1. Purpose
Mimaki Engineering Co., Ltd. (hereinafter referred to as “Mimaki”) recognizes ensuring the cybersecurity of our products as a critical responsibility.
This policy establishes a framework for customers, dealers, distributors, security researchers, and other stakeholders to appropriately report vulnerabilities related to our products, enabling timely analysis, assessment, and remediation.
2. Scope
This policy applies to the following products and services (for details, refer to the CRA-Covered Product List):
- Printers with network connectivity
- Software
- Cloud Services
- Firmware
- Other products containing digital elements
3. Vulnerability Reporting Channel
Please use the CRA Incident Assessment Checklist to evaluate the reported incident.
Then, please report the vulnerability information through one of the following channels:
For CRA-related incidents only:
- Email: cra-report@emea.mimaki.com
- Web Form: CRA Incident Assessment Report
4. Information to Include in Your Report
Please provide the following information whenever possible:
- Product name
- Model name
- Software and/or Firmware version
- Date and time the vulnerability was discovered
- Description of the vulnerability
- Steps to reproduce vulnerability
- Scope of Impact
- Evidence of exploitation
- Proposed Measures
5. Mimaki’s Response Policy
Mimaki will handle submitted reports according to the following process:
(1) Receipt Confirmation
A confirmation of receipt will be sent promptly after the report is received.
(2) Initial Assessment
We will evaluate the report to determine the existence of vulnerability.
(3) Risk Assessment
The following factors will be assessed:
- Impact on Confidentiality
- Impact on Integrity
- Impact on Availability
- Ease of Exploitation / Vulnerability to Attack
- Anticipated Customer Impact
(4) Countermeasures Implementation
We may implement one or more of the following measures where necessary:
- Software patches
- Firmware updates
- Workarounds or Mitigation Guidance
- Customer Notifications
- Additional measures can be proposed based on the nature of vulnerabilities
6. Public Disclosure
After the vulnerability has been remediated, Mimaki may disclose the following information, as appropriate:
- Vulnerability Summary
- CVE Identifier and/or CVSS Score
- Affected Products
- Scope of Impact
- Exploitability
- Countermeasure details
- Update Instructions
To protect customers, disclosure of vulnerability information prior to remediation may be restricted.
7. Response to Good-Faith Security Research
Mimaki will not pursue unnecessary legal action against researchers who report vulnerabilities in good faith and in accordance with this policy.
However, the following are prohibited:
- Acquisition of Customer Data
- Acquisition of Personal Information
- Unauthorized Access
- Service Disruption
- Destruction or Disruption of Systems
- Any other activities identified as prohibited acts at our discretion
8. CRA Reporting Response
If a critical vulnerability or evidence of active exploitation is identified in a product, Mimaki will fulfill its reporting obligations to the relevant EU authorities in accordance with the Cyber Resilience Act (CRA) and other applicable regulations.
Under the CRA, vulnerabilities that are actively exploited may require an initial notification within 24 hours, followed by more detailed reporting within 72 hours, as prescribed by the regulation.
