From , manufacturers selling software or connected products in the EU must report actively exploited vulnerabilities within 24 hours (Reg. (EU) 2024/2847, Art. 14 (opens in a new tab)). I build the intake channel, the triage runbook and the reporting workflow — an operating process with a rehearsed dry-run — for $2,500 fixed in 10 working days.
$2,500 fixed· 10 working days
Half on start, half on delivery of the evidence pack. Milestone billing above $8,000. Evidence pack or no fee: every engagement ends with a dated evidence pack. If I don’t deliver it, you don’t pay the closing half.
What is this for, exactly?
Manufacturers of products with digital elements on the EU market — obliged to report actively exploited vulnerabilities from 11 September 2026.
What do you get?
- A vulnerability intake channel: /.well-known/security.txt, a disclosure policy, a monitored inbox
- A triage runbook with severity criteria and the “is it actively exploited?” decision
- The reporting workflow: 24-hour early warning, 72-hour full notification, final report within 14 days of a corrective measure — routed via the CRA Single Reporting Platform to your CSIRT
- Named roles, a contact list, and one rehearsed dry-run
Why is “a process, not a document” the whole product?
A reporting policy PDF does not answer a 24-hour clock. What answers it is: a route for the world to tell you about a vulnerability (/.well-known/security.txt, a disclosure policy, a monitored inbox), a triage step that decides “is this actively exploited?”, named people who know it is their job, and a workflow that has been run once before it is run for real. That is what gets built, and the dry-run at the end is what proves it works.
What is the cheapest honest test of your exposure?
Open yourdomain/.well-known/security.txt. If it returns a 404, there is currently no published route for a researcher to report a vulnerability to you — which means the 24-hour clock can start without you knowing. That single check is free, takes ten seconds, and is exactly how I find most of the companies I write to. This site's own security.txt and disclosure policy are live — the artefact I sell, deployed where you can inspect it.
Where do the reports actually go?
Once, through the CRA Single Reporting Platform, addressed to the CSIRT of your main establishment — with the information made available to ENISA. The workflow encodes the route, the timelines (24 hours / 72 hours / 14 days, one month for severe incidents) and the content each stage needs, per the Commission's published guidance (European Commission, “CRA reporting obligations” (opens in a new tab), retrieved ).