MENU
FJ | FJD
FJ | FJD
-
- All Pipettes, Dispensers & Automated Liquid Handlers
- Mechanical Pipettes
- Electronic Pipettes
- Multi-Channel Pipettes
- Positive Displacement Pipettes & Dispensers
- Bottle-Top Dispensers
- Pipette Controllers
- Dispenser & Pipette Accessories
- Automated Pipetting
- Automation Consumables
- Automation Accessories
- Liquid Handler & Pipette Services
Sorry, we couldn't find anything on our website containing your search term.
You are about to leave this site.
Please be aware that your current cart is not saved yet and cannot be restored on the new site nor when you come back. If you want to save your cart please login in into your account.
Sorry, we couldn't find anything on our website containing your search term.
- Home
- Company & Careers
- Legal
- Cybersecurity
Cybersecurity
We are committed to the security of our products, solutions, services, and IT infrastructure, and we take a holistic approach to this. To address reported vulnerabilities in our product portfolio and IT infrastructure, we have established a mandatory process for Coordinated Vulnerability Disclosure (CVD). Eppendorf’s central Security Incident Response Team (SIRT) is responsible for this.
The basis for this is the Cyber Resilience Act (Regulation (EU) 2024/2847). Our process is based on the BSI Technical Guideline TR-03183-3 as well as EN ISO/IEC 29147 and EN ISO/IEC 30111.
We cooperate in good faith with individuals who report vulnerabilities through the channels described under “Contact.” We accept reports regarding currently listed products as well as Eppendorf’s IT infrastructure. We do not require a non-disclosure agreement (NDA) for the submission of reports; we respect anonymous reports upon request. We do not intend to take legal action against individuals who:
1. test systems as part of a responsible investigation without harming third parties,
2. test products without affecting customers,
3. comply with applicable law,
4. engage in coordinated disclosure—that is, do not publish details before the expiration of a mutually agreed-upon period,
5. and avoid compromising the security or privacy of third parties.
Our process consists of the following four steps:
To report a vulnerability in an Eppendorf product, solution, or infrastructure component, please use the methods described under “Contact” or the reporting form on this page. You will typically receive an initial response within 5 business days (based on Hamburg, Germany). If possible, please provide the following:
1. A description of the vulnerability, including proof-of-concept or network capture (if available)
2. The affected product, solution, or infrastructure component, including model and firmware/version (if available)
3. Whether the vulnerability is already publicly known
Anyone is welcome to report discovered vulnerabilities—regardless of service contracts or the product lifecycle. We take the interests of the reporter into account (anonymity is available upon request) and address every vulnerability that, in our reasonable judgment, affects Eppendorf products, solutions, or infrastructure components.
We investigate and reproduce the reported vulnerability. If necessary, we request additional information from the reporter.
Internal resolution is carried out in collaboration with the relevant development and operations teams. National and government CSIRTs/CERTs may be informed of a vulnerability in advance. During this time, we maintain contact with the reporter and provide updates on the current status.
Following a successful analysis, appropriate fixes are developed—if necessary—and prepared for distribution. Confirmed vulnerabilities are generally disclosed within 90 days of confirmation, in coordination with the national CSIRT or ENISA, typically via a security advisory. A security advisory usually includes:
1. A description of the vulnerability with a CVE reference and CVSS score
2. Affected products and software/hardware versions
3. Information on countermeasures and workarounds
4. Source of available fixes
If you have questions regarding the security of our products and infrastructure or wish to report potential vulnerabilities, you can reach us as follows. We accept messages in German and English; encrypted communication is preferred. You will receive an initial response within 5 business days.
Email: Security@eppendorf.com
PGP Public Key: https://eppendorf.com/.well-known/pgp-key.asc
security.txt: www.eppendorf.com/.well-known/security.txt
Languages: German, English
Version
V1.0 (September 1, 2026): Release
The basis for this is the Cyber Resilience Act (Regulation (EU) 2024/2847). Our process is based on the BSI Technical Guideline TR-03183-3 as well as EN ISO/IEC 29147 and EN ISO/IEC 30111.
We cooperate in good faith with individuals who report vulnerabilities through the channels described under “Contact.” We accept reports regarding currently listed products as well as Eppendorf’s IT infrastructure. We do not require a non-disclosure agreement (NDA) for the submission of reports; we respect anonymous reports upon request. We do not intend to take legal action against individuals who:
1. test systems as part of a responsible investigation without harming third parties,
2. test products without affecting customers,
3. comply with applicable law,
4. engage in coordinated disclosure—that is, do not publish details before the expiration of a mutually agreed-upon period,
5. and avoid compromising the security or privacy of third parties.
Process Overview
Our process consists of the following four steps:
1. Reporting
To report a vulnerability in an Eppendorf product, solution, or infrastructure component, please use the methods described under “Contact” or the reporting form on this page. You will typically receive an initial response within 5 business days (based on Hamburg, Germany). If possible, please provide the following:
1. A description of the vulnerability, including proof-of-concept or network capture (if available)
2. The affected product, solution, or infrastructure component, including model and firmware/version (if available)
3. Whether the vulnerability is already publicly known
Anyone is welcome to report discovered vulnerabilities—regardless of service contracts or the product lifecycle. We take the interests of the reporter into account (anonymity is available upon request) and address every vulnerability that, in our reasonable judgment, affects Eppendorf products, solutions, or infrastructure components.
2. Analysis
We investigate and reproduce the reported vulnerability. If necessary, we request additional information from the reporter.
3. Resolution
Internal resolution is carried out in collaboration with the relevant development and operations teams. National and government CSIRTs/CERTs may be informed of a vulnerability in advance. During this time, we maintain contact with the reporter and provide updates on the current status.
4. Disclosure
Following a successful analysis, appropriate fixes are developed—if necessary—and prepared for distribution. Confirmed vulnerabilities are generally disclosed within 90 days of confirmation, in coordination with the national CSIRT or ENISA, typically via a security advisory. A security advisory usually includes:
1. A description of the vulnerability with a CVE reference and CVSS score
2. Affected products and software/hardware versions
3. Information on countermeasures and workarounds
4. Source of available fixes
Contact – Eppendorf SIRT
If you have questions regarding the security of our products and infrastructure or wish to report potential vulnerabilities, you can reach us as follows. We accept messages in German and English; encrypted communication is preferred. You will receive an initial response within 5 business days.
Email: Security@eppendorf.com
PGP Public Key: https://eppendorf.com/.well-known/pgp-key.asc
security.txt: www.eppendorf.com/.well-known/security.txt
Languages: German, English
Version
V1.0 (September 1, 2026): Release
Read more