Mascot: The trusted reference standard for protein identification by mass spectrometry for 25 years

Posted by Ville Koskinen (September 23, 2026)

EU Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) is a European Union regulation that aims to improve the cybersecurity of all digital products sold in the EU – including proteomics tools. The regulation applies to companies and manufacturers, not end users. The main obligations are set to apply from December 2027, although some of the vulnerability reporting obligations already begin this month (September 2026). IT procurement teams and software distributors will be actively preparing for the main deadline. As a user of Mascot products, you don’t need to take any immediate action. From September 2026, we now have a formal vulnerability reporting procedure, and we will work towards CRA compliance for the December 2027 deadline.

Benefits to users

My reaction to the CRA as a consumer is: finally! The software market is full of products with known exploitable vulnerabilities and manufacturers who are reluctant to provide security updates. The CRA applies to every company that sells software products to people in any EU country, whether or not the company itself is based in the EU. So, almost every company worldwide will have to improve their software development processes for developing secure products: ignoring the EU market isn’t a winning strategy, and making a secure product for the EU and insecure for the rest of the world would be foolish.

The reaction of a small business making software for a niche field of scientific data processing could be one of two types. A business could whinge about having useless paperwork and tick-box exercises to do. Or, we can take it as an opportunity to make a better product for you. Matrix Science will take the opportunity.

The initial phase of the CRA establishes an EU-wide reporting mechanism for actively exploited vulnerabilities in software products. Take a moment to consider the exact definition from the regulation: it is “a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner” (EU Cyber Resilience Act (CRA) article 3). Most software products have both known and undiscovered vulnerabilities. Many of them are theoretical and can’t be exploited in practice. Some of them are exploitable, meaning they could, under certain conditions, be used for remote code execution, denial of service or breach of access restrictions.

The CRA reporting requirement applies to vulnerabilities that are actively exploited by unlawful or malicious actors. It is primarily a regulated communication mechanism to alert people quickly when an exploit is happening. The practical consequence is, companies (including Matrix Science) are incentivised to reduce or eliminate vulnerabilities in their products in the first place. It would not be fun to be in the news as the attack vector for a cybersecurity breach or to deal with the reputational damage.

From September 2026, we now have a formal vulnerability reporting mechanism. If you discover or learn about an actively exploited vulnerability in Mascot Server, Mascot Distiller or Mascot Daemon, please report it to us immediately. We will triage the severity and if there is concrete evidence of an unlawful or malicious actor, we will report the incident to the EU authorities and contact the affected users with mitigation instructions. In any case, we will fix any security hole in the product and provide a hotfix or a patch release, depending on the severity.

Securing your Mascot products

There are some easy steps to make sure your Mascot product is not accessible to malicious actors.

Mascot Server: Mascot Server requires a web server to function, but it doesn’t open any inbound TCP or UDP ports on its own. Always keep the web server behind a firewall; never allow access to ports 80 or 443 from the public Internet. You can also integrate Mascot Security with single sign-on (SSO) systems for user identification and authentication. This way, an attacker would need to gain access to your internal network (possibly also your authentication system) to exploit a vulnerability in Mascot Server.

If you have installed Mascot Server on your laptop or workstation, and you only access it through http://localhost, then you can block ports 80 and 443 in your PC’s firewall to prevent any incoming network access. These steps ensure an attacker would need to gain local access through other means in order to exploit a vulnerability in Mascot Server, at which point you have a bigger problem.

(Mascot cluster mode, which is not the default, requires certain inbound TCP ports to be open on the Mascot nodes. You should never run Mascot in cluster mode on the open Internet; always use a private network.)

Mascot Distiller and Mascot Daemon: Mascot Distiller and Mascot Daemon are desktop (GUI) applications. They don’t open any TCP or UDP ports in the local network, but they do have to make outbound HTTP(S) requests to Mascot Server and potentially matrixscience.com. Make sure the network connection between these is secure. If Mascot Distiller and Mascot Server are at different physical sites, use a VPN to ensure the traffic is encrypted.

A useful summary of the ports used by Mascot Server and Mascot Distiller is available in Help: How to set up remote working.

If you frequently download and process raw files from repositories like PRIDE, you should be aware that it is theoretically possible to craft a malicious file that causes Distiller to crash or worse. This applies to all vendor raw file formats as well as open formats like mzML. PRIDE provides checksum.txt in every project. You can calculate the checksum of the downloaded project and compare to checksum.txt to confirm the file hasn’t been modified in transit. However, it is possible to upload malicious files to PRIDE before checksum.txt is created, because checksum.txt is computed by the uploader, so comparing a checksum won’t help in that case.

Preparing for the December 2027 deadline

The main CRA deadline is December 2027. As a regular user, there isn’t anything you need to do to prepare for the deadline. The onus is on manufacturers and software distributors.

The CRA defines three product categories: default, important and critical. Most software products, including Mascot Server, Mascot Distiller and Mascot Daemon, are in the default category. Products in this category can be self-assessed by the company making them, in this case Matrix Science.

Any product released in the EU after December 2027 must comply with essential cybersecurity requirements (Annex I) and user instructions (Annex II) required by the CRA. So, from December 2027, any product release of Mascot Server, Daemon or Distiller will be shipped with a cybersecurity risk assessment, EU declaration of conformity, software bill of materials (SBOM) and relevant technical drawings and documentation required by the regulation. We may start to provide these in on a voluntary basis before the deadline. We will also make the documentation available for at least 10 years after each product release, as required by the CRA. Stay tuned for more news in 2027.

Keywords: ,

Comments are closed.