Cyber Resilience Act statement
Regulation (EU) 2024/2847 sets cybersecurity requirements for products with digital elements placed on the EU market. Our control software and instrument firmware are in scope, which makes GDS a manufacturer under the Regulation. This is how we are approaching it.
Which of our products are in scope
The Regulation covers products with digital elements — software and hardware whose intended purpose includes a data connection. That includes, but is not limited to:
- Control, acquisition and analysis software — GDSLAB, GDSBES and our other control and analysis applications, with their associated data and results components, as standalone software products
- Instrument firmware — pressure and volume controllers, data acquisition modules, load frames, and instrument controllers
- Complete testing systems — apparatus supplied with control software and firmware as an integrated product
Passive components with no digital elements — cells, membranes, porous discs, tubing, and transducers without embedded processing — are not products with digital elements in their own right, though they may form part of a system that is.
Product classification
We do not consider our products to be important or critical products under Annex III or Annex IV of the Regulation. Annex III lists specific categories — identity management, browsers, password managers, VPNs, operating systems, routers, network interfaces, firewalls, hypervisors, smart home products, connected toys and processors with security-related functionality among them — and our products match none of them. Annex IV covers security boxes, smart meter gateways and smartcards. On that basis our products fall in the default category, where conformity is self-assessed. The microcontrollers in our instrument controllers perform control functions rather than security ones, so the entries covering processors with security-related functionality do not catch them either.
Timeline and where we are
| Date | Obligation | Our position |
|---|---|---|
| 10 Dec 2024 | Regulation entered into force | Noted |
| 11 Jun 2026 | Chapter IV applied — notification of conformity assessment bodies | No GDS action required |
| 11 Sep 2026 | Article 14 reporting of actively exploited vulnerabilities and severe incidents begins | Route being confirmed |
| 11 Dec 2027 | Full essential requirements — Annex I, conformity assessment, CE marking, technical documentation | Planned |
Products already in the field
Those dates apply to products placed on the market from 11 December 2027. Under Article 69, a product placed on the market before then falls under the Regulation only if it is substantially modified after that date — so an instrument already in your laboratory does not retrospectively acquire a cybersecurity CE marking, a declaration of conformity or a published SBOM.
Reporting is the exception. The Article 14 obligations below apply to all in-scope products already on the market, so from 11 September 2026 an actively exploited vulnerability in an instrument we shipped years ago is reportable in the same way as one in a product sold tomorrow. What we will actually fix is governed by our support periods, which run independently of these dates. How far the same question reaches back into our supply chain is set out under supplier security.
Article 14 reporting
From 11 September 2026, where we become aware of a vulnerability in one of our products that is being actively exploited, or of a severe incident affecting the security of one of our products, we must report it to ENISA and to our designated national CSIRT through the ENISA single reporting platform:
| Deadline | Submission |
|---|---|
| Within 24 hours | Early warning that an actively exploited vulnerability or severe incident exists |
| Within 72 hours | Vulnerability notification or incident notification with technical detail and any corrective action taken |
| Within 14 days | Final report for an actively exploited vulnerability, once a corrective measure is available |
Alongside the regulatory report we will notify affected users of the product without undue delay, and where appropriate we will publish an advisory with the mitigation or corrective measures available.
We are completing these arrangements. Reports reach us at security@gdsinstruments.com, and the clock runs from the moment we become aware. Which entity files the report and to which national CSIRT is being confirmed with our EU authorised representative; registration for the ENISA single reporting platform follows from that.
Help us meet the 24-hour clock
If you see signs that a vulnerability in a GDS product is being exploited in your laboratory, tell us immediately at security@gdsinstruments.com and say so in the subject line. Our reporting deadline runs from the moment we become aware, so early notice from you directly affects whether we can comply.
Essential requirements
Annex I of the Regulation sets out the essential cybersecurity requirements in two parts. Part I concerns the security properties of the product itself; Part II concerns vulnerability handling. Our public commitments map to them as follows:
| Requirement | Where we address it |
|---|---|
| Secure default configuration; minimised attack surface | Secure development |
| Protection of data integrity and confidentiality | Secure development |
| Security update mechanism and secure distribution | Secure development |
| Identify and document components; maintain an SBOM | Software transparency |
| Address and remediate vulnerabilities without delay | Disclosure policy |
| Regular security testing and review | Secure development |
| Publicly disclose fixed vulnerabilities | Advisories |
| Coordinated vulnerability disclosure policy | Disclosure policy |
| Contact address for reporting vulnerabilities | Disclosure policy, security.txt |
| Security updates disseminated without delay, free of charge | Support periods |
| Support period determined and published | Support periods |
Requirements that produce no public artefact — our internal risk assessments, test records and technical documentation — are maintained and made available to competent authorities on request rather than published here.
Conformity assessment and CE marking
From 11 December 2027, products with digital elements placed on the EU market must carry the CE marking in respect of their cybersecurity conformity, supported by an EU declaration of conformity and technical documentation.
Our approach: internal self-assessment against Annex I, supported by technical documentation and the EU declaration of conformity kept for ten years after the product is placed on the market or for its support period, whichever is longer, with the declaration supplied with the product and available on request.
Where a harmonised standard is published that covers our product category, we intend to use it as the route to presumption of conformity.
Our authorised representative in the EU
GDS is established in the United Kingdom, so the products we place on the EU market reach it from outside the Union. Our authorised representative in the Union is the Dublin entity of Judges Scientific plc, which holds the technical documentation and acts as the point of contact for market surveillance authorities. Ask us and we will give you its registered name and address.
Information supplied with our products
Annex II requires certain information to be supplied to the user with the product. For GDS products that means the user instructions will state the manufacturer's identity and contact point, the vulnerability reporting address, the product's intended purpose and known limitations, the support period end date, and where to obtain security updates. Those details are being added to our documentation ahead of December 2027 and will point to this site.
What about the UK?
The Cyber Resilience Act is EU law. As a UK manufacturer exporting into the EU, we are subject to it in respect of products we place on the EU market.
The UK has no equivalent. The Product Security and Telecommunications Infrastructure Act 2022 covers consumer connectable products, which laboratory instruments are not, and the Cyber Security and Resilience Bill introduced in November 2025 governs operators of essential services rather than products.
Because we would rather run one process than several, our practice is to apply CRA-level vulnerability handling to all our products regardless of the market they are sold into.
This page is not legal advice
It describes our own compliance position as we understand it. If you need to establish your obligations as a distributor, importer or operator, take your own advice. If you believe we have got something wrong, please tell us — we would rather correct it.