Reference v2

Preliminary version — not yet issued. This declaration is complete in substance but not yet signed: the EU declaration of conformity behind it is held as a draft while a few security decisions are still open. Please do not yet use it as evidence towards third parties. You will receive the signed version as soon as it exists — write to security@brinkhaus-gmbh.de.

Supplier declaration on cyber resilience

ProductopenXEdge — variant brinkhaus
Legal basisRegulation (EU) 2024/2847 (Cyber Resilience Act)

What we declare

Brinkhaus GmbH declares as the manufacturer that the openXEdge product supplied by us conforms to the relevant requirements of Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements.

The product is a default-category product under the regulation; it is listed neither in Annex III nor in Annex IV as an important or critical product. Conformity assessment is therefore lawfully carried out by ourselves (Module A, internal control). No notified body is involved.

This declaration applies from the firmware version named in the corresponding EU declaration of conformity (document KE-openXEdge-brinkhaus) and to all subsequent versions of that variant.

Manufacturer

ManufacturerBrinkhaus GmbH
AddressSchneekoppenweg 6, 30916 Isernhagen, Germany
Commercial registerLocal Court of Hanover, HRB 219360
VAT IDDE327832140
Managing DirectorDr. Jan Brinkhaus
Security contactsecurity@brinkhaus-gmbh.de

The manufacturer is established in the Union; no authorised representative has been appointed.

Support period

Brinkhaus provides security updates for the openXEdge firmware and the container stack shipped with it through the signed update channel for five years from the delivery of the individual device.

The period starts with the delivery of the individual device and runs per device; a replacement device starts a period of its own.

It applies to every firmware release of this device.

What this means for your own obligations

You may use this declaration for your supplier records. For the cyber resilience of the supplied product:

RequirementHow we meet it
Security updatesThrough a signed update channel; every update is cryptographically verified before installation, and a failed installation returns to the previous state by itself
Vulnerability reportingPublic reporting address security@brinkhaus-gmbh.de; good-faith reporters have no legal action to fear
Software bill of materials (SBOM)Maintained for every released version in CycloneDX format and provided to you on request within ten working days
Technical documentationMaintained under Annex VII and presented to market surveillance authorities on reasoned request
User informationIn this documentation, in particular the Security and support page

Conditions of operation

This declaration assumes the device is operated as intended:

  1. in a protected company or plant network, not reachable from the internet and with no port forwarding to the device;
  2. physically access-protected, for example in a locked cabinet;
  3. with the initial password changed and individual user accounts in use;
  4. on a current firmware version supplied by us.

If the device is operated outside these conditions, this declaration loses its basis. The details are on the Security and support page.

Further documents on request

On request to security@brinkhaus-gmbh.de you can obtain:

  • the full EU declaration of conformity under Annex V, with CE marking,
  • the software bill of materials (SBOM) for the firmware running on your device,
  • information on the technical documentation under Annex VII.

Signature

Signed for and on behalf of Brinkhaus GmbH:

Place 
Date 
NameDr. Jan Brinkhaus
FunctionManaging Director

Signature