Product Security

PSIRT Services

From organization to PSIRTaaS: we build your product security incident response - structure, processes, tooling - or run it as a service for you. Either way, you get a PSIRT that can actually intake, assess and disclose vulnerabilities under real deadline pressure, not just one that looks good in a policy document.

PSIRT Services

The Challenge

With the CRA at the latest, a working PSIRT becomes mandatory: vulnerabilities must be intaken, assessed and published as advisories in a coordinated way, demonstrably and on time. Many organizations lack the structure, experience and capacity to do this. Without a working PSIRT, reports from external security researchers are often answered too late or simply disappear internally, with direct consequences for reputation and regulatory deadlines. A PSIRT is not a one-off project, it is a permanent operational capability: reports arrive unannounced, often outside office hours, and regulatory response deadlines leave little room to maneuver. EACG supports the build-up from the first process to a fully-fledged PSIRT and operates it as PSIRTaaS on request, including the tooling integration with TrustSource this requires.

From organization to operations

01

PSIRT setup & organization

Roles, processes and governance for a capable product security incident response.

02

CRA & NIS2 conformance

Reporting duties, deadlines and evidence under the CRA and NIS2, built into your PSIRT processes instead of a separate compliance file.

03

Processes & tooling

CVD, triage, assessment and advisory publication - orchestrated with TrustSource (CVD, CSAF, PSIRT Automation).

04

Vulnerability disclosure policy

A public VDP as a clear reporting channel for external security researchers, aligned with your CVD processes.

05

Training & tabletop exercises

We rehearse the real thing before it happens: realistic scenarios for your PSIRT team and the departments around it.

06

PSIRTaaS

We run your PSIRT as a service - from vulnerability intake to the published advisory.

Let's talk about your project.

Get in touch →