From building the process inside your company to supporting the 24-hour reporting system — one route.
Nothing in place yet? That is exactly where we start.
From that day, any manufacturer selling digital products in the EU must report an actively exploited vulnerability or a severe incident within 24 hours of becoming aware of it. The clock runs whether you find out at nine in the morning or three in the morning. There are dozens of fields to complete, the submission is in English, and someone inside your company has to be authorised to approve it.
We design the reporting roles around your organisation and produce the internal documents the regulation asks for. Review and approval pass to the next person automatically.
The moment a case is filed, the deadlines are calculated and watched, and every required field is guided step by step. Once internal approval is done, we walk you through the ENISA submission.
Decisions, reviews, approvals and submissions are sealed into a record that cannot be altered — an asset that helps demonstrate to a regulator that you followed the procedure.
From triage to the 24-hour deadline to the audit record — these are the actual screens.
Tell us where you stand and we will map out what you need — free of charge.