PSIRT: vulnerability management for the CRA
Your products' software integrates a large number of third-party components. Their vulnerabilities are triaged throughout the support period, and an actively exploited one must be notified within 24 hours. This work is continuous, rarely urgent, and therefore hard to justify internally until an incident occurs.
We support you in two ways: building your PSIRT with your own teams, or carrying out this role on your behalf throughout the support period.


A continuous workload, even without incidents
A product's software rests on dozens to hundreds of third-party components, most of them open source. Their stream of published vulnerabilities never stops. Even though most do not affect your configuration, each dismissed case still has to be checked. The work is therefore ongoing, even for a product that will never face an incident.
This work belongs to a team dedicated to product security, the PSIRT, not to be confused with the team that handles incidents on your information system. It has a dedicated contact address and publishes a coordinated vulnerability disclosure policy. Industry guidelines advise against assigning both roles to the same person, except in a micro-enterprise.
This vulnerability management sits within the broader requirements of the Cyber Resilience Act.
Two offers
The choice depends on your headcount, the number of products and the length of your support periods. With a stable development team and several products, building in-house is justified. With one or two products and no security profile available, outsourcing costs less. The two offers can be combined: a PSIRT built in-house can keep calling on us for complex cases.
Building your PSIRT
- Who triages vulnerabilities
- Your teams
- Who receives reports
- Your psirt@ mailbox
- Who drafts advisories and notifications
- Your teams, TrustnGo review optional
- Who decides between fix and mitigation
- You
- TrustnGo's commitment
- Setup mission, then optional escalation
- Typical duration
- 6 to 10 weeks
Outsourced PSIRT
- Who triages vulnerabilities
- TrustnGo
- Who receives reports
- Your psirt@ mailbox, forwarded to TrustnGo
- Who drafts advisories and notifications
- TrustnGo, validated by you
- Who decides between fix and mitigation
- You, on TrustnGo's recommendation
- TrustnGo's commitment
- Setup, Run, Response, Ready modules
- Typical duration
- Product support period
Offer 1: building your PSIRT
A time-boxed mission that leaves your teams autonomous at the end. We design the process with you and draft the documents. We then train the people who will hold the role, and verify that the whole thing works on a real case before stepping back.
What we produce
- Scoping: product perimeter, support periods, critical third-party components, designation of roles and backups
- Coordinated vulnerability disclosure policy ready to publish, aligned with domain standards
- security.txt template compliant with RFC 9116 and specification of the public reporting page
- Triage procedure: applicability, exploitability and risk criteria, documented decision format, vulnerability register
- Notification procedure: criteria to qualify an actively exploited vulnerability or a severe incident, internal validation flow, meeting the 24-hour, 72-hour and 14-day deadlines
- Early warning, notification and final report templates
- Security advisory template, with a recommendation to adopt the CSAF format
- Recommendations to generate an SBOM at every build from your existing build system and to correlate it with vulnerability databases
- Definition of roles and decision points between the PSIRT, development, management and communication
- Content ready to integrate into your technical documentation
What you put in place
- Creation and administration of the psirt@yourdomain mailbox and the reporting page
- SBOM generation from your build system (we can take care of it, as an option)
- Designation of the people holding the roles
Training and validation
The program draws on our trainings.
- Training of the designated people on the triage procedure and on meeting notification deadlines
- Tabletop exercise on an exploited vulnerability scenario, including drafting a dry-run notification
- End-of-mission review and gap report
After the mission, optional
- Escalation to TrustnGo for exploitability analysis of complex vulnerabilities and review of notifications
- Annual tabletop exercise and review of the disclosure policy
SBOM generation setup available as an option. Escalation under an annual contract.
Offer 2: outsourced PSIRT
We hold the role on your behalf throughout the support period and handle analysis, drafting and deadline tracking. The decisions remain yours. The offer is made of four modules you can subscribe to separately; Setup is a prerequisite for Run and Response.
PSIRT Setup
Initial setup of the process and its documentation.
- Coordinated vulnerability disclosure policy ready to publish
- security.txt template compliant with RFC 9116 and specification of the public reporting page
- Recommendations to create the psirt@yourdomain address and forward it to TrustnGo (deployed by you)
- Triage procedure, definition of roles and decision points between your teams and ours
- Recommendations to generate an SBOM at every build and a delivery procedure (setup by us available as an option)
- Content ready to integrate into your technical documentation
SBOM generation setup available as an option.
PSIRT Run
Continuous monitoring and triage throughout the support period.
- Correlation of published vulnerabilities with the SBOM you send us
- Applicability and exploitability analysis in the product's actual configuration
- Documented decision for each vulnerability, submitted for your validation
- Reporting to the maintainers of the third-party components concerned
- Vulnerability register kept up to date and a monthly report
Per product or per SBOM. 12-month commitment.
PSIRT Response
Handling of reports and situations subject to a regulatory deadline.
- Intake and initial triage of reports received on psirt@
- Qualification of an actively exploited vulnerability or a severe incident
- Drafting of the early warning, the notification and the final report, filed after your validation, and tracking of the 24-hour, 72-hour and 14-day deadlines
- Drafting of security advisories in CSAF format
- Coordination with the national CSIRT and relevant third parties
Time spent per event, billed hourly.
PSIRT Ready
Preparing your teams.
- Training of the internal referent on the procedure and on meeting notification deadlines
- Annual tabletop exercise on an exploited vulnerability scenario
- Annual review of the disclosure policy and the security.txt file
See our trainings.

For IT services companies and integrators
Service under your own brand
You sell the service and manage the client relationship; we deliver offer 1 or the modules of offer 2 as a subcontractor, under a confidentiality agreement.
Method transfer and escalation
We build your IT services company's PSIRT under offer 1. Your analysts then handle monitoring and triage; we keep complex exploitability analyses and notifications, under a multi-year escalation contract.
How to get started
- 1
A 45-minute call to review your products, their support periods, the state of your SBOM and the people available to hold the PSIRT roles.
- 2
A written recommendation for one of the two offers, with scope, deadlines and decision points.
- 3
For offer 1, a 6-to-10-week mission depending on the state of your build system. For offer 2, setup, then monitoring starting on the agreed date.
Note: the obligation to notify actively exploited vulnerabilities and severe incidents has applied since 11 September 2026. It covers all products in the scope of the regulation, including those placed on the market before 11 December 2027, and remains in effect after the end of the support period. If you already sell a product, the notification procedure is required now, even if you defer the rest.
