ComplyITCOMPLIANCE. SIMPLIFIED.
OFFICIAL VULNERABILITY INTELLIGENCE

Know what matters.
Act before impact.

Known and exploited vulnerabilities from official EUVD, CISA KEV and NVD sources — translated into clear operational priorities.

10.0CRITICAL · EXPLOITED
CVE-2024-3400 · CISA KEV
REGULATORY RADAR · SEPTEMBER 2026

CRA reporting goes live.
Are manufacturers ready?

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe product-security incidents through ENISA’s Single Reporting Platform.

24h early warning72h full notification14d / 1mo final report
Read the official CRA guidance
GDPR · OPEN CONSULTATION

A common EU breach notification template is taking shape

What security and privacy teams should prepare before a harmonised digital form reaches national authorities.

Review the EDPB template ↗
PRACTICAL GUIDE · 8 MIN

One incident. Three possible notifications.

Walk through NIS2, GDPR and CRA decisions without losing the evidence trail or the clock.

Read the reporting timeline →
REPORT OR NOT?

Test the decision.
See the obligation.

Choose a scenario to see how technical facts become a regulatory reporting decision.

COMPLYIT ASSESSMENT
Likely reportable

Start the NIS2 assessment immediately. Preserve detection time, affected services, impact, indicators and the decision trail for the 24-hour early warning.

EvidenceImpactScopeDeadlineAuthority
Run your own assessment
REGULATORY RADAR

What changed.
What to do next.

A concise operational view of the rules behind cyber-incident reporting.

GDPR

Standard breach template under consultation

Align evidence fields across security, privacy and legal teams before the form becomes operational.

CRA

Single Reporting Platform becomes operational

Manufacturers and open-source stewards need ownership, escalation paths and report-ready product evidence.

NIS2

National implementation keeps evolving

Reporting thresholds, competent authorities and local submission paths must remain current in every Member State.

DORA

Financial entities report major ICT incidents

Keep the DORA decision path distinct while reusing reliable evidence, classification and approval records.

INCIDENT OF THE WEEK
ANONYMISED CASE18h 42m remaining

Suspicious access to a production system

A first-time sign-in from an unexpected country reaches a managed service environment. Is it a security event, a significant incident or a reportable personal data breach?

SignalAI classificationHuman approvalAuthority
See the decision trail
AUTHORITY SPOTLIGHT
SI

Slovenia: URSIV and SI-CERT

Know which body is competent, which channel to use and what evidence should be ready before the deadline starts to bite.

National CSIRT
SI-CERT
Competent authority
URSIV
Framework
NIS2
Open official authority page ↗
TEMPLATES & CHECKLISTS

Be ready before
the clock starts.

Practical structures for repeatable, auditable reporting.

MONTHLY EU THREAT BRIEF

Five risks. Three rule changes.
One clear priority list.

05critical vulnerabilities worth validating
03regulatory changes translated into actions
01incident scenario for your tabletop exercise
Get the monthly brief
MONITORED OFFICIAL SOURCESEUVD · ENISACISA KEVNVD · NIST
VULNERABILITY WATCH

Official signals.
Operational context.

VULNERABILITY WATCH

New risk appears.
Stay ahead.

Official sources, clear context, no noise. Unsubscribe at any time.