Coordinated Vulnerability Disclosure (CVD) Policy

Created: 11 September 2026

1.Introduction and Purpose

Icom Incorporated ("Icom", "we", "us" or "our") is committed to the security of its products and services. We believe that coordinated vulnerability disclosure benefits our customers and the wider digital community.

This policy sets out Icom's approach to Coordinated Vulnerability Disclosure (CVD), taking into account the requirements of Regulation (EU) 2024/2847 (the Cyber Resilience Act, "CRA").

This policy explains how security researchers and members of the public can report potential security vulnerabilities in Icom products, and how we will respond to reported vulnerabilities.

2.Scope

This policy applies to potential security vulnerabilities in products with digital elements manufactured or provided by Icom, and in software associated with those products.

The scope generally includes:

  • Icom products with radio communications functionality;
  • Icom products with network connectivity;
  • firmware embedded in Icom products;
  • software or applications provided by Icom for use with Icom products;
  • product update mechanisms or related online services provided by Icom; and
  • other products or services designated by Icom as being within scope for vulnerability reporting.

The support period for products and software within scope is five years from the end of production. If you are unsure whether a product is covered by this policy, please contact the dealer from whom you purchased the product.

Out of Scope

As a general rule, the following are outside the scope of this policy:

  • products or software for which Icom's security support has ended;
  • third-party products, software, websites or services that are not operated or managed by Icom;
  • denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks;
  • social engineering, phishing or impersonation of employees;
  • physical intrusion, theft or damage to facilities or equipment;
  • large-scale use of automated tools or other activity that places an excessive load on Icom's or a third party's systems;
  • access to personal data, confidential information or third-party data beyond what is necessary to demonstrate a vulnerability;
  • intentional disruption of the normal operation of Icom products or services; and
  • use of a vulnerability to gain unauthorised access, alter or delete data, or exfiltrate data.

Even where a vulnerability relates to a component, software or service supplied by a third party, please report it to us if it may affect an Icom product. Where appropriate, we will coordinate with the relevant third party.

3.Reporting a Vulnerability

To report a security vulnerability, please use our Vulnerability Reporting Form.

Please note that, in the following circumstances, we may be unable to accept or process a report correctly, may only be able to process it to a limited extent, or may require additional time to handle it:

  • the reported vulnerability is outside the scope of this policy;
  • the report is submitted in a language other than English;
  • the report is submitted anonymously;
  • the information provided is insufficient;
  • the vulnerability is reported by a method other than the Vulnerability Reporting Form.

To reduce the risk of vulnerability information being disclosed to third parties before remediation, please do not post such information on social media, public forums, or issue-tracking systems accessible to third parties.

4.Our Response

As a general rule, we will take the following steps in response to vulnerability reports that we receive:

  • We aim to acknowledge receipt of the report within five working days.
  • We will review the report and investigate the affected product and the reproducibility of the reported vulnerability.
  • We will assess the impact, severity and exploitability of the vulnerability, as well as the range of affected products.
  • Where necessary, we may ask the reporter to provide additional information.
  • Where a supplier of a component or software is involved, we may coordinate with the relevant third party.
  • Where appropriate, we will consider remediation measures such as software patches, firmware updates, workarounds, security advisories or other measures.
  • We will provide status updates to the reporter where reasonably practicable.
  • Where possible, we will notify the reporter when remediation has been completed or when a course of action has been decided.
  • As a general rule, information on validated and verified vulnerabilities will be publicly disclosed within 90 days of the initial report. Where there is a valid justification, including the status of remediation or mitigation measures, the timing of disclosure may be adjusted.
  • If requested by the reporter, we will acknowledge the reporter in our security advisory.

Please note that we do not guarantee remediation, an update or an individual response in relation to every report received.

Investigation and remediation may take time depending on factors such as product architecture, the complexity of the vulnerability, the involvement of third-party components, and the potential impact of remediation on safety or functionality.

5.Safe Harbour

Where a reporter conducts security research in good faith, complies with this policy and applicable law, and reports a vulnerability to us, we will treat that activity as a contribution to improving the security of Icom products.

Where the following conditions are met, we will not, as a general rule, pursue criminal charges against the reporter solely on the basis of that research and report. We will also not require the reporter to enter into a non-disclosure agreement (NDA) as a condition of accepting the vulnerability report or commencing our investigation:

  • the reporter complies with this policy;
  • the research and report are carried out in good faith;
  • the reporter does not access data beyond what is necessary to verify the vulnerability;
  • the reporter does not misuse information obtained or disclose it to third parties;
  • the reporter does not intentionally disrupt Icom's or a third party's products, systems or services; and
  • the reporter reports the vulnerability to Icom and cooperates with us in good faith regarding the timing of public disclosure.

This policy does not limit legal action by third parties and does not authorise conduct that is unlawful.

If you are unsure whether your activity is consistent with this policy, please contact us via our PSIRT mailbox (psirt@icom.co.jp) before continuing your research.

6.Coordinated Disclosure

Where public disclosure of vulnerability information is necessary, we will work with the reporter and relevant third parties with the aim of minimising the impact on users.

We ask reporters, as a general rule, not to publicly disclose vulnerability information for 90 days from the date of the initial report, or for another period agreed between Icom and the reporter.

Where appropriate, we may take the following steps:

  • coordinate the timing and content of public disclosure with the reporter;
  • coordinate remediation with relevant component suppliers, software providers or other third parties;
  • where a security advisory is to be published, notify the reporter in advance where reasonably practicable;
  • where requested by the reporter and where we consider it appropriate, include the reporter's name, organisation or handle in a security advisory; and
  • where a vulnerability is already being exploited, or there is a serious and imminent risk to users, disclose information before the end of the 90-day period.

If agreement cannot be reached on the timing of disclosure, Icom and the reporter should continue to engage in good faith, taking into account user safety, the readiness of remediation, the likelihood of exploitation and the wider societal impact.

We may consider the CVD process complete in any of the following circumstances:

  • we determine that the reported issue does not constitute a vulnerability;
  • the vulnerability has been remediated or mitigated and any necessary public disclosure has been completed; or
  • we have requested additional information and, after a reasonable period without a response, we are unable to continue the investigation.

7.Information Protection

We will treat vulnerability reports as confidential, except where disclosure is required by law or is necessary for the public disclosure of vulnerability information. We will use the reporter's personal data for vulnerability handling and other legitimate business purposes, and will not disclose such personal data to third parties without the reporter's explicit consent.

For information about the protection of personal data, please refer to our Privacy Policy and GDPR Privacy Policy.