TrustnGoTrustnGo

PSIRT: vulnerability management for the CRA

Your products' software integrates a large number of third-party components. Their vulnerabilities are triaged throughout the support period, and an actively exploited one must be notified within 24 hours. This work is continuous, rarely urgent, and therefore hard to justify internally until an incident occurs.

We support you in two ways: building your PSIRT with your own teams, or carrying out this role on your behalf throughout the support period.

PSIRT: vulnerability management for the CRA

A continuous workload, even without incidents

A product's software rests on dozens to hundreds of third-party components, most of them open source. Their stream of published vulnerabilities never stops. Even though most do not affect your configuration, each dismissed case still has to be checked. The work is therefore ongoing, even for a product that will never face an incident.

This work belongs to a team dedicated to product security, the PSIRT, not to be confused with the team that handles incidents on your information system. It has a dedicated contact address and publishes a coordinated vulnerability disclosure policy. Industry guidelines advise against assigning both roles to the same person, except in a micro-enterprise.

This vulnerability management sits within the broader requirements of the Cyber Resilience Act.

Two offers

The choice depends on your headcount, the number of products and the length of your support periods. With a stable development team and several products, building in-house is justified. With one or two products and no security profile available, outsourcing costs less. The two offers can be combined: a PSIRT built in-house can keep calling on us for complex cases.

1

Building your PSIRT

Who triages vulnerabilities
Your teams
Who receives reports
Your psirt@ mailbox
Who drafts advisories and notifications
Your teams, TrustnGo review optional
Who decides between fix and mitigation
You
TrustnGo's commitment
Setup mission, then optional escalation
Typical duration
6 to 10 weeks
2

Outsourced PSIRT

Who triages vulnerabilities
TrustnGo
Who receives reports
Your psirt@ mailbox, forwarded to TrustnGo
Who drafts advisories and notifications
TrustnGo, validated by you
Who decides between fix and mitigation
You, on TrustnGo's recommendation
TrustnGo's commitment
Setup, Run, Response, Ready modules
Typical duration
Product support period

Offer 1: building your PSIRT

A time-boxed mission that leaves your teams autonomous at the end. We design the process with you and draft the documents. We then train the people who will hold the role, and verify that the whole thing works on a real case before stepping back.

1

What we produce

  • Scoping: product perimeter, support periods, critical third-party components, designation of roles and backups
  • Coordinated vulnerability disclosure policy ready to publish, aligned with domain standards
  • security.txt template compliant with RFC 9116 and specification of the public reporting page
  • Triage procedure: applicability, exploitability and risk criteria, documented decision format, vulnerability register
  • Notification procedure: criteria to qualify an actively exploited vulnerability or a severe incident, internal validation flow, meeting the 24-hour, 72-hour and 14-day deadlines
  • Early warning, notification and final report templates
  • Security advisory template, with a recommendation to adopt the CSAF format
  • Recommendations to generate an SBOM at every build from your existing build system and to correlate it with vulnerability databases
  • Definition of roles and decision points between the PSIRT, development, management and communication
  • Content ready to integrate into your technical documentation
2

What you put in place

  • Creation and administration of the psirt@yourdomain mailbox and the reporting page
  • SBOM generation from your build system (we can take care of it, as an option)
  • Designation of the people holding the roles
3

Training and validation

The program draws on our trainings.

  • Training of the designated people on the triage procedure and on meeting notification deadlines
  • Tabletop exercise on an exploited vulnerability scenario, including drafting a dry-run notification
  • End-of-mission review and gap report
4

After the mission, optional

  • Escalation to TrustnGo for exploitability analysis of complex vulnerabilities and review of notifications
  • Annual tabletop exercise and review of the disclosure policy
11,000 EUR excl. VATMission flat fee

SBOM generation setup available as an option. Escalation under an annual contract.

For IT services companies and integrators

1

Service under your own brand

You sell the service and manage the client relationship; we deliver offer 1 or the modules of offer 2 as a subcontractor, under a confidentiality agreement.

2

Method transfer and escalation

We build your IT services company's PSIRT under offer 1. Your analysts then handle monitoring and triage; we keep complex exploitability analyses and notifications, under a multi-year escalation contract.

How to get started

  1. 1

    A 45-minute call to review your products, their support periods, the state of your SBOM and the people available to hold the PSIRT roles.

  2. 2

    A written recommendation for one of the two offers, with scope, deadlines and decision points.

  3. 3

    For offer 1, a 6-to-10-week mission depending on the state of your build system. For offer 2, setup, then monitoring starting on the agreed date.

Note: the obligation to notify actively exploited vulnerabilities and severe incidents has applied since 11 September 2026. It covers all products in the scope of the regulation, including those placed on the market before 11 December 2027, and remains in effect after the end of the support period. If you already sell a product, the notification procedure is required now, even if you defer the rest.

Let's work together

Get a Price Quote