Focus

PSIRT and SBOM for manufacturers

Build vulnerability and reporting processes under the Cyber Resilience Act before the first report is due.

Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents via the ENISA reporting platform. From 11 December 2027, all CRA requirements apply. I help you set up a Product Security Incident Response Team (PSIRT), a software bill of materials (SBOM) and a robust vulnerability process.

Arrange an initial consultation

At a glance

Audience
Hardware and software manufacturers, product management and development
Format
Consulting and implementation – on site or remote
Language
German or English

What we work on together

  • Classifying your products and your role under the CRA
  • Setting up a PSIRT with roles, workflows and reporting channels
  • Creating an SBOM and keeping it current in your build pipeline
  • Vulnerability management and coordinated disclosure
  • Reporting process for the 24-hour, 72-hour and final report deadlines

Does this fit your situation?

Describe your situation briefly. I usually get back to you within one working day – with an initial assessment, not a sales pitch.