Product Security
About Moog Product Security
At Moog, we build advanced systems where quality, performance, and reliability matter. We recognize this extends to the digital elements of our products. Moog has implemented product cyber risk management practices to deliver the quality and reliability our customers depend on.
EU Cyber Resilience Act (CRA)
Moog is committed to embedding robust security practices across the entire product lifecycle to ensure full compliance with the EU Cyber Resilience Act. From secure-by-design development through continuous risk assessments, vulnerability testing, and incident response planning, we build and maintain reliable, resilient, and compliant digital products.
To report a Cybersecurity vulnerability or Concern with Moog Products
Use the button below to submit a form, or email us at product.security@moog.com
In your submission, please include:
- Product name and model/part number
- Software/firmware version(s)
- Brief description of the issue and its potential impact
- Steps to reproduce plus relevant logs/screenshots
- Your contact information
- Any other relevant details to enable rapid triage and response
Our report handling process
Moog follows the following steps to respond to submissions.
- Awareness: Moog becomes aware of a potential cybersecurity concern.
- Initial triage: Moog assesses submission for validity and whether enough information has been provided.
- Technical analysis: Moog investigates the reported concern, its applicability and impact on the Moog product.
- Remediation: Moog takes action to address the identified cybersecurity concern in line with customer and compliance expectations.
- Disclosure: When appropriate, Moog will disclose the verified cybersecurity risks to the relevant parties with remediation guidance and follow the applicable regulatory notification process.