Ten reports, one harness
Reporting is a first-class output in Vulnetix: the same data that drives scanning, prioritisation and remediation is what fills the reports, so the board deck and the assessor's evidence come from the work rather than a separate quarterly effort.
EU AI Act
AI-BOM discovery and scanner findings mapped onto system inventory, risk monitoring, logging and post-market obligations.
NIST AI RMF
AI inventory, risk signals and firewall telemetry mapped onto the Govern, Map, Measure and Manage functions.
ISO/IEC 42001
AI asset data, controls evidence and manual attachments assembled into an exportable AI management system report.
OWASP Top 10
Findings grouped by OWASP category via a CWE map, with unmapped issues left visible as follow-up gaps.
PCI DSS
A ROC-style workspace with pre-seeded requirements, linked telemetry, and per-requirement assessor findings and methods.
EU Cyber Resilience Act
Vulnerability handling, SBOM coverage, CBOM quantum posture and the 24-hour reporting exposure for open exploited vulnerabilities.
ISO 27001
A Statement of Applicability over all 93 Annex A controls plus clauses 4 to 10, with telemetry prefill and a completion tracker for the rows still missing a justification.
OWASP DSOMM
193 activities scored across 5 dimensions and levels 1 to 5, against a target level set per dimension or area, on a maturity radar and heatmap.
Scan Coverage
Every input classified into a coverage taxonomy, with unclassified runs kept visible instead of hidden.
Exposure and Remediation Performance
Open exposure, mean time to remediate against your SLA, KEV and aging pressure, and ATT&CK technique context.
The two operational reports, Scan Coverage and Exposure and Remediation Performance, give you a Continuous Threat Exposure Management (CTEM) read on the programme: what is covered, what is exposed, and whether remediation is actually keeping pace against your SLA.
How every report works
Choose the reporting window and whether the report is org-wide or narrowed to specific repositories; every control and finding inherits that boundary. Frameworks with a fixed control catalogue (PCI DSS especially) are pre-seeded so you start with the real requirement list, and seeded controls carry a marker until a human assesses them. Package Firewall and AI Firewall activity, scanner cadence and finding severity feed the controls that have a machine signal, but presence of a control never auto-upgrades a status to satisfied on its own. Export as a rendered PDF for the board, framework-agnostic OSCAL JSON for a GRC platform, or an evidence bundle (SBOM, VEX, CVE list, assessment notes) with SHA-256 sums for an assessor.
Read the launch write-up in the Reports announcement, or see how the evidence gets there via the Code Scanner.