According to the Question 5.4. in the FAQ on the Cyber Resilience Act, the following applies to actively exploited vulnerabilities in third-party components: Manufacturers are required to notify any actively exploited vulnerability contained in their product with digital elements.
Frequentis AG
Company · Austria
Counts here are a floor, never a total: they cover the 326 consultation files tracked so far (29,503 submissions, mostly 2025–26), so an organization's real filing history is larger, not smaller.
Track Frequentis in PolicySpeak: request access →
Work at Frequentis AG? so we know who speaks for it.
Their record over time
Frequentis AG filed 2 positions on 30 Mar 2026, across 1 of the 326 legislative files tracked here.
What they argued
We would kindly ask for additional guiding and examples for what entails a product with digital elements as well as a clearer delineation of the role as a manufacturer and distributor in cases where a company acts as a project-based system integrator like in the following example: The companys activities correspond to those of a project-based IT systems integrator: from a portfolio of proprietary, in-house developed…
Looking for an argument rather than an organization? Search every submission for a phrase and see everyone who used it.
Is this your organization?
Everything on this page comes from Frequentis AG’s own submissions to the European Commission — we have added nothing and interpreted nothing. If something is wrong or out of date, email info@policyspeak.com and we will correct it. If you are an individual named in a record, our privacy policy sets out your rights to correction, objection and removal.
Quotes are verbatim from submissions published by the European Commission, trimmed to their opening passage and never summarized by a model. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.