OMRON will strive to supply secure products and services for customer’s safety and security.
Product security policy
OMRON group conducts product security activities to implement security measures against cyberattacks.
Please click here for the latest information.
Vulnerability Disclosure Policy
OMRON collects information on security vulnerabilities affecting its products and services from a wide range of sources and addresses such information appropriately to help ensure the safety and security of its customers. Please click here for the latest information.
Reporting a vulnerability
OMRON accepts information on vulnerabilities related to our products.
Please click here to submit your information.
Vulnerability status of Factory Automation products
Please click here for the latest information.
Practice of Regulatory Compliance
European Union Cyber Resilience Act
The European Union Cyber Resilience Act (EU Cyber Resilience Act, EU‑CRA) is a regulation that establishes common cybersecurity requirements for digital products with communication capabilities placed on the EU market.
This publication provides an overview of the regulation and related standards, as well as an introduction to Omron’s initiatives in this area.
- OMRON White Paper for Product Security:“Security Risks in Manufacturing Sites and Key Points You Should Know” ‑European Union Cyber Resilience Act
Practice of Security Development Lifecycle
Certification for the IEC 62443-4-1
Controller Division, Product Business Division HQ. of its Industrial Automation Company obtained third-party certification for the IEC 62443-4-1 international standard, which defines process and organizational requirements for the development of secure control components to be used in industrial automation and control systems.
Certification for the GB40050-2021
Some PLCs (Programmable Logic Controllers) are now required to comply with the mandatory national standard GB40050-2021, based on the China Cybersecurity Law.
The relevant laws and standards, as well as the certification status of OMRON PLCs, are outlined here.
- OMRON White Paper for Product Security:Security Risks in Manufacturing Environments and Key Points to Know.- China Security Standards Edition
- OMRON White Paper for Product Security:OMRON FA System Devices Certified under the China Cybersecurity Law
Supply Chain Security Risk Management
OMRON is committed to ensuring security across the entire supply chain supporting the delivery of its products and services. We identify cyber risks at every stage of the supply chain—including procurement, manufacturing, and maintenance—and work to prevent incidents and mitigate their impact. Strengthening supply chain security depends on close collaboration with contractors and suppliers, and we continuously enhance these partnerships.
Handling of the Software Bills of Materials (SBOMs)
Provision of SBOMs to Customers
- ・OMRON does not make SBOMs publicly available or provide them unconditionally.
- ・However, if a customer requires an SBOM for product security management purposes, OMRON will provide information in OMRON’s prescribed format. Such provision is subject to OMRON’s confirmation that there are reasonable grounds for the request and to the prior execution of an appropriate agreement governing the disclosure. Please contact OMRON through the inquiry page below.
Compliance with the Requirements of the EU Cyber Resilience Act (Regulation (EU) 2024/2847)
- ・OMRON places a strong emphasis on supply chain security for control equipment products and creates and maintains SBOMs that include at least the top-level dependencies.
- ・Upon request from a market surveillance authority, conformity assessment body, or other relevant body pursuant to applicable laws and regulations, OMRON will provide an SBOM where necessary.
Security Guideline for Factory Automation products
Security Guideline which contains information about our security approach for our Factory Automation products and some recommendations on the use of the products is available.
Activity Achievements
- October 2024:
- Authorized as a CVE Numbering Authority for security vulnerabilities. Please click here for the latest information.
- July 2026:
- OMRON’s Product Security Incident Response Team (OMRON PSIRT) has received a Letter of Appreciation from the Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) in recognition of our continued efforts to enhance product security.