Coordinated vulnerability disclosure policy
Where finders report, what you promise back, and on what timeline.
- Scope: Acme Desktop Agent 3.x
- Report to: security@acme.eu
- Acknowledge within: [TO BE DECIDED]
- Safe harbour: yes
EU Cyber Resilience Act, for makers of devices and self-hosted software
Send us an SBOM. We match every component whose package URL points to a source we have verified and list the rest as not checked. We flag the vulnerabilities CISA lists as exploited, run the 24-hour clock once you open a case, and keep a record your auditor can verify.
From $149/mo, 30-day refund
Seller: Tigran Avakov, a self-employed individual, Mirzo-Ulugbek 45A, 100007 Tashkent, Uzbekistan. support@musterproof.com
Acme Desktop Agent
3.4.0 / 412 components
org.apache.logging.log4j:log4j-core
2.14.1 to 2.15.0
org.apache.commons:commons-text
1.9 to 1.10.0
In force since 2026-09-11.
A consultant reads your product for two weeks and hands you a PDF. It is accurate on the day it is written. Then you merge a dependency bump, and the document quietly stops describing your product.
An enterprise scanner tells you about a vulnerability. It does not tell you whether that vulnerability reaches your product, it does not run a 24-hour clock, and it does not produce anything a market surveillance authority would accept as a record.
Both of them give you one link. The Regulation asks for the whole chain.
What you ship
What is wrong with it
What you decided
When you told them
That you can prove it
Non-compliance with the essential requirements and the vulnerability obligations reaches EUR 15 million or 2.5% of worldwide turnover, whichever is higher.
Three sources, checked on a schedule that matches how fast they move.
Components are matched against OSV every night. The CISA catalogue of actively exploited vulnerabilities syncs every six hours, and a new match is flagged against it the moment it lands, not at the next sync. EPSS tells you which of the rest is worth this week.
Advisories for npm, PyPI, Maven, Go, Cargo, NuGet, RubyGems, Packagist, Hex, Pub, Swift, CRAN, Hackage, Alpine, Debian, Ubuntu, Red Hat, AlmaLinux and Rocky Linux packages, matched by package, release and version range rather than by name alone. Other Linux distributions, and releases we have not verified, are not matched yet.
The catalogue of vulnerabilities being exploited right now. A new match is checked against it on the same run, not at the next sync.
The probability that a vulnerability gets exploited in the next 30 days. It decides what is worth this week among everything that is not on fire.
A vulnerability the database has withdrawn does not appear. Sending you to fix something the source itself no longer stands behind is worse than saying nothing.
What you decided
CISA says a component is being exploited. Whether that reaches your product, and whether it triggers your obligation, is a judgement only you can make. We hand you the signal, the clock and the record. The call stays yours, and so does the wording.
Marking a finding "not affected" requires a reason. An auditor will read it. A product that lets you close a vulnerability in silence is selling you the feeling of compliance.
The clock starts when you say it starts, and it cannot be moved.
Opening a case fixes all three deadlines at once: the early warning, the detailed notification, and the final report. Reminders go out before each one, to the people on the account, in their own time zone and in UTC side by side.
That you know. Minimal facts, sent to your CSIRT and to ENISA.
What it is, what you know about severity and impact, what mitigation exists.
The description, the fix, and the measures. Fourteen days for a vulnerability, one month for an incident.
Deadlines are stored as columns, not recalculated on every page load. A deadline that depends on which version of our code is running is not a deadline.
Every step is chained to the one before it.
Each entry carries the hash of the entry before. Change an old record and every hash after it stops matching. Export the journal and your auditor can verify the whole chain without trusting us, without an account, and without our servers being up.
Break it and watch.
This is the real structure, not a picture of one. Edit any entry below. Every hash after it stops matching, and the chain reports itself broken.
| Seq | When (UTC) | Who | What happened | Hash | Actions |
|---|---|---|---|---|---|
| 1 | Sep 11, 08:00 | ingest_token:ci | 412 components received from CIsbom.received | f7276a12e643e47cb655b8ea4917baa67c8b0ad2f2f2b82aae5ebc55daea68e7 | |
| 2 | Sep 11, 08:06 | system | CVE-2021-44228 flagged as actively exploitedalert.sent | 3e447face7d5a30451e12cb9403d828eee184d1a88b9653956ca8cc805804736 | |
| 3 | Sep 11, 08:41 | anna@acme.eu | Case opened, 24-hour clock startedreport.opened | 15f60371bae000581ed61c381fc15d0b6ec057d9bf3ad5a43436960b0e24273a | |
| 4 | Sep 12, 06:12 | anna@acme.eu | Early warning submitted, 2h 29m before the deadlinereport.stage.submitted | 1791336be0b2b9bddca27bfced2e960f143fca82e1544ac7eaee2b955efb54a0 | |
| 5 | Sep 14, 05:03 | anna@acme.eu | Detailed notification submittedreport.stage.submitted | 1ee376796fcabfb686e9825aa3a5f9044cc11009e18bd1f5a0e2d7cbe5d2cd96 |
1ee376796fcabfb686e9825aa3a5f9044cc11009e18bd1f5a0e2d7cbe5d2cd96Your auditor runs the same check on the exported file. That is the point: the record does not ask anyone to take our word for it.
A missed deadline is recorded exactly as it happened. A product that hides one is selling reassurance, and reassurance is worth nothing in the room where this gets checked.
The morning view
Fifty critical findings in transitive dependencies is the normal state of any product, and colouring them red teaches you to stop looking. Red is reserved for a component someone is exploiting right now.
Reporting obligations have applied since 2026-09-11.
Deadlines are shown in your time zone.
Red means a component is listed by CISA as actively exploited. Nothing else is red.
| Product | Status | Known exploited | Critical / High | Open |
|---|---|---|---|---|
| Acme Desktop Agent | Action today | 1 | 2 / 6 | 21 |
| Acme CLI | Scheduled work | 0 | 1 / 2 | 9 |
| Acme Gateway (firmware) | Scheduled work | 0 | 0 / 1 | 4 |
| Acme Cloud outside CRA scope | Nothing urgent | 0 | 0 / 0 | 0 |
That is the product rendering above, not a picture of it. The same components, the same traffic-light rule, the same data shapes. A drawing of a dashboard drifts from the dashboard within a week.
What you hand over
Four documents the Regulation expects you to have. Built from your product registry, not from a blank template you fill in twice.
Where finders report, what you promise back, and on what timeline.
The first place a finder looks. Published with an expiry date, because a stale one points at an address nobody reads.
How a report reaches you, who triages it, how fast a fix ships.
A skeleton with your data filled in and every remaining decision marked. It says so on the first page.
Where the decision is yours, the document says [TO BE DECIDED] instead of a plausible number. A document that decided your response times for you is one you sign without reading, and then hear about from whoever quotes it back at you.
When a buyer asks
Pick a version and build its release pack: the SBOM, a file of vulnerability statements, the product’s documents that have no gaps, the security contact from your security.txt, and a manifest with a SHA-256 for every file. Then send the buyer a link.
CycloneDX VEX for a CycloneDX SBOM, OpenVEX for an SPDX one. Nothing is called not affected on its own: a finding with no recorded decision is listed as under review. An SPDX release with no findings gets no statements file: OpenVEX needs at least one statement, and the pack says why.
The pack keeps the version and the hash of every file as they were the day it was built, and each download is checked against that hash. A decision made later goes into the next pack, so what the buyer holds is what you handed over.
The link works for 30 days unless you pick another term, and you can revoke it at any time. The page is read-only and is not indexed. You see how often it was opened and when. The access record is a count and a time: it holds no address and no browser.
A document that still has [TO BE DECIDED] gaps is left out of the pack and named on the page. The pack does not say your product is secure. It says what was decided and shows the rest as not yet reviewed.
Said here rather than discovered in month three.
We assemble the package with the fields filled in and run the deadlines. Whether the single reporting platform exposes an API is not settled yet. When it is, direct submission is the obvious next step. We would rather write this sentence than imply an integration that does not exist.
You generate the SBOM in your own build. It lists what you ship and nothing else. It is encrypted at rest with a separate key per object, because a dependency map of someone else’s product is an attack plan if it leaks.
They are drafts built from your registry, and every page says so. Have a qualified adviser read them before you rely on them.
That judgement is yours, and the Regulation puts it on you rather than on your vendor. We make it fast to make and impossible to forget.
Free until it is not
Works right up to the morning someone asks when you learned about a vulnerability and the honest answer is a cell somebody edited last March.
Paid once per audit
Real expertise, delivered once. Correct on the day it is written, and silent for every release after it. You buy it again next year.
Paid by the year
Excellent at finding vulnerabilities. Built for a security team you do not have, priced for a company you are not, and it does not produce a record of what you did about them.
From $149 per month
The whole chain, from the SBOM to the exported record, for teams where the person handling compliance also ships the product.
Monthly, or yearly at 20% off. Every plan includes the full workflow. The difference is how many products you cover.
$149 /mo
Billed monthly.
$1,430.40 /yr
Billed yearly. You save $357.60.
Up to three products.
$299 /mo
Billed monthly.
$2,870.40 /yr
Billed yearly. You save $717.60.
Up to ten products, three seats.
$499 /mo
Billed monthly.
$4,790.40 /yr
Billed yearly. You save $1,197.60.
For consultants looking after several clients: up to fifty products, ten seats.
Start free with one product and the whole workflow. A trial you cannot finish tells you nothing.
7 questions about scope, deadlines and your data.
Manufacturers, importers and distributors of products with digital elements sold in the EU, including companies established outside the EU. If you sell downloadable software or a device in the EU it very likely does, including if you are established outside the EU. Standalone SaaS and non-commercial open source are outside the scope. We ask you to classify each product, and when you mark one out of scope we stop asking you for compliance work on it.
From 2026-09-11, manufacturers must report actively exploited vulnerabilities and severe incidents through the ENISA single reporting platform: early warning within 24 hours, a detailed notification within 72 hours, and a final report within 14 days for a vulnerability or one month for an incident. This applies to products already placed on the market.
From 2027-12-11, the Regulation applies in full: essential requirements (Annex I), SBOM, a vulnerability handling process, technical documentation, conformity assessment and CE marking.
The CISA catalogue syncs every six hours. A newly matched vulnerability is checked against the catalogue we already hold the moment it lands, so a component that is being exploited is flagged on the same run rather than at the next sync, and the alert goes out by email and webhook within minutes of that. If CISA lists a vulnerability we matched earlier, the next sync, within six hours, puts the Known exploited label on its row, turns the product red in the dashboard and, if the finding is still open in your current release and not marked fixed or not affected, sends the alert by email and webhook with the date CISA added it. In both cases the 24-hour clock starts when you open a case, not when we flag it.
It is encrypted before it reaches storage, with a separate key per object wrapped by a master key we can rotate without touching your data. Nobody browses a bucket. A dependency map of your product is an attack plan against you, and it is treated as one.
Yes, and that is the design. The export carries every entry plus the root hash. Verifying it needs the file and a SHA-256 implementation. It does not need us, our servers, or our continued existence.
The journal records it as it happened, and the export shows it. We considered making that softer and decided against it: a record that flatters you is not a record, and the person who will read it knows the difference.
Sign in with your work email and post one SBOM. You get back what is exploitable in your product today, what to upgrade to, and what the Regulation expects you to have by each date.
One command: syft your build, one POST, and the report comes back the same day.
This material is generated from your own product data and public sources. It is not legal advice. Have a qualified adviser review your compliance documentation before you rely on it.