Cyber Resilience Act statement

Regulation (EU) 2024/2847 sets cybersecurity requirements for products with digital elements placed on the EU market. Our control software and instrument firmware are in scope, which makes GDS a manufacturer under the Regulation. This is how we are approaching it.

Which of our products are in scope

The Regulation covers products with digital elements — software and hardware whose intended purpose includes a data connection. That includes, but is not limited to:

  • Control, acquisition and analysis software — GDSLAB, GDSBES and our other control and analysis applications, with their associated data and results components, as standalone software products
  • Instrument firmware — pressure and volume controllers, data acquisition modules, load frames, and instrument controllers
  • Complete testing systems — apparatus supplied with control software and firmware as an integrated product

Passive components with no digital elements — cells, membranes, porous discs, tubing, and transducers without embedded processing — are not products with digital elements in their own right, though they may form part of a system that is.

Product classification

We do not consider our products to be important or critical products under Annex III or Annex IV of the Regulation. Annex III lists specific categories — identity management, browsers, password managers, VPNs, operating systems, routers, network interfaces, firewalls, hypervisors, smart home products, connected toys and processors with security-related functionality among them — and our products match none of them. Annex IV covers security boxes, smart meter gateways and smartcards. On that basis our products fall in the default category, where conformity is self-assessed. The microcontrollers in our instrument controllers perform control functions rather than security ones, so the entries covering processors with security-related functionality do not catch them either.

Timeline and where we are

DateObligationOur position
10 Dec 2024 Regulation entered into force Noted
11 Jun 2026 Chapter IV applied — notification of conformity assessment bodies No GDS action required
11 Sep 2026 Article 14 reporting of actively exploited vulnerabilities and severe incidents begins Route being confirmed
11 Dec 2027 Full essential requirements — Annex I, conformity assessment, CE marking, technical documentation Planned

Products already in the field

Those dates apply to products placed on the market from 11 December 2027. Under Article 69, a product placed on the market before then falls under the Regulation only if it is substantially modified after that date — so an instrument already in your laboratory does not retrospectively acquire a cybersecurity CE marking, a declaration of conformity or a published SBOM.

Reporting is the exception. The Article 14 obligations below apply to all in-scope products already on the market, so from 11 September 2026 an actively exploited vulnerability in an instrument we shipped years ago is reportable in the same way as one in a product sold tomorrow. What we will actually fix is governed by our support periods, which run independently of these dates. How far the same question reaches back into our supply chain is set out under supplier security.

Article 14 reporting

From 11 September 2026, where we become aware of a vulnerability in one of our products that is being actively exploited, or of a severe incident affecting the security of one of our products, we must report it to ENISA and to our designated national CSIRT through the ENISA single reporting platform:

DeadlineSubmission
Within 24 hoursEarly warning that an actively exploited vulnerability or severe incident exists
Within 72 hoursVulnerability notification or incident notification with technical detail and any corrective action taken
Within 14 daysFinal report for an actively exploited vulnerability, once a corrective measure is available

Alongside the regulatory report we will notify affected users of the product without undue delay, and where appropriate we will publish an advisory with the mitigation or corrective measures available.

We are completing these arrangements. Reports reach us at security@gdsinstruments.com, and the clock runs from the moment we become aware. Which entity files the report and to which national CSIRT is being confirmed with our EU authorised representative; registration for the ENISA single reporting platform follows from that.

Help us meet the 24-hour clock

If you see signs that a vulnerability in a GDS product is being exploited in your laboratory, tell us immediately at security@gdsinstruments.com and say so in the subject line. Our reporting deadline runs from the moment we become aware, so early notice from you directly affects whether we can comply.

Essential requirements

Annex I of the Regulation sets out the essential cybersecurity requirements in two parts. Part I concerns the security properties of the product itself; Part II concerns vulnerability handling. Our public commitments map to them as follows:

RequirementWhere we address it
Secure default configuration; minimised attack surfaceSecure development
Protection of data integrity and confidentialitySecure development
Security update mechanism and secure distributionSecure development
Identify and document components; maintain an SBOMSoftware transparency
Address and remediate vulnerabilities without delayDisclosure policy
Regular security testing and reviewSecure development
Publicly disclose fixed vulnerabilitiesAdvisories
Coordinated vulnerability disclosure policyDisclosure policy
Contact address for reporting vulnerabilitiesDisclosure policy, security.txt
Security updates disseminated without delay, free of chargeSupport periods
Support period determined and publishedSupport periods

Requirements that produce no public artefact — our internal risk assessments, test records and technical documentation — are maintained and made available to competent authorities on request rather than published here.

Conformity assessment and CE marking

From 11 December 2027, products with digital elements placed on the EU market must carry the CE marking in respect of their cybersecurity conformity, supported by an EU declaration of conformity and technical documentation.

Our approach: internal self-assessment against Annex I, supported by technical documentation and the EU declaration of conformity kept for ten years after the product is placed on the market or for its support period, whichever is longer, with the declaration supplied with the product and available on request.

Where a harmonised standard is published that covers our product category, we intend to use it as the route to presumption of conformity.

Our authorised representative in the EU

GDS is established in the United Kingdom, so the products we place on the EU market reach it from outside the Union. Our authorised representative in the Union is the Dublin entity of Judges Scientific plc, which holds the technical documentation and acts as the point of contact for market surveillance authorities. Ask us and we will give you its registered name and address.

Information supplied with our products

Annex II requires certain information to be supplied to the user with the product. For GDS products that means the user instructions will state the manufacturer's identity and contact point, the vulnerability reporting address, the product's intended purpose and known limitations, the support period end date, and where to obtain security updates. Those details are being added to our documentation ahead of December 2027 and will point to this site.

What about the UK?

The Cyber Resilience Act is EU law. As a UK manufacturer exporting into the EU, we are subject to it in respect of products we place on the EU market.

The UK has no equivalent. The Product Security and Telecommunications Infrastructure Act 2022 covers consumer connectable products, which laboratory instruments are not, and the Cyber Security and Resilience Bill introduced in November 2025 governs operators of essential services rather than products.

Because we would rather run one process than several, our practice is to apply CRA-level vulnerability handling to all our products regardless of the market they are sold into.

This page is not legal advice

It describes our own compliance position as we understand it. If you need to establish your obligations as a distributor, importer or operator, take your own advice. If you believe we have got something wrong, please tell us — we would rather correct it.