External Coordinated Vulnerability Disclosure Policy
Last Revised: September 3, 2026
Our commitment
Emerson is committed to building secure, resilient products and to engaging constructively with customers, partners, and the security research community. We investigate credible vulnerability reports, remediate issues in a timely and risk-based manner, and communicate clearly so users can take appropriate action. We encourage those who report discovered vulnerabilities to us to do so under responsible and coordinated disclosure in order to avoid unnecessary risk for the critical industries we serve. This policy complements our internal vulnerability management and incident response processes and supports our regulatory obligations.
Scope
This policy applies to security vulnerabilities discovered in Emerson's:
- Hardware products, including industrial controllers, sensors, actuators, analyzers, transmitters, valves, and other field device
- Embedded systems and firmware operating on Emerson products
- Software products, including on-premises applications, configuration tools, and device management platforms
- Cloud services and web applications that are part of or directly support Emerson product offerings
The following are generally outside the scope of this policy:
- Social engineering, physical attacks, or non-security bugs
- Denial-of-service testing and other production system testing that risks service degradation or other harm
- Findings in products or services not owned or maintained by Emerson (we will help route where feasible)
If you are unsure whether your report is in scope under this policy, contact us and we will route your submission appropriately.
How to report a potential vulnerability
If you believe you have identified a vulnerability, it is important that you provide enough detail to enable us to identify the relevant product and to validate and triage.
Reporting Channel
When submitting a vulnerability report, please provide:
- Product name, version/build (include any relevant configuration details and environmental details, such as network topology, operating system, etc.)
- Your contact details- see our Privacy Notice for additional details regarding our processing of your personal information
- General description of your finding(s)
Once a secure channel is established, be prepared to submit the following additional information
- Technical description and reproduction steps (screenshots or writeups)
- Any logs or network traces (avoid including personal or confidential data)
If you are a customer or key stakeholder (e.g., regulator, or cyber security organisation such as ENISA) please also indicate:
- The deployment context for the Product – i.e., in what aspect of your network and/or infrastructure is the Product deployed;
- Whether the Product is used to support safety of life or critical infrastructure or services;
- Whether there is a risk to life or risk of systemic failure as a consequence of the vulnerability;
- Whether you are a NIS2 or similarly regulated entity.
What you can expect from us
We aim to follow a consistent, risk-based process aligned with our internal vulnerability management policy:
- Acknowledgement: We typically acknowledge receipt within 2 business days and should provide a tracking reference number with the acknowledgement.
- Assessment: We validate and classify the issue using recognised severity methods and our confidential threat modelling and which considers real-world exploitability and safety impact. We may request more information from you during our assessment- failure to respond promptly may result in closure of the case.
- Remediation: When determined necessary, we develop a fix or effective mitigation and determine update or advisory plans (including out-of-cycle releases for serious issues). Please note: the time required for handling may be impacted by multiple factors, including the criticality and complexity of the vulnerability.
- Coordination: We coordinate disclosure timing with you where possible, balancing user protection, disclosure embargo requirements, and transparency.
- Status Updates: To the extent possible, we provide status updates at key milestones (validation, fix availability, advisory publication).
- Credit: With your consent and in accordance with this policy, we may recognise your contribution in any public advisory.
Investigating vulnerabilities and responsible reporting
Emerson supports good-faith security research conducted in a lawful, responsible manner. To protect customers and operations, the following conditions apply to any investigation and disclosure activity:
- Do not use Emerson infrastructure for testing. Emerson does not authorise proactive testing against its production services, networks, or equipment. Testing must be limited to products or environments you own or are expressly authorised to test (e.g., your licensed instance, a vendor-provided sandbox). Unauthorised access or interference may violate applicable laws, including the US Computer Fraud and Abuse Act. Emerson reserves all rights to take appropriate action in response to unlawful activity.
- Avoid harmful techniques. Do not attempt denial-of-service, brute force, social engineering, physical intrusion or tampering, data exfiltration, or actions that could degrade safety or service continuity. Do not test on live production or operational systems. Use test accounts and minimal data; do not access personal or confidential information.
- Coordinate publication (embargo). If you believe you have identified a vulnerability, contact us first in accordance with the “How to report a potential vulnerability” section above. Please allow a reasonable remediation window before any public disclosure. For safety-critical or widely deployed issues, we may request a longer embargo to protect users. Emerson may engage third-party coordinators (e.g., CISA, ENISA) when a vulnerability affects multiple vendors or critical infrastructure sectors.
- Media and public statements. Journalists, analysts, and other notifiers should not publish technical details of suspected vulnerabilities until Emerson has confirmed the issue and either released a fix/effective mitigation or agreed a coordinated disclosure date. Please contact EmersonPR@fleishman.com to coordinate. Premature publication can increase risk to users and may require urgent advisories that disrupt customer operations.
- Attribution and updates. Once a fix or effective mitigation is available, Emerson will publish an advisory and may, with your consent, acknowledge your contribution. We reserve the right to withhold acknowledgement if any researcher does not adhere to this coordinated disclosure policy.
Bug bounty and unauthorised testing
Emerson does not operate a bug bounty program and does not offer financial rewards or incentives for proactive testing or vulnerability searching against its products, services, or infrastructure. Unauthorised access, interference, or testing may constitute a violation of applicable laws, including the US Computer Fraud and Abuse Act. Emerson reserves all rights to take appropriate action in response to unlawful activity.
Customer notifications and security advisories
When a confirmed vulnerability requires action or broad awareness:
- Our Trust Center provides a centralized location for security advisories and links to the relevant brand advisory pages, where we publish details on affected versions, vulnerability descriptions, CVSS scores and potential impacts, remediation steps (including mitigations, patches, or updates), and acknowledgments where applicable. Customers can subscribe for updates.
- For time-critical cases, we may send ad-hoc notifications to impacted customers with immediate mitigations or remediation steps.
- Where a third-party component is implicated, we may issue interim guidance while coordinating with the supplier.
Regulatory coordination
Where required by law (for example, in the EU under the Cyber Resilience Act), we will notify the competent authorities or CSIRTs. We may also make secondary notifications required under other frameworks (e.g., NIS2, GDPR). These steps follow our internal legal and compliance processes and do not delay actions needed to protect users.
Safe-harbour note
We value good-faith research. If you follow this policy and applicable laws, avoid data access/exfiltration, and do not disrupt services, we will not initiate legal action solely on the basis of your responsible security testing and reporting. This statement does not waive any rights we may have in other circumstances.
Contact and updates
Emerson reserves the right to update or modify this policy at any time. Material changes will be reflected in the version number and effective date below.
Continued submission of vulnerability reports after a policy update constitutes acceptance of the updated terms.