Reporting obligations under Article 14 began 11 September 2026; the full Annex I essential requirements apply from 11 December 2027. If you sell software into the EU, that applies to you regardless of where you're based.
Every engagement includes reporting written for direct submission, not internal notes you have to reformat before your auditor can use them.
Manual testing against the product-property requirements in Annex I Part I: no known exploitable vulnerabilities at release, secure-by-default configuration, and proper access control and encryption.
We review whether your coordinated vulnerability disclosure (CVD) policy, intake channel, and remediation workflow meet the lifecycle-handling requirements in Annex I Part II.
We help you pressure-test whether you could meet the 24-hour early warning, 72-hour notification, and 14-day final report timeline for an actively exploited vulnerability, before you have to do it for real.
Findings and remediation evidence structured to feed into the technical documentation your CE-marking submission will eventually need.
Tell us what you're selling into the EU and where you are on Annex I readiness, and you'll get a proposal back directly.