Starting point
A vulnerability inbox turned into a working starting point for PSIRT and SBOM.
We establish how to receive vulnerability reports, which components affect you and who owns what, before the process becomes more mature.
01 Fit
When this service fits
When vulnerability reports already reach you (by inbox, address or form) but there is no agreed way of handling them. It is a working starting point for device and software manufacturers, not a finished, mature PSIRT.
02 Scope
What we review
- How reports are received: a coordinated vulnerability disclosure (CVD) policy, a security.txt file and a contact channel.
- Report triage and an advisory template for customers.
- The software bill of materials (SBOM) as the basis for judging what actually affects you.
- The update and patch distribution process.
- A CRA art. 14 runbook: who reports an actively exploited vulnerability, and how, to the coordinating CSIRT and to ENISA.
- A tabletop dry run: what we do after a report of an actively exploited vulnerability.
03 Result
What decision the result supports
It leaves you with an agreed direction for reports, components and ownership, without pretending the process is mature on day one.
04 Inputs
What to prepare
- How reports are currently received, if at all (inbox, address, form).
- A list of products and components, or an existing SBOM.
- The people responsible for the product, patches and customer communication.
05 Terms
How scope and quotation are set
Scope and quotation depend on the number of products, the material available and the conversations required. We establish both after a short scoping call.
06 Limits
What this service does not replace
We set up the vulnerability handling process, but we do not guarantee that the product is free of vulnerabilities. It is a starting point, not a mature, fully staffed PSIRT, nor a substitute for ongoing security work. The manufacturer remains responsible for legally required reports and for the product itself.
07 Process
Signal → review → evidence → decision
Where does the vulnerability report come from?
Does it affect our product or a component?
What can we confirm and show customers?
How and to whom do we report, and what do we fix?
08 Questions
Questions before starting
- Is this a finished PSIRT? No. It is a working starting point that can then be developed and maintained.
- Why do we need an SBOM? Without a component list it is hard to judge which reports actually affect you.
- Does it connect with CRA Snapshot? Yes; it is the natural next step after CRA Snapshot.
09 Contact
Discuss the PSIRT/SBOM scope
We begin with a short description of the product and how reports reach you today.
Discuss your productSource: CISA SBOM. Editorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.