Reporting is the step most tools hand you a CSV for. It is the fourth step of the Vulnetix loop, and we treat it as a first-class output: the same data that drives scanning, prioritisation and remediation is what fills the reports, so the board deck and the assessor's evidence come from the work rather than a separate quarterly scramble.
Six regulatory and framework reports
EU AI Act
AI-BOM discovery and scanner findings mapped onto system inventory, risk monitoring, logging and post-market obligations.
NIST AI RMF
AI inventory, risk signals and firewall telemetry mapped onto the Govern, Map, Measure and Manage functions.
ISO/IEC 42001
AI asset data, controls evidence and manual attachments assembled into an exportable AI management system report.
OWASP Top 10
Findings grouped by OWASP category via a CWE map, with unmapped issues left visible as follow-up gaps.
PCI DSS
A ROC-style workspace with pre-seeded requirements, linked telemetry, and per-requirement assessor findings and methods.
EU Cyber Resilience Act
Vulnerability handling, SBOM coverage, CBOM quantum posture and the 24-hour reporting exposure for open exploited vulnerabilities.
Two native operational reports
Not every question leadership asks is a regulation. These two answer "are we actually scanning everything?" and "is the program reducing risk?", straight from the same data.
ISO 27001
A Statement of Applicability over all 93 Annex A controls plus clauses 4 to 10, with telemetry prefill and a completion tracker for the rows still missing a justification.
OWASP DSOMM
193 activities scored across 5 dimensions and levels 1 to 5, against a target level set per dimension or area, on a maturity radar and heatmap.
Scan Coverage
Every input classified into a coverage taxonomy, with unclassified runs kept visible instead of hidden.
Exposure and Remediation Performance
Open exposure, mean time to remediate against your SLA, KEV and aging pressure, and ATT&CK technique context.
One harness, eight outputs
The reports share one engine. Set the period and choose org-wide or a specific set of repositories, and every control inherits that boundary. Fixed-catalogue frameworks (PCI DSS especially) are pre-seeded so you start with the real requirement list, and seeded controls carry a marker until a human assesses them. Package Firewall and AI Firewall activity, scanner cadence and finding severity feed the controls that have a machine signal, but presence of a control never auto-upgrades a status to satisfied on its own. Export as a rendered PDF, framework-agnostic OSCAL JSON, or an evidence bundle (SBOM, VEX, CVE list, assessment notes) with SHA-256 sums.