This page allows customers and other stakeholders to report potential security vulnerabilities affecting Spirax Sarco products, software, firmware, connected solutions and associated digital services. Spirax Sarco is committed to supporting the security and resilience of its products throughout their lifecycle. We welcome the responsible reporting of potential cybersecurity vulnerabilities affecting Spirax Sarco products, software, firmware or associated digital services.
The Cyber Resilience Act (CRA) is European legislation intended to strengthen the cybersecurity of products with digital elements and improve the management of cybersecurity vulnerabilities throughout a product's lifecycle. We encourage responsible disclosure and welcome information that helps us assess, manage and, where appropriate, address potential product security concerns.
For available software, firmware updates and supporting resources for Spirax Sarco products, please visit our Software page.
If you believe you have identified a potential product security vulnerability, please submit a report using one of the following methods:
Email: productsecurity@uk.spiraxsarco.com
or
Complete the form opposite.
Please provide where available:
| Step: | Description: | |
| 1 | Receive | You submit: Your report through our approved reporting channel. We: Receive and record your submission. |
| 2 | Review | We: Review the information provided and carry out an initial validation. |
| 3 | Assess | We: Determine whether an Spirax Sarco product or service is affected and assess the potential severity and impact |
| 4 | Respond | We: Investigate the issue and identify appropriate mitigation or corrective action where required |
| 5 | Communicate | You can expect: Relevant updates or customer communication where appropriate. |
| 6 | Close | We: Record the outcome, retain relevant evidence and close the submission. |