Entry offer

Readiness Snapshot

Could you actually meet a 24-hour reporting clock?

£950

+ VAT · one-off · paid online

· Delivered within 5 working days

From 11 September 2026 you have 24 hours to report an actively exploited vulnerability. You cannot report what you cannot detect — so the real question is not whether you have read Article 14, it is whether a report could travel from a component advisory to a named person to ENISA inside a day.

This answers that, without you granting anything. I work from public information — firmware downloads, app stores, documentation, certification databases — plus any artefacts you choose to send: an SBOM, release notes, your disclosure policy. You get the gaps named, ranked, and a one-page escalation path you can hand to whoever is on call.

What you get

  • A verdict on the 24-hour clock: detect, triage, report — or not
  • Named gaps in detection, triage and escalation
  • A one-page who-does-what-when-a-report-lands
  • Known-CVE exposure across your public stack
  • Gaps ranked, with a 30-minute readout
  • Fee credited toward a Readiness Review

Worth buying if

  • You do not yet know who owns your Article 14 reporting process on 11 September.
  • A customer questionnaire has landed and you need to answer it honestly.
  • Granting code access needs legal or procurement time you do not want to spend yet.
  • You are building the internal case for a deeper review and need ammunition.

How it works

  1. Buy it online

    Checkout runs on Stripe — VAT added there. No scoping call, no proposal cycle.

  2. I work from the outside

    Research across your public surface — firmware images, companion apps, docs, registries — plus any artefacts you send. No scanning of your infrastructure, no exploitation.

  3. Gaps, ranked

    A concise written summary with the gaps in priority order and the escalation path on one page, plus a 30-minute readout call.

  4. The fee carries forward

    Upgrade to a Readiness Review and the £950 is credited against it.

Asked before buying

  • Do you need access to our code or hardware?

    No — and that is deliberate, because it is what keeps this a same-week purchase with no NDA and no procurement. I work from public information plus any artefacts you choose to send: an SBOM, release notes, your disclosure policy. Reading your firmware is the Readiness Review. This is the outside view and your paperwork, which is exactly what an Article 14 report has to travel through.

  • Is any of this intrusive testing?

    No. It is research and analysis of public information — no port scanning of your infrastructure, no exploitation, no traffic generated against your services.

  • What if you find very little?

    A short list is a finding in itself — it tells you the outside view is clean and the open questions live inside the firmware. You get the same readout and the same credit toward a Review.

Start with the Snapshot

Secure checkout by Stripe. VAT added at checkout where applicable. The fee is credited toward a Readiness Review.

Field notes

Join the list

One field — your work email. One email every two weeks.

We’ll email you one confirmation link — click it and you’re on the list. Unsubscribe any time, in every issue. Handled per the privacy notice.