phone Number

Incomplete submissions may delay or prevent validation. All reports must be submitted in English.

Submission guidelines

When submitting a report:

  • Attach screenshots as files (Word or PDF), rather than embedding them in the email body.
  • Use a clear and non-sensitive subject line
  • Include your public key for secure communication

Important Notice:

  • This process applies only to RTX products. For other inquiries, please contact your RTX representative.
  • Contact information is used solely for vulnerability handling. See RTX Privacy Policy https://www.rtx.dk/privacy-statement/).
  • To protect our customers, we encourage you not to share the vulnerability with any other people or organization without prior coordination with the RTX PSIRT. You may be asked to delay disclosure until remediation is complete. 
  • Response times may vary depending on complexity.
    Thank you for your cooperation.

Report a Vulnerability Here

Please include: - Detailed description of the vulnerability - Detailed description of potential exploitation scenarios - Date of discovery - Method of discovery
Please include: - Hardware/software product name with any version or revision number in RTX - Proof-of-concept code (if available) - Technical details (e.g., system configuration, logs, traces, exploit code, sample packet capture) - Tools/software name/version used for validation
Please include: - Reproduction steps to confirm the potential vulnerability - Potential impact of the vulnerability - References to any public disclosures (e.g., CVE, research papers) - Common Vulnerability Scoring System (CVSS) V3 or V4 score (if available)

By submitting this form, you give your consent for RTX to process your personal data for the above purposes.
Read more in our Privacy Statement.

What RTX does

Analysis

Upon receiving a report, RTX will investigate the potential vulnerability in accordance with internal procedures. We will keep you updated throughout the process and may request additional information to reproduce the vulnerability. If confirmed, a risk assessment will be conducted to determine its severity and potential impacts.

Handling

Validated vulnerabilities are addressed through a remediation plan prioritized according to the severity of the issue and the risk analysis.

Disclosure

Once resolved, RTX will disclose the vulnerability to relevant stakeholders. We aim to balance transparency with the need to give our partners sufficient time to implement necessary fixes. As such, the publication of advisories may be delayed to reduce potential risks.

RTX acknowledges contributors who have voluntarily reported vulnerabilities and assisted us in improving our cybersecurity.

Internal process

  • Acknowledgement within 3 business days
  • Initial assessment within 10 business days
  • Target resolution for critical issues: within 90 days of initial report
  • Timely notification to authorities and partners as required by EU law

Your Safe Harbor

RTX will not pursue legal action against individuals who:

  • Act in good faith and follow this policy
  • Protect user, employee, and customer privacy
  • Avoid service disruption
  • Do not damage or misuse systems or data

Public Disclosure

Please refrain from public disclosure until RTX has completed remediation or agreed on a coordinated disclosure timeline.

Rewards

RTX does not currently operate a bug bounty program. However, valid contributions may be publicly acknowledged unless anonymity is requested.

Legal

Throughout the vulnerability disclosure process, you are expected to:

  • Comply with all applicable laws and regulations
  • Limit testing to what is necessary for validation
  • Avoid disrupting RTX services
  • Avoid intrusive or high-intensive scanning tools
  • Protect privacy and safety of individuals
  • Anonymize sensitive data
  • Avoid accessing, modifying, or deleting unnecessary data
  • Securely delete any collected data after use

This policy does not constitute a waiver of any rights or create obligations beyond those explicitly stated. RTX reserves the right to take legal action in cases of non-compliance.

Advisory Notices

RTX publishes security advisory notices in alignment with industry standards, including RED-DA and CRA requirements, to ensure transparency and support risk assessment for customers.

Downloadable product files will appear here, when relevant.

 

You can also subscribe to advisory notices here.

Important Dates

CRA

Date

Description

December 10, 2024

CRA came into effect. The Cyber Resilience Act (CRA) became part of the EU legal framework.

September 11, 2026

All manufacturers of products with digital elements are required to report vulnerabilities and security incidents contained in their products.

December 11, 2027

CRA becomes fully enforceable; all requirements must be met by manufacturers of products with digital elements.

NIS2

Date

Description

January 16, 2023

NIS2 Directive officially entered into force, starting the timeline for member state transposition.

October 17, 2024

Deadline for EU Member States to adopt and publish laws complying with NIS2

October 18, 2024

National laws based on NIS2 begin to apply, with organizations required to comply.

April 17, 2025

Deadline for Member States to establish lists of "essential" and "important" entities, including those providing domain name registration services.

October 17, 2027

Deadline for the Commission to report on the functioning of the NIS2 Directive.