Printing: this page is set up for printing. Use your browser’s print function
(Ctrl+P); navigation and page furniture are hidden automatically. A signed
original is available from us on request.
Preliminary version — not yet issued. This declaration is complete in substance but not yet signed: the EU declaration of conformity behind it is held as a draft while a few security decisions are still open. Please do not yet use it as evidence towards third parties. You will receive the signed version as soon as it exists — write to security@brinkhaus-gmbh.de.
Supplier declaration on cyber resilience
| Product | openXEdge — variant brinkhaus |
| Legal basis | Regulation (EU) 2024/2847 (Cyber Resilience Act) |
What we declare
Brinkhaus GmbH declares as the manufacturer that the openXEdge product supplied by us conforms to the relevant requirements of Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements.
The product is a default-category product under the regulation; it is listed neither in Annex III nor in Annex IV as an important or critical product. Conformity assessment is therefore lawfully carried out by ourselves (Module A, internal control). No notified body is involved.
This declaration applies from the firmware version named in the corresponding EU declaration of conformity (document KE-openXEdge-brinkhaus) and to all subsequent versions of that variant.
Manufacturer
| Manufacturer | Brinkhaus GmbH |
| Address | Schneekoppenweg 6, 30916 Isernhagen, Germany |
| Commercial register | Local Court of Hanover, HRB 219360 |
| VAT ID | DE327832140 |
| Managing Director | Dr. Jan Brinkhaus |
| Security contact | security@brinkhaus-gmbh.de |
The manufacturer is established in the Union; no authorised representative has been appointed.
Support period
Brinkhaus provides security updates for the openXEdge firmware and the container stack shipped with it through the signed update channel for five years from the delivery of the individual device.
The period starts with the delivery of the individual device and runs per device; a replacement device starts a period of its own.
It applies to every firmware release of this device.
What this means for your own obligations
You may use this declaration for your supplier records. For the cyber resilience of the supplied product:
| Requirement | How we meet it |
|---|---|
| Security updates | Through a signed update channel; every update is cryptographically verified before installation, and a failed installation returns to the previous state by itself |
| Vulnerability reporting | Public reporting address security@brinkhaus-gmbh.de; good-faith reporters have no legal action to fear |
| Software bill of materials (SBOM) | Maintained for every released version in CycloneDX format and provided to you on request within ten working days |
| Technical documentation | Maintained under Annex VII and presented to market surveillance authorities on reasoned request |
| User information | In this documentation, in particular the Security and support page |
Conditions of operation
This declaration assumes the device is operated as intended:
- in a protected company or plant network, not reachable from the internet and with no port forwarding to the device;
- physically access-protected, for example in a locked cabinet;
- with the initial password changed and individual user accounts in use;
- on a current firmware version supplied by us.
If the device is operated outside these conditions, this declaration loses its basis. The details are on the Security and support page.
Further documents on request
On request to security@brinkhaus-gmbh.de you can obtain:
- the full EU declaration of conformity under Annex V, with CE marking,
- the software bill of materials (SBOM) for the firmware running on your device,
- information on the technical documentation under Annex VII.
Signature
Signed for and on behalf of Brinkhaus GmbH:
| Place | |
| Date | |
| Name | Dr. Jan Brinkhaus |
| Function | Managing Director |
Signature