---
title: "Contact EmSA — CAN Security and CRA Compliance Guidance"
canonical_url: https://can-security.net/contact/
description: "Reach Embedded Systems Academy about CAN and CAN FD security, EU CRA and IEC 62443 obligations, customizing a Solutions shell, or reviewing a risk assessment."
last_updated: 2026-08-27
---
# Contact EmSA

Most of what we offer is described under [Solutions](https://can-security.net/solutions/) (off-the-shelf solutions mapped to EU CRA and IEC 62443 requirements) and at [emsa.courses](https://emsa.courses/) (training classes for EU CRA and CAN/CANopen related topics). For the two cases that do not fit, customizing a Solutions shell for your CAN system or reviewing your [risk assessment](https://can-security.net/resources/terms-and-definitions/#term-risk-assessment) record, reach us directly.

## Reach Us

All written inquiries across the EmSA platforms go through our central contact point:[  
Go to the ESAcademy contact form →](https://www.esacademy.com/en/contact-us.html?subject=cansecurity.net)

**  
Embedded Systems Academy GmbH**, Germany / Europe  
Phone: +49 5105 582 7897

**Embedded Systems Academy, Inc.**, US / Americas  
Phone: +1 877 812 6393 (toll-free, North America)

## Reporting a Security Vulnerability

To report a suspected security vulnerability in an EmSA product, use the same central contact point with "Security" as the subject, or the security address given there. That page states what a useful report contains and how EmSA handles it.  
[Report a security vulnerability →](https://www.esacademy.com/en/contact-us.html?subject=Security#security)

## Frequently Asked Questions

### How do I report a security vulnerability in an EmSA product?

Use the [security reporting section of the ESAcademy contact form](https://www.esacademy.com/en/contact-us.html?subject=Security#security), entering "Security" as the subject, or write to the security address listed there. Name the affected product and version, describe the impact, and include enough technical detail to reproduce or verify the issue. Please do not disclose the vulnerability publicly before EmSA has had a reasonable opportunity to investigate and address it.

### How do I request a risk assessment review?

Use the [ESAcademy contact form](https://www.esacademy.com/en/contact-us.html?subject=cansecurity.net) or call the number for your region and describe your CAN or CAN FD system. EmSA reviews your existing [risk assessment](https://can-security.net/resources/terms-and-definitions/#term-risk-assessment) record against EU CRA and IEC 62443 expectations and reports where the gaps are.

### Which EmSA product fits my CRA obligation?

It depends on the threat you need to cover. The [Solutions](https://can-security.net/solutions/) catalog maps each control to the [CRA Annex I requirements](https://can-security.net/resources/cra-requirements/) it supports. If none fit your system as shipped, EmSA can customize a Solutions shell for your application.

### Do you offer training on CAN security and the EU CRA?

Yes. EmSA runs scheduled and on-site classes on CAN, CANopen, and EU CRA topics. The current catalog and dates are listed at [emsa.courses](https://emsa.courses/).
