Product Announcement · 20 July 2026

Reports are Live: Eight Exec-Ready Reports, Built from the Daily Work

Vulnetix now turns the findings, SBOMs, firewall telemetry and triage decisions your teams already produce into eight period-scoped reports. Six map to the regulations and frameworks your auditors ask about; two are native operational reads on coverage and remediation performance. Org-wide or per-repository, exportable for the board, a GRC tool, or an assessor.

See the feature page

Reporting is the step most tools hand you a CSV for. It is the fourth step of the Vulnetix loop, and we treat it as a first-class output: the same data that drives scanning, prioritisation and remediation is what fills the reports, so the board deck and the assessor's evidence come from the work rather than a separate quarterly scramble.

Six regulatory and framework reports

Regulation (EU) 2024/1689

EU AI Act

AI-BOM discovery and scanner findings mapped onto system inventory, risk monitoring, logging and post-market obligations.

NIST AI Risk Management Framework 1.0

NIST AI RMF

AI inventory, risk signals and firewall telemetry mapped onto the Govern, Map, Measure and Manage functions.

ISO/IEC 42001:2023

ISO/IEC 42001

AI asset data, controls evidence and manual attachments assembled into an exportable AI management system report.

OWASP Top 10:2025

OWASP Top 10

Findings grouped by OWASP category via a CWE map, with unmapped issues left visible as follow-up gaps.

PCI DSS v4.0.1, Report on Compliance

PCI DSS

A ROC-style workspace with pre-seeded requirements, linked telemetry, and per-requirement assessor findings and methods.

Regulation (EU) 2024/2847

EU Cyber Resilience Act

Vulnerability handling, SBOM coverage, CBOM quantum posture and the 24-hour reporting exposure for open exploited vulnerabilities.

Two native operational reports

Not every question leadership asks is a regulation. These two answer "are we actually scanning everything?" and "is the program reducing risk?", straight from the same data.

ISO/IEC 27001:2022

ISO 27001

A Statement of Applicability over all 93 Annex A controls plus clauses 4 to 10, with telemetry prefill and a completion tracker for the rows still missing a justification.

OWASP DevSecOps Maturity Model

OWASP DSOMM

193 activities scored across 5 dimensions and levels 1 to 5, against a target level set per dimension or area, on a maturity radar and heatmap.

Vulnetix Scan Coverage

Scan Coverage

Every input classified into a coverage taxonomy, with unclassified runs kept visible instead of hidden.

CTEM-aligned

Exposure and Remediation Performance

Open exposure, mean time to remediate against your SLA, KEV and aging pressure, and ATT&CK technique context.

One harness, eight outputs

The reports share one engine. Set the period and choose org-wide or a specific set of repositories, and every control inherits that boundary. Fixed-catalogue frameworks (PCI DSS especially) are pre-seeded so you start with the real requirement list, and seeded controls carry a marker until a human assesses them. Package Firewall and AI Firewall activity, scanner cadence and finding severity feed the controls that have a machine signal, but presence of a control never auto-upgrades a status to satisfied on its own. Export as a rendered PDF, framework-agnostic OSCAL JSON, or an evidence bundle (SBOM, VEX, CVE list, assessment notes) with SHA-256 sums.

Explore all eight reports →