If you place software on the EU market, you are now required to report actively
exploited vulnerabilities to ENISA within 24 hours of becoming aware of them — including
in products you shipped years ago.
REPORTING OBLIGATION LIVE2026-09-11·penalties to €15M or 2.5% of global turnover
The hard part isn't the report. It's knowing you owe one.
The 24-hour window starts when you become aware. That means someone has to be watching
every dependency in every product you ship, continuously, against the vulnerabilities that
are actually being exploited in the wild — not the 40,000 CVEs published each year, but
the roughly 1,700 on CISA's Known Exploited Vulnerabilities catalogue and its equivalents.
Most small vendors have no such process. Linux Foundation research found only
32% of manufacturers produce an SBOM for all products, and
41% have not yet determined whether the CRA applies to them at all.
Who
Manufacturers placing products with digital elements on the EU market. Importers and
distributors carry related duties.
What
Early warning to ENISA within 24 hours of awareness of an actively exploited
vulnerability; fuller notification within 72 hours.
From
11 Sep 2026 — reporting duties. Full obligations,
including SBOM in technical documentation, from 11 Dec 2027.
Exposure
Up to €15 million or 2.5% of worldwide annual turnover, plus market
restrictions and recalls.
What this does
You send us a lockfileYour package-lock.json or requirements.txt
— whatever your product actually ships with. No source code, no repo access.
We generate the component inventory and check itEvery component is matched against the CISA Known Exploited Vulnerabilities catalogue
— the roughly 1,700 vulnerabilities confirmed under active exploitation, not the
40,000-plus CVEs published each year. This is the automated, working part: the same
matching engine, re-run against the current catalogue.
You get told before the clock runs outIf a component you ship appears on the exploited list, you get the affected product,
the version, and a pre-filled draft of the ENISA Article 14 early warning — ready for
your review, not auto-submitted anywhere.
Founding member pricing
$79per month, all products
Flat rate. No per-seat, per-repository or per-scan pricing.
Existing compliance platforms start around $250–800/month and are built for teams with
a dedicated security function.
Email your package-lock.json or requirements.txt
to [email protected].
Get your first report within 24 hours.
Being straight with you, since this is a real charge: the SBOM-generation and
KEV-matching engine is built and tested — it's not vaporware behind a payment button.
What's manual right now, as a founding member, is onboarding: there's no automatic GitHub
connection yet, so you send us the lockfile directly, and again whenever your dependencies
change materially. We re-run your check against the current KEV catalogue every few days.
Automatic repo connection and continuous real-time monitoring are the next things we build,
and founding members get moved onto that automatically at no extra cost when it ships.