Skip to content

Cyber Resilience Act (CRA)

Report an incident or learn about our commitment to CRA compliance.

For more than four decades, Hatteland Technology has been committed to manufacturing the toughest, most reliable IT hardware possible. Cybersecurity is fundamental to our products, as demonstrated by our compliance with a long list of industry standards, including IACS UR E27, ISO 9001:2015, ISO 27001:2023, and more. Our key focus – keeping our customers safe and operative – fully aligns with our obligations under the Cyber Resilience Act (CRA), and we are prepared to meet them as they come into effect.

Our CRA commitment

As a manufacturer and distributor of products used in safety-critical systems, Hatteland Technology adheres to strict cybersecurity principles both in production and through the life-cycle of our products. This corresponds with key obligations in the Cyber Resiliency Act (CRA), including Secure by Design, Vulnerability Handling, Security Updates, and Software Bill of Materials (SBOM). Please visit the official CRA explainer for a complete overview of requirements and obligations.

Hatteland Technology will comply with the:

  • CRA vulnerability reporting requirements effective September 11, 2026

  • CRA product requirements effective December 11, 2027

Report Exploited Vulnerability or Security Incident

Hatteland Technology is required to report actively exploited vulnerabilities contained in our products and severe incidents having an impact on the security of our products in accordance with Article 14 of the Cyber Resilience Act (CRA).

If you or your organization become aware of an actively exploited vulnerability in a Hatteland Technology product, or a security incident that you reasonably suspect was caused by or has affected the security of a Hatteland Technology product, please report it in as much detail as possible to our cybersecurity team.

Artboard 13

What is the Cyber Resilience Act (CRA)?

"The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first EU-wide law to set mandatory cybersecurity requirements for products with digital elements; hardware and software; across their entire lifecycle. It shifts responsibility for security onto the organisations that place these products on the market, rather than leaving it to users."

– Excerpt from the official EU Cyber Resilience Act (CRA) website.

Our Cybersecurity practices

Per Annex I of CRA, the essential cybersecurity requirements fall into two categories:

• Security properties the product must have
• Processes the manufacturer must run

Hatteland Technology meets the CRA requirements through the following cybersecurity framework:

1
Secure by Design
2
Vulnerability Reporting
3
Security Updates
4
User Transparency

Get in touch

For questions related to the Cyber Resilience Act, or to report an incident, please contact HT PSIRT (Product Security Incident response team):

About Hatteland Technology

Hatteland Technology provides tactical IT hardware you can rely on in the harshest of environments. Our solutions comprise specialised monitors, panel computers, client computers & servers, network switches, and CCTV cameras. 

The majority of the 200 people who make up Hatteland Technology live and work in Norway, Sweden or Finland. We also have a strong commercial presence in Germany, Italy, and the US.

Find out more about us here