Product Security

Our Commitment to Product Security

Advantest takes all possible threats to our products very seriously and recognizes the importance of information received from customers and clients, in addition to our company's technology and sales information. Thus, a Product Security Incident Response Team (PSIRT) and a reporting process have been established that ensure any product security issues are immediately dealt with.

Policies and Rules Related to Product Security

Advantest has established a Product Cyber Security Policy setting out our approach to identifying, assessing and remediating any potential vulnerabilities in our products.
This policy aims to integrate cybersecurity to every phase of the lifecycle of an Advantest product. It establishes fundamental cybersecurity principles like Secure-by-Design and Secure-by-Default, which are followed from product planning and enable security features to be enabled by default. It also defines clear roles and responsibilities if a security issue is ever discovered.

Organization of the Product Security Management System

In FY2026, Advantest formed the Advantest PSIRT to reinforce initial response systems for product security incidents. PSIRT is the single point of contact for the users of our products to enable them to communicate directly and rapidly with us, in order to facilitate reporting on vulnerabilities. Furthermore, a reporting process that is available 24 hours a day, 365 days a year, has also been incorporated to facilitate early detection and swift response to global cybersecurity issues.

Advantest's PSIRT is composed of experts from different departments who work together across organizational boundaries to respond to potential product security issues as quickly as possible. PSIRT members fulfill specific roles and responsibilities.

Advantest’s PSIRT is dedicated to identifying possible cyber threats related to product security and designing solutions for any possible product security issues. If applicable, PSIRT will analyze the issue and coordinate all related processes, while Advantest’s defect management and R&D teams are responsible for developing patches and corrective actions to restore cybersecurity to the affected product.

System for Responding to Product Security Incidents

Advantest created a form through which any product security related issues can be reported to PSIRT. Said form can be found below and can be accessed without log-in requirements.

After a report is submitted, Advantest’s PSIRT will follow a pre-defined process to deal with the issue as quickly as possible, in order to restore full security to our products, as the safety of our customers’ data is of the highest priority to us.

Upon receipt of an issue, Advantest's PSIRT performs an initial triage and determines whether the reported item qualifies as a vulnerability, an exploited vulnerability, an incident, a severe incident, or a non-security issue. If the reported issue is not related to product security, the report is forwarded to the appropriate support team. For issues classified as security-related, PSIRT performs the detailed analysis and classification. Only exploited vulnerabilities and severe incidents are considered reportable under the Cyber Resilience Act (CRA). For reportable cases, the PSIRT prepares the report to ENISA, the European Union Agency for Cybersecurity. The report is reviewed by the Legal team and submitted by the Compliance team.

Reporting a Security Issue

The Advantest Group encourages users of our products to report any possible security vulnerabilities and incidents to us. After a report Advantest allocates appropriate resources to analyze, validate and provide actions to address the issue and restore proper security to the affected product.

To help ensure a smooth and efficient review process, please verify that you have all relevant information available before submitting your report.
For your convenience, we have outlined all required information below.

What product information do you have to submit?

  • Your name and contact information (e.g. email address, phone number)
  • Name of the affected product and further detail information (e.g. serial number, firmware version, ...)
  • Source of cybersecurity information
  • Description of the vulnerability
  • If applicable: exploit description
  • If applicable: incident description
  • If applicable: impact description

Important information before you submit

Please make sure you comply with the following points before you submit your report:

  • We kindly ask that forms be filled out in English, if possible, to help ensure a smooth and efficient review process.
  • We kindly ask you to submit any reports to us only through the form above to allow us to deal with any potential vulnerability as quickly as possible. Alternatively, you can also contact us at:
    • Postal address:
      Advantest Europe GmbH
      Compliance Unit
      Herrenberger Str. 130
      71034 Boeblingen
      Germany
  • Only new reports will be considered. Reports about vulnerabilities that have been publicly addressed by Advantest will not be considered.
  • Only share information that is relevant and do not share any information that you are not allowed to share with us, such as, for example, business secrets.

Frequently asked Questions

  • QI'm unsure whether what I found really qualifies as a security vulnerability.
    A

    If you believe that there is a possible weakness, susceptibility or flaw in an Advantest product that could be exploited by a cyber threat, e.g. that could potentially allow unauthorized access, data disclosure, unauthorized modification, code execution or bypass of security controls, please report it through our form. This also applies if it's unclear whether what you've found could be exploited in any of the ways mentioned.

  • QHow do I report a vulnerability for an Advantest product?
    A

    Through the form above. Please mention your name and contact info, alongside choosing the correct product and describing the vulnerability and the source of the information. Alternatively, you can also contact us at:

    • Postal address:
      Advantest Europe GmbH
      Compliance Unit
      Herrenberger Str. 130
      71034 Boeblingen
      Germany
  • QWhat do I need to consider by reporting?
    A
    • If possible, please submit your report in English to help ensure a smooth and efficient review process.
    • Reports through the form above are preferred. Alternatively, you can also contact us via mail. For the address, please refer above.
    • Only new reports will be considered. Reports about vulnerabilities that have been publicly addressed by Advantest will not be considered.
    • Only share information that is relevant and do not share any information that you are not allowed to share with us, such as, for example, business secrets.
  • QWhere do I learn about security updates for my purchased product?
    A
    • Through direct communications via customer facing teams.
    • Service instructions.
    • Corporate communications and public release if applicable.
  • QWhere do I learn about possible security risks?
    A

    If a security risk is discovered, you will be notified by Advantest directly.

  • QHow long will my purchased product get security updates?
    A

    The support period of Advantest products differs depending on the product and ranges over multiple years. During this period, security patches are provided to address any identified vulnerabilities affecting the product. For further information on this, please contact your designated Advantest representative.

ExcelPDF