Background Image

Product Security

About Moog Product Security

At Moog, we build advanced systems where quality, performance, and reliability matter. We recognize this extends to the digital elements of our products. Moog has implemented product cyber risk management practices to deliver the quality and reliability our customers depend on. 

EU Cyber Resilience Act (CRA)

Moog is committed to embedding robust security practices across the entire product lifecycle to ensure full compliance with the EU Cyber Resilience Act. From secure-by-design development through continuous risk assessments, vulnerability testing, and incident response planning, we build and maintain reliable, resilient, and compliant digital products. 

To report a Cybersecurity vulnerability or Concern with Moog Products

Use the button below to submit a form, or email us at product.security@moog.com

In your submission, please include:

  • Product name and model/part number
  • Software/firmware version(s)
  • Brief description of the issue and its potential impact
  • Steps to reproduce plus relevant logs/screenshots
  • Your contact information
  • Any other relevant details to enable rapid triage and response

Our report handling process

Moog follows the following steps to respond to submissions.
 

  1. Awareness: Moog becomes aware of a potential cybersecurity concern.

  2. Initial triage: Moog assesses submission for validity and whether enough information has been provided.

  3. Technical analysis: Moog investigates the reported concern, its applicability and impact on the Moog product.

  4. Remediation: Moog takes action to address the identified cybersecurity concern in line with customer and compliance expectations.

  5. Disclosure: When appropriate, Moog will disclose the verified cybersecurity risks to the relevant parties with remediation guidance and follow the applicable regulatory notification process.