Cybersecurity Vendors
Compliance for organizations that secure others
Cybersecurity vendors face heightened scrutiny given their privileged access to customer environments. Thalorin helps security companies demonstrate their own robust security posture through comprehensive compliance programs that meet the expectations of security-conscious customers.
The statute that protects the sharing of cyber threat indicators expired, and what brought it back is a one-year patch. The Cybersecurity Information Sharing Act of 2015 lapsed on 30 September 2025 when its ten-year authorisation ran out, and it took the funding legislation enacted on 3 February 2026 to amend 6 U.S.C. 1510(a) and put the end date at 30 September 2026. Any vendor whose product moves indicators between customers, sharing communities and government has been building against a liability protection granted a year at a time, in arrears.
In the European Union a security vendor's own products sit in the most heavily assessed tier of the Cyber Resilience Act. Annex III class II — hypervisors and container runtime systems, firewalls, intrusion detection and prevention systems, tamper-resistant microprocessors and microcontrollers — has no self-assessment route at all: Article 32(3) allows only EU type-examination with production control, full quality assurance, or a European cybersecurity certification scheme at assurance level at least substantial. Chapter IV, which lets Member States designate the notified bodies, applied from 11 June 2026, eighteen months ahead of the Regulation itself.
Disclosure is the process built for the wrong audience. From 11 September 2026 an actively exploited vulnerability in a product with digital elements is a regulatory notification: an early warning within 24 hours to the coordinating CSIRT and to ENISA through the single reporting platform established by Article 16, a fuller technical notification at 72 hours, and a final report within 14 days of a corrective measure. That clock runs beside the CVE assignment, the European Vulnerability Database ENISA has maintained since May 2025, and every customer notification clause already signed.
A security vendor's own estate becomes evidence inside its customers' assessments, which changes what the record has to support. An advisory binds to the affected releases and to the customers running them; each standing entitlement into a customer environment is an asset carrying its own control record; and a coordinated disclosure, an Article 14 notification and a customer's assessor are answered from one state in Thalorin rather than from three reconstructions written separately under pressure.
Technology companies must prove their security
Class II leaves no self-assessment route
Hypervisors, container runtimes, firewalls and intrusion detection systems fall in Annex III class II of the Cyber Resilience Act, where Article 32(3) requires a notified body or a European cybersecurity certificate at assurance level at least substantial. Neither arrives on your schedule.
A 24-hour clock owed to a regulator
From 11 September 2026 an actively exploited vulnerability triggers an early warning to ENISA and the coordinating CSIRT within a day. Disclosure processes designed around researcher embargoes and staged customer advisories contain no step that fires that quickly.
Liability protection renewed in increments
6 U.S.C. 1510(a) runs the Cybersecurity Information Sharing Act only to 30 September 2026, restored by legislation enacted on 3 February 2026 after it had lapsed. Features and commitments that depend on sharing indicators are sold on terms longer than the safe harbour beneath them.
Your access sits inside your customer's scope
Privileged access into a customer environment makes your own controls evidence in their assessment. Their assessor tests your joiner-mover-leaver records and your session logging, and a weakness found on your side becomes a finding on theirs.
How Thalorin helps
Security vendor self-assessment
Assess against the essential requirements in Annex I of the Cyber Resilience Act before settling a product's class, since Annex III class II removes the self-assessment route outright rather than raising a bar.
SOC 2 for security products
Take the system description out to the product, not only the corporate environment behind it: a buyer of a security tool reads it for what the tool does with their data, not for how the vendor runs its own laptops.
Privileged access documentation
Hold every standing entitlement into a customer environment as an asset with an owner, an approval and a review date, so an assessor tests the access path instead of a policy describing it.
Customer trust assurance
A buyer of security tooling wants the current state, not a badge: which report is live, what its scope covers, and how long the release they run stays supported. Serve those from the assessed record, not from a hand-kept page.
Vulnerability management compliance
Resolve an advisory to affected releases and to the customers running them, carrying the CVE identifier, the European Vulnerability Database entry and the Article 14 notification against a single event.
Incident response transparency
Run the per-contract notification obligations on the same timeline as the regulatory clocks, so one incident produces one account rather than a set of parallel narratives written separately and later compared.
Cybersecurity Vendors: common questions
Is our security product an important product under the Cyber Resilience Act?
If it is a hypervisor or container runtime, a firewall, an intrusion detection or prevention system, or a tamper-resistant microprocessor or microcontroller, it is class II under Annex III. SIEM systems, password managers, malware detection and removal tools, VPN products, network management systems, identity and privileged access management, operating systems and public key infrastructure software are class I. Class I permits internal control only where harmonised standards, common specifications or a certification scheme at assurance level at least substantial are applied in full. Class II has no such route.
What has to be reported from 11 September 2026, and to whom?
Actively exploited vulnerabilities in your products, and severe incidents affecting their security, go to the CSIRT designated as coordinator and to ENISA through the single reporting platform established by Article 16. An early warning is due within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure being made available for a vulnerability, or within one month of the 72-hour notification for a severe incident.
Do the Cybersecurity Information Sharing Act protections still cover threat intelligence sharing?
Through 30 September 2026 as matters stand. The Act's ten-year authorisation lapsed on 30 September 2025, and the funding legislation enacted on 3 February 2026 amended 6 U.S.C. 1510(a) to replace 30 September 2025 with 30 September 2026. Longer-term reauthorisation has been discussed without being enacted. Sharing arrangements written on the assumption of a standing safe harbour should record which protections they actually rely on, and what the parties do if the authorisation is allowed to lapse a second time.
Our MDR service runs inside customer environments. Whose compliance obligation is that?
Both parties', in different registers. Controls over the access path, the tooling and the analysts are yours to evidence; the risk the arrangement introduces into the customer's environment is theirs to manage, and their assessor will test your side as part of doing so. Separating one customer's evidence from another's across a shared delivery platform is a different problem again, and Thalorin treats multi-tenant orchestration on the managed service provider capability rather than here.
Does a coordinated vulnerability disclosure policy satisfy the Cyber Resilience Act?
It is necessary and not sufficient. Annex I Part II of the Cyber Resilience Act requires manufacturers to put in place and enforce a policy on coordinated vulnerability disclosure, and ISO/IEC 29147 and ISO/IEC 30111 set the recognised practice for receiving reports and handling them internally. Neither addresses Article 14, which is a duty owed to a regulator on a fixed clock regardless of how the finding arrived, and no embargo agreed with a researcher suspends it.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Cybersecurity Vendors.
See how one evidence artifact satisfies Cybersecurity Vendors requirements alongside every other framework you carry.