What is not on the table.
- Legal advice on classification
- Filing reports on your behalf
- Penetration testing
- Conformity assessment for important or critical products
- NIS2 compliance work
Nothing here is hard to understand. It is hard to execute at 3 a.m. with nobody named and no channel that anyone watches.
Deadlines as published by the European Commission and ENISA, read 6 September 2026, and checked against the official text of Regulation (EU) 2024/2847. Sources in the table below.
For a vulnerability it is no later than 14 days after a corrective or mitigating measure is available. For an incident it is within one month after the incident notification was submitted. Most summaries collapse the two into one number.
Annex III (important, Class I and II) and Annex IV (critical) change the conformity assessment route under Articles 7, 8 and 32. Article 14, the reporting duty, applies regardless. Being a default product does not move the date.
Titles as they appear in Regulation (EU) 2024/2847, retrieved 6 September 2026 from the EU Publications Office.
"This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026."
ENISA has not published a public URL for the Single Reporting Platform as of 6 September 2026, so this page links the ENISA platform page rather than guessing an address.
It runs in your browser and nothing is sent anywhere. It will not tell you whether you are in scope. It will tell you which question to take to counsel first.
The whole process is public. You pay to have it working in your repositories by the end of an afternoon instead of the end of a quarter.
The whole process, in writing, for teams who would rather do it themselves.
The same kit, running in your repos and on your site before the session ends.
For teams who want the runbook to still be true in six months.
For agencies who ship products for other people and keep getting asked the same question.
Payment: Install and agency licence by Wise or bank transfer. Retainer by bank transfer. No card checkout on this offer yet.
Remote, screen shared, one sitting. Cairo (GMT+2), so EU mornings and afternoons both work.
Walk the decision tree against your actual shipped artefacts. Which are in scope, which are not, and why.
Install the workflow, run it by hand on the default branch, then on a real tag. Inspect the CycloneDX and SPDX output.
Deploy security.txt with a real expiry. Stand up the intake form in whichever of the three variants fits. Send one test report through it.
Roles, escalation path, the coordinating CSIRT, the EU Login and Assigned Representative step, the severity triage table, and the three communication templates. The runbook answers "which CSIRT is mine" in two steps: your Member State under Article 14(7), then your team read off ENISA's published list of designated coordinators. No phone calls, no guessing.
One simulated actively exploited vulnerability, run end to end against the clock.
Registration on the ENISA platform itself stays your action, under your own Assigned Representative account. Nobody should be registering as you.
If you ship a client, an agent, a desktop app, firmware or an SDK into the EU, the shipped artefact is the thing to look at. The free decision tree walks the question in about ten minutes. It does not answer it for you.
Dependency alerts are not an SBOM, not an intake channel, and not a 24 hour process with a named person. The kit adds the three parts that are missing.
The platform opens on 11 September 2026. The work that takes time is the intake channel and the named roles, not the form.
Two or three sentences: what the product is, which repositories build it, and whether anything today produces an SBOM. You get back a yes or a no on fit, a session slot, and the price you already read on this page.
Not legal or tax advice. This is process tooling. Whether your product is in scope, and which class it falls into, is your call with your own counsel.
Prefer email or WhatsApp? omar@neurascale.org or +20 150 047 7334. Cairo (GMT+2), which covers EU mornings and afternoons.