Email from a researcher
“I think I found a weakness in your app.” Who reads this, who checks it and when does that person receive a response?
This page distinguishes official frameworks, practical delivery and specialist assessment. Victory Consulting is not a regulator, certification body or government authority.
You sell an app, software, a smart device or an online product. Someone discovers a security problem. You do not want to work out, in that moment, who handles it, what is true and what must be reported.
Victory Consulting makes that route clear in advance. Not by randomly “hacking”, but by giving your team a workable guide, accountable people and a file.
Discuss your situation →“I think I found a weakness in your app.” Who reads this, who checks it and when does that person receive a response?
Your developer discovers that a recent update may be exploitable. Is it a technical issue, an incident, or does it possibly need to be reported?
A business customer asks: “How do you handle vulnerabilities?” You want to be able to show a clear policy and process.
Not every issue automatically falls under the same law or reporting deadline. That is why a good route always starts with facts, role and impact.
The report arrives through one clear channel. The reporter receives a proper acknowledgement.
The team gathers facts: which product, which customer, which risk and what information is still missing?
The assigned owner decides with the right specialist whether remediation, communication or a report is required.
Decisions, deadlines and remediation are kept in one file. That provides calm and evidence.
The Cyber Resilience Act is European legislation. It does not automatically apply to every business, but may apply to organisations making products with digital elements available on the EU market.
Regulation (EU) 2024/2847 lays down cybersecurity requirements for products with digital elements made available on the EU market.
Official EU overview ↗For manufacturers, actively exploited vulnerabilities and severe incidents require an early warning within 24 hours and full notification within 72 hours.
Official reporting deadlines ↗For Dutch cyber resilience and reporting processes, we refer to NCSC guidance and the Cyber Security Act where it applies to the organisation.
NCSC CVD guidance ↗We do not deduct a subsidy from a proposal before a scheme, activity, company and award actually allow it. For this type of service, no general Dutch subsidy was found that we may present as a fixed discount.