The framework
- Regulation (EU) 2024/2847 imposes security-by-design, vulnerability handling and reporting duties on products with digital elements placed on the EU market.
- It mandates an SBOM, coordinated vulnerability disclosure, and security updates over a defined support period.
- Reporting duties phase in ahead of full application.
Where a red-team result fits
Vulnerability handling
A coordinated vulnerability-disclosure process and an SBOM are baseline expectations — Provael ships both, and publishes a security.txt.
Evidence produced
- An SBOM published with each release.
- A coordinated vulnerability-disclosure policy and RFC 9116 security.txt.
- Secure-by-default posture: no telemetry and no network egress by default.
Dates (verified 6 Jul 2026)
- Reporting obligations (Art. 14) apply
- 11 September 2026
- Full application
- 11 December 2027
Not legal advice; verify the live EUR-Lex/ISO text at launch before relying on these dates.
Primary references
What it is — and isn’t
- adversarial-only — Provael measures adversarial robustness — susceptibility to manipulation — not general accuracy, reliability, or functional safety.
- evidence-not-certification — The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
- behavioural-not-worst-case — Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility — a behavioural lower bound, not a certified worst-case bound.
Running Provael does not make a system compliant or certified — it generates measurements you can put into a conformity or assurance file.
Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.
Clause references are indicative; a wrong clause citation is worse than a missing one.
Turn this into filed evidence.
Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.