Reports

Exec-ready reports, built from the daily work.

Ten reports, produced continuously from the findings, SBOMs, firewall telemetry and triage decisions your teams already generate. Eight map to the regulations, standards and frameworks your auditors ask about; two are native operational reads on coverage and remediation performance. All of them are period-scoped, org-wide or per-repository, and exportable for the board, a GRC tool, or an assessor.

Request a Demo

Ten reports, one harness

Reporting is a first-class output in Vulnetix: the same data that drives scanning, prioritisation and remediation is what fills the reports, so the board deck and the assessor's evidence come from the work rather than a separate quarterly effort.

Regulation (EU) 2024/1689

EU AI Act

AI-BOM discovery and scanner findings mapped onto system inventory, risk monitoring, logging and post-market obligations.

NIST AI Risk Management Framework 1.0

NIST AI RMF

AI inventory, risk signals and firewall telemetry mapped onto the Govern, Map, Measure and Manage functions.

ISO/IEC 42001:2023

ISO/IEC 42001

AI asset data, controls evidence and manual attachments assembled into an exportable AI management system report.

OWASP Top 10:2025

OWASP Top 10

Findings grouped by OWASP category via a CWE map, with unmapped issues left visible as follow-up gaps.

PCI DSS v4.0.1, Report on Compliance

PCI DSS

A ROC-style workspace with pre-seeded requirements, linked telemetry, and per-requirement assessor findings and methods.

Regulation (EU) 2024/2847

EU Cyber Resilience Act

Vulnerability handling, SBOM coverage, CBOM quantum posture and the 24-hour reporting exposure for open exploited vulnerabilities.

ISO/IEC 27001:2022

ISO 27001

A Statement of Applicability over all 93 Annex A controls plus clauses 4 to 10, with telemetry prefill and a completion tracker for the rows still missing a justification.

OWASP DevSecOps Maturity Model

OWASP DSOMM

193 activities scored across 5 dimensions and levels 1 to 5, against a target level set per dimension or area, on a maturity radar and heatmap.

Vulnetix Scan Coverage

Scan Coverage

Every input classified into a coverage taxonomy, with unclassified runs kept visible instead of hidden.

CTEM-aligned

Exposure and Remediation Performance

Open exposure, mean time to remediate against your SLA, KEV and aging pressure, and ATT&CK technique context.

The two operational reports, Scan Coverage and Exposure and Remediation Performance, give you a Continuous Threat Exposure Management (CTEM) read on the programme: what is covered, what is exposed, and whether remediation is actually keeping pace against your SLA.

How every report works

Choose the reporting window and whether the report is org-wide or narrowed to specific repositories; every control and finding inherits that boundary. Frameworks with a fixed control catalogue (PCI DSS especially) are pre-seeded so you start with the real requirement list, and seeded controls carry a marker until a human assesses them. Package Firewall and AI Firewall activity, scanner cadence and finding severity feed the controls that have a machine signal, but presence of a control never auto-upgrades a status to satisfied on its own. Export as a rendered PDF for the board, framework-agnostic OSCAL JSON for a GRC platform, or an evidence bundle (SBOM, VEX, CVE list, assessment notes) with SHA-256 sums for an assessor.

Read the launch write-up in the Reports announcement, or see how the evidence gets there via the Code Scanner.

Request a Demo →