PSIRT Services
From organization to PSIRTaaS: we build your product security incident response - structure, processes, tooling - or run it as a service for you. Either way, you get a PSIRT that can actually intake, assess and disclose vulnerabilities under real deadline pressure, not just one that looks good in a policy document.
The Challenge
With the CRA at the latest, a working PSIRT becomes mandatory: vulnerabilities must be intaken, assessed and published as advisories in a coordinated way, demonstrably and on time. Many organizations lack the structure, experience and capacity to do this. Without a working PSIRT, reports from external security researchers are often answered too late or simply disappear internally, with direct consequences for reputation and regulatory deadlines. A PSIRT is not a one-off project, it is a permanent operational capability: reports arrive unannounced, often outside office hours, and regulatory response deadlines leave little room to maneuver. EACG supports the build-up from the first process to a fully-fledged PSIRT and operates it as PSIRTaaS on request, including the tooling integration with TrustSource this requires.
From organization to operations
PSIRT setup & organization
Roles, processes and governance for a capable product security incident response.
CRA & NIS2 conformance
Reporting duties, deadlines and evidence under the CRA and NIS2, built into your PSIRT processes instead of a separate compliance file.
Processes & tooling
CVD, triage, assessment and advisory publication - orchestrated with TrustSource (CVD, CSAF, PSIRT Automation).
Vulnerability disclosure policy
A public VDP as a clear reporting channel for external security researchers, aligned with your CVD processes.
Training & tabletop exercises
We rehearse the real thing before it happens: realistic scenarios for your PSIRT team and the departments around it.
PSIRTaaS
We run your PSIRT as a service - from vulnerability intake to the published advisory.