Focus
PSIRT and SBOM for manufacturers
Build vulnerability and reporting processes under the Cyber Resilience Act before the first report is due.
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents via the ENISA reporting platform. From 11 December 2027, all CRA requirements apply. I help you set up a Product Security Incident Response Team (PSIRT), a software bill of materials (SBOM) and a robust vulnerability process.
Arrange an initial consultationAt a glance
- Audience
- Hardware and software manufacturers, product management and development
- Format
- Consulting and implementation – on site or remote
- Language
- German or English
What we work on together
- Classifying your products and your role under the CRA
- Setting up a PSIRT with roles, workflows and reporting channels
- Creating an SBOM and keeping it current in your build pipeline
- Vulnerability management and coordinated disclosure
- Reporting process for the 24-hour, 72-hour and final report deadlines
Does this fit your situation?
Describe your situation briefly. I usually get back to you within one working day – with an initial assessment, not a sales pitch.