Central Reporting Office under the Cyber Resilience Regulation
(Regulation (EU) 2024/2847)

IMATEQ ITALIA Srl
Strada Savonesa 12/16 CAP 15057
Interporto di Rivalta
Büros: Stabile 39 - Officina: Stabile 60
15057 Tortona - Fr. Rivalta Scrivia - AL

Go to the reporting form

Product Security
Reporting cybersecurity vulnerabilities and security incidents
The cybersecurity of our products is an essential part of product safety.
Under the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, binding requirements apply within the European Union regarding the cybersecurity of products containing digital elements.

These include, in particular, the systematic management of vulnerabilities and cybersecurity incidents, as well as corresponding reporting and handling processes.

The statutory CRA reporting obligations come into force on 11 September 2026.

IMATEQ Germany therefore provides a central reporting channel for product security.
Here, customers, operators, maintenance providers, suppliers, security experts and other individuals or organisations can report information regarding potential cybersecurity vulnerabilities or security incidents.

A report may relate to a locomotive or another product, as well as to individual digital components, subsystems, software or firmware used within it.

These may include, for example, vehicle control systems, control units, communication and radio systems, routers and network technology, diagnostic and remote access systems, or other digital components.

Vulnerabilities in a supplier’s components may also be relevant if these form part of a Vossloh Rolling Stock product.

Accordingly, the CRA documentation covers not only the vehicle as a whole, but also the digital products it contains and their software.

WHAT SHOULD BE REPORTED?
Please report in particular:

  • known or suspected cybersecurity vulnerabilities

  • potential or confirmed cyberattacks

  • unauthorised access to a product or a digital component

  • possible tampering with software, firmware, data or communications

  • unusual or unexpected behaviour of a digital system that may be security-related

  • Vulnerabilities in software, interfaces, network or communication components

  • Security issues relating to diagnostic, maintenance, update or remote access

  • other observations that may indicate a potential cybersecurity incident

It is also advisable to report an incident even if it has not yet been conclusively established whether a vulnerability or security incident actually exists.

The technical assessment is carried out by Vossloh Rolling Stock / Imateq.

WHAT INFORMATION DO WE NEED?
To enable us to assess the report as quickly as possible, please provide the following details, where known:

What has happened?
A full and specific description of the observation.

Which product is affected?
For example, the type of locomotive, rolling stock or other product from Vossloh Rolling Stock.

Which component or software is affected?
If known: system, device, software/firmware version or manufacturer/supplier.

When and where was the observation made?
Date, time, as well as the vehicle, location or operational situation.

What effects were observed?
For example, malfunction, unusual communication, data alteration, unauthorised access or system failure.

What further information is available?
If available: error messages, log files, screenshots or other technical information.

Who is reporting the incident?
Name, organisation and contact details for any queries.

WHAT HAPPENS AFTER THE REPORT IS SUBMITTED?
1. Receipt and assessment
Upon receipt, the report is recorded and technically assessed in accordance with the established Product Security and CRA process.

2. Enquiries
If further information is required, we will contact the person or organisation that submitted the report.

3. Action
Depending on the outcome of Vossloh Rolling Stock’s assessment, the necessary technical and organisational measures are initiated and, where necessary, affected suppliers, customers and relevant authorities are involved.

4. Feedback
You will then receive a reply.

8. Confidential treatment of the report
Vossloh Rolling Stock / Imateq treats incoming reports confidentially and uses the information provided solely to the extent necessary to investigate and deal with the matter reported.