1. Purpose

Mimaki Engineering Co., Ltd. (hereinafter referred to as “Mimaki”) recognizes ensuring the cybersecurity of our products as a critical responsibility.
This policy establishes a framework for customers, dealers, distributors, security researchers, and other stakeholders to appropriately report vulnerabilities related to our products, enabling timely analysis, assessment, and remediation.

2. Scope

This policy applies to the following products and services (for details, refer to the CRA-Covered Product List):

  • Printers with network connectivity
  • Software
  • Cloud Services
  • Firmware
  • Other products containing digital elements

3. Vulnerability Reporting Channel

Please use the CRA Incident Assessment Checklist to evaluate the reported incident.
Then, please report the vulnerability information through one of the following channels:

For CRA-related incidents only:

4. Information to Include in Your Report

Please provide the following information whenever possible:

  • Product name
  • Model name
  • Software and/or Firmware version
  • Date and time the vulnerability was discovered
  • Description of the vulnerability
  • Steps to reproduce vulnerability
  • Scope of Impact
  • Evidence of exploitation
  • Proposed Measures

5. Mimaki’s Response Policy

Mimaki will handle submitted reports according to the following process:

(1) Receipt Confirmation

A confirmation of receipt will be sent promptly after the report is received.

(2) Initial Assessment

We will evaluate the report to determine the existence of vulnerability.

(3) Risk Assessment

The following factors will be assessed:

  • Impact on Confidentiality
  • Impact on Integrity
  • Impact on Availability
  • Ease of Exploitation / Vulnerability to Attack
  • Anticipated Customer Impact

(4) Countermeasures Implementation

We may implement one or more of the following measures where necessary:

  • Software patches
  • Firmware updates
  • Workarounds or Mitigation Guidance
  • Customer Notifications
  • Additional measures can be proposed based on the nature of vulnerabilities

6. Public Disclosure

After the vulnerability has been remediated, Mimaki may disclose the following information, as appropriate:

  • Vulnerability Summary
  • CVE Identifier and/or CVSS Score
  • Affected Products
  • Scope of Impact
  • Exploitability
  • Countermeasure details
  • Update Instructions

To protect customers, disclosure of vulnerability information prior to remediation may be restricted.

7. Response to Good-Faith Security Research

Mimaki will not pursue unnecessary legal action against researchers who report vulnerabilities in good faith and in accordance with this policy.
However, the following are prohibited:

  • Acquisition of Customer Data
  • Acquisition of Personal Information
  • Unauthorized Access
  • Service Disruption
  • Destruction or Disruption of Systems
  • Any other activities identified as prohibited acts at our discretion

8. CRA Reporting Response

If a critical vulnerability or evidence of active exploitation is identified in a product, Mimaki will fulfill its reporting obligations to the relevant EU authorities in accordance with the Cyber Resilience Act (CRA) and other applicable regulations.

Under the CRA, vulnerabilities that are actively exploited may require an initial notification within 24 hours, followed by more detailed reporting within 72 hours, as prescribed by the regulation.