OMRON will strive to supply secure products and services for customer’s safety and security.

Product security policy

OMRON group conducts product security activities to implement security measures against cyberattacks.
Please click here for the latest information.

Vulnerability Disclosure Policy

OMRON collects information on security vulnerabilities affecting its products and services from a wide range of sources and addresses such information appropriately to help ensure the safety and security of its customers. Please click here for the latest information.

Reporting a vulnerability

OMRON accepts information on vulnerabilities related to our products.
Please click here to submit your information.

Vulnerability status of Factory Automation products

Please click here for the latest information.

Practice of Regulatory Compliance

European Union Cyber Resilience Act

The European Union Cyber Resilience Act (EU Cyber Resilience Act, EU‑CRA) is a regulation that establishes common cybersecurity requirements for digital products with communication capabilities placed on the EU market.
This publication provides an overview of the regulation and related standards, as well as an introduction to Omron’s initiatives in this area.

Practice of Security Development Lifecycle

Certification for the IEC 62443-4-1

Controller Division, Product Business Division HQ. of its Industrial Automation Company obtained third-party certification for the IEC 62443-4-1 international standard, which defines process and organizational requirements for the development of secure control components to be used in industrial automation and control systems.

Certification for the GB40050-2021

Some PLCs (Programmable Logic Controllers) are now required to comply with the mandatory national standard GB40050-2021, based on the China Cybersecurity Law.
The relevant laws and standards, as well as the certification status of OMRON PLCs, are outlined here.

Supply Chain Security Risk Management

OMRON is committed to ensuring security across the entire supply chain supporting the delivery of its products and services. We identify cyber risks at every stage of the supply chain—including procurement, manufacturing, and maintenance—and work to prevent incidents and mitigate their impact. Strengthening supply chain security depends on close collaboration with contractors and suppliers, and we continuously enhance these partnerships.

Handling of the Software Bills of Materials (SBOMs)

Provision of SBOMs to Customers

  • ・OMRON does not make SBOMs publicly available or provide them unconditionally.
  • ・However, if a customer requires an SBOM for product security management purposes, OMRON will provide information in OMRON’s prescribed format. Such provision is subject to OMRON’s confirmation that there are reasonable grounds for the request and to the prior execution of an appropriate agreement governing the disclosure. Please contact OMRON through the inquiry page below.

https://www.ia.omron.com/global_network/

Compliance with the Requirements of the EU Cyber Resilience Act (Regulation (EU) 2024/2847)

  • ・OMRON places a strong emphasis on supply chain security for control equipment products and creates and maintains SBOMs that include at least the top-level dependencies.
  • ・Upon request from a market surveillance authority, conformity assessment body, or other relevant body pursuant to applicable laws and regulations, OMRON will provide an SBOM where necessary.

Security Guideline for Factory Automation products

Security Guideline which contains information about our security approach for our Factory Automation products and some recommendations on the use of the products is available.

Activity Achievements

October 2024:
Authorized as a CVE Numbering Authority for security vulnerabilities. Please click here for the latest information.
July 2026:
OMRON’s Product Security Incident Response Team (OMRON PSIRT) has received a Letter of Appreciation from the Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) in recognition of our continued efforts to enhance product security.