Cybersecurity

ANEP integrates cybersecurity into our solutions from the design phase onward to protect equipment, communications, and the associated data.

Our approach is specifically aligned with the European requirements applicable to connected devices, with particular emphasis on the RED Cyber standard EN 18031-1 and the evolving European regulatory framework under the Cyber Resilience Act.

RED cyber EN 18031-1

Our solutions meet the latest cybersecurity requirements
The RED Cyber Standard EN 18031-1 defines security requirements for Internet-connected radio equipment.

OUR KEY INITIATIVES IN CYBERSECURITY:

ALL COMMUNICATIONS ARE ENCRYPTED USING TLS ENCRYPTION (MQTT, SIP, VoIP)

REMOTE PROGRAMMING AND UPDATES ARE PERFORMED SECURELY OVER IP

Our goal: to offer connected devices designed to be secure, scalable, and tailored to the cybersecurity challenges of smart buildings.


Regulations on Cyber Resilience

(Cyber Resilience Act)

 

Preparing for New European Requirements
The Cyber Resilience Act (CRA) strengthens cybersecurity requirements for products containing digital components.

The 4 pillars of cyber resilience:

Be Proactive: Identify risks and prepare your teams before a problem arises.
Defend: Minimize damage and stop an attack as soon as it begins.
Recover: Restore data and resume operations quickly after an incident.
Adapt: Fix vulnerabilities to prevent the same attack from happening again.

September 11, 2026, marks the CRA’s first operational deadline. Manufacturers of products containing digital components are required to reporting vulnerability notification.

REPORT A CYBERSECURITY ISSUE
Have you identified a vulnerability or security issue in an ANEP product or service?

You can send us any information to the following secure email address:

security@anepanywhere.com

Each report is reviewed by our teams in accordance with applicable requirements

  1. Early warning within 24 hours to the relevant authorities (ANSSI / CERT-FR)
  2. Report serious incidents within 72 hours and provide an interim analysis detailing the vulnerability, its severity level, and the proposed corrective or attenuation measures.
  3. Notify affected users without undue delay so that they can implement the necessary security measures

Any questions?

For any general inquiries regarding the cybersecurity of our products, you can also contact our teams.