en-GB
dd/MM/yyyy

Optoma

Loading ring icon

Product Security (PTSI) And EU Cyber Resilience Act (CRA)

Our Commitment to Product Security

At Optoma, we are committed to delivering products that are secure, reliable and trusted by our customers. We recognise that cybersecurity is an ongoing responsibility and an essential part of the products and services we provide.

We continuously work to improve the security of our products by incorporating security considerations into product design, development, maintenance and vulnerability management activities.

Product Security Principles

In managing product security risks and vulnerability reports, we are guided by the following principles:

  • Taking security reports seriously;
  • Working collaboratively with customers, partners and security researchers;
  • Investigating reported vulnerabilities responsibly and professionally;
  • Assessing, mitigating and remediating confirmed security issues where appropriate;
  • Communicating responsibly throughout the vulnerability management process; and
  • Continuously improving the security of our products and services.

Regulatory Framework

EU Cyber Resilience Act (CRA)

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) (the "CRA") establishes cybersecurity requirements for products with digital elements placed on the European Union market. We are committed to supporting the objectives of the CRA and implementing the processes necessary to comply with applicable legal requirements. The CRA entered into force on 10 December 2024, with certain reporting obligations applying from 11 September 2026 and the main product compliance obligations applying from 11 December 2027. We will implement and maintain its product security, vulnerability management, incident reporting and compliance processes in accordance with the applicable requirements and implementation timelines under the CRA.

Further information regarding our product security processes and vulnerability disclosure practices can be found in our Coordinated Vulnerability Disclosure (CVD) Policy.

UK Product Security and Telecommunications Infrastructure (PSTI) Regulations

The UK Product Security and Telecommunications Infrastructure Act 2022 (the "PSTI Act") and the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 (the "PSTI Regulations") came into force on 29 April 2024. All Optoma in-scope products are required to comply with the requirements under the PSTI Act and PSTI Regulations. Statements of Compliance for Optoma products that fall within the scope of the PSTI Regulations are available below.

Product Name Support Period for Security Updates* PSTI Statement of Compliance
ML1080/ML1080ST December 2023 - December 2025 LDMLGZBZ-LDMLGZBZST.pdf
UHZ55 February 2024 - February 2026 VDUHZUZ.pdf
GT2100HDR July 2023 - July 2025 DAZHHUZST.pdf
GT3500HDR April 2024 - April 2026 DAZHHSZUST.pdf
UHZ35ST September 2023 - September 2025 DAZKHSZST.pdf
UHZ66 October 2023 - October 2025 DAZKHUZ.pdf
UHZ58LV November 2025 - November 2027 VDUHZUBLV.pdf
UHZ68LV February 2025 - February 2027 VDUHZLBLV.pdf
UHZ78LV December 2025 - December 2027 VDUHZTBLV.pdf
Photon Go May 2025 - May 2027 LDPGSGH.pdf
GT2200HDR June 2026 - June 2028 DALHSUNST.pdf

* The defined support period will not be shortened after the publication. If the defined support period is extended, the new defined support period will be published as soon as is practicable.

Report a Security Vulnerability

We welcome reports of potential security vulnerabilities from customers, partners, security researchers and other members of the security community. If you believe you have identified a security vulnerability affecting any of our products with digital elements, including related software, firmware or remote data processing solutions, we encourage you to report it to our Product Security Incident Response Team (PSIRT).

Reports may be submitted through our online submission form at Vulnerability Report.

To assist us in investigating the reported issue, please include where possible:

  • Product name and model number;
  • Software, firmware or application version;
  • Description of the vulnerability;
  • Steps required to reproduce the issue;
  • Technical details sufficient to understand and reproduce the issue;
  • Proof-of-concept information (if available);
  • Information regarding any observed exploitation;
  • Your contact information.

Any personal data provided in connection with a vulnerability report will be processed in accordance with our Privacy Policy. Please refer to our Privacy Policy for further information about how Optoma processes personal data.

For further information regarding Optoma's vulnerability reporting and disclosure process, please refer to our Coordinated Vulnerability Disclosure (CVD) Policy.