Non-disclosure Reporting
This page describes RTX’s process for reporting and handling security vulnerabilities according to the Cybersecurity Resilience Act (CRA).
Non-disclosure Reporting
Introduction
The RTX PSIRT (Product Security Incident Response Team) is responsible for managing security issues, including vulnerabilities and incidents, affecting RTX products.
RTX is committed to proactively addressing potential security vulnerabilities. As part of this commitment, we provide a dedicated product security point of contact to ensure efficient handling, coordination, and resolution of reported issues.
Vulnerability Disclosure Policy
RTX publishes security advisories for affected products in alignment with CERT’s Coordinated Vulnerability Disclosure (CVD) framework. This approach ensures that vulnerabilities are responsibly managed, risks are mitigated, and users receive sufficient information to assess potential impacts on their systems.
Security advisories do not represent a comprehensive list of all reported incidents, as disclosures are coordinated and published in accordance with CVD principles.
RTX aims to comply with applicable regulations and legislation. To support this, a structured PSIRT reporting mechanism has been established to collect, evaluate, and act on vulnerability information submitted to RTX.
Policy Scope
Purpose & Scope
This policy defines the process for reporting vulnerabilities affecting RTX-branded systems, products, solutions, and services.
The following are out of scope and not covered by this policy:
- Vulnerabilities in products or services licensed to or managed by third parties
- Non-technical issues such as social engineering or manipulation
- Cybersecurity incidents or attacks, including Denial of Service (DoS) vulnerabilities
Step-by-step Process
Reporting a Vulnerability
If you believe you have identified a security vulnerability, please report it to RTX at: security@rtx.dk
Please ensure your report includes sufficient detail to allow validation and reproduction.
Required information:
- Hardware/software product name with any version or revision number in RTX
- Proof-of-concept code (if available)
- Detailed description of the vulnerability
- Detailed description of potential exploitation scenarios
- Date of discovery
- Method of discovery
- Reproduction steps to confirm the potential vulnerability
- Technical details (e.g., system configuration, logs, traces, exploit code, sample packet capture)
- Tools/software name/version used for validation
- Potential impact of the vulnerability
- References to any public disclosures (e.g., CVE, research papers)
- Common Vulnerability Scoring System (CVSS) V3 or V4 score (if available)
Your contact information:
- Name
- Organization/Company
- Department/Role
- Email Address
- Phone Number
Incomplete submissions may delay or prevent validation. All reports must be submitted in English.
Submission guidelines
When submitting a report:
- Attach screenshots as files (Word or PDF), rather than embedding them in the email body.
- Use a clear and non-sensitive subject line
- Include your public key for secure communication
Important Notice:
- This process applies only to RTX products. For other inquiries, please contact your RTX representative.
- Contact information is used solely for vulnerability handling. See RTX Privacy Policy https://www.rtx.dk/privacy-statement/).
- To protect our customers, we encourage you not to share the vulnerability with any other people or organization without prior coordination with the RTX PSIRT. You may be asked to delay disclosure until remediation is complete.
- Response times may vary depending on complexity.
Thank you for your cooperation.
Report a Vulnerability Here
What RTX does
Analysis
Upon receiving a report, RTX will investigate the potential vulnerability in accordance with internal procedures. We will keep you updated throughout the process and may request additional information to reproduce the vulnerability. If confirmed, a risk assessment will be conducted to determine its severity and potential impacts.
Handling
Validated vulnerabilities are addressed through a remediation plan prioritized according to the severity of the issue and the risk analysis.
Disclosure
Once resolved, RTX will disclose the vulnerability to relevant stakeholders. We aim to balance transparency with the need to give our partners sufficient time to implement necessary fixes. As such, the publication of advisories may be delayed to reduce potential risks.
RTX acknowledges contributors who have voluntarily reported vulnerabilities and assisted us in improving our cybersecurity.
Internal process
- Acknowledgement within 3 business days
- Initial assessment within 10 business days
- Target resolution for critical issues: within 90 days of initial report
- Timely notification to authorities and partners as required by EU law
Your Safe Harbor
RTX will not pursue legal action against individuals who:
- Act in good faith and follow this policy
- Protect user, employee, and customer privacy
- Avoid service disruption
- Do not damage or misuse systems or data
Public Disclosure
Please refrain from public disclosure until RTX has completed remediation or agreed on a coordinated disclosure timeline.
Rewards
RTX does not currently operate a bug bounty program. However, valid contributions may be publicly acknowledged unless anonymity is requested.
Legal
Throughout the vulnerability disclosure process, you are expected to:
- Comply with all applicable laws and regulations
- Limit testing to what is necessary for validation
- Avoid disrupting RTX services
- Avoid intrusive or high-intensive scanning tools
- Protect privacy and safety of individuals
- Anonymize sensitive data
- Avoid accessing, modifying, or deleting unnecessary data
- Securely delete any collected data after use
This policy does not constitute a waiver of any rights or create obligations beyond those explicitly stated. RTX reserves the right to take legal action in cases of non-compliance.
Advisory Notices
RTX publishes security advisory notices in alignment with industry standards, including RED-DA and CRA requirements, to ensure transparency and support risk assessment for customers.
Downloadable product files will appear here, when relevant.
You can also subscribe to advisory notices here.
Important Dates
CRA
|
Date |
Description |
|
December 10, 2024 |
CRA came into effect. The Cyber Resilience Act (CRA) became part of the EU legal framework. |
|
September 11, 2026 |
All manufacturers of products with digital elements are required to report vulnerabilities and security incidents contained in their products. |
|
December 11, 2027 |
CRA becomes fully enforceable; all requirements must be met by manufacturers of products with digital elements. |
NIS2
|
Date |
Description |
|
January 16, 2023 |
NIS2 Directive officially entered into force, starting the timeline for member state transposition. |
|
October 17, 2024 |
Deadline for EU Member States to adopt and publish laws complying with NIS2 |
|
October 18, 2024 |
National laws based on NIS2 begin to apply, with organizations required to comply. |
|
April 17, 2025 |
Deadline for Member States to establish lists of "essential" and "important" entities, including those providing domain name registration services. |
|
October 17, 2027 |
Deadline for the Commission to report on the functioning of the NIS2 Directive. |