Solutions · Incident Response

Four hours to a verified answer.

When a vulnerability goes public in a component you ship, the CRA gives you 24 hours to file an early warning and NIS2 gives you 72 to notify. Most manufacturers cannot even confirm exploitability in that window. ELTON can, because the model of your device exists before the incident does. ELTON is an exploitability management platform, delivered as a managed program. Our team verifies exploitability on your device the day a disclosure lands.

Why four hours is possible

The digital twin already models your firmware, software, and interfaces. Verification starts at disclosure, not after a scoping call and a signed statement of work.

The problem

Windows written in hours, processes written in weeks.

Vigilance and reporting clocks start when you become aware, not when your vendor has availability. A retainer is the only honest way to promise hours.

Three overlapping clocks

CRA early warning at 24 hours. NIS2 notification at 72. MDR vigilance timelines running underneath both. Each expects a position you can stand behind. None of them pause for procurement.

Guessing is its own liability

An early warning filed on speculation creates one problem. Silence past the deadline creates another. The only clean path out is a fast, evidenced determination.

Customers call first

Hospitals see the same headline you do, usually within hours. The first day decides whether they get a verified statement or a holding line. Your answer becomes their risk assessment.

The retainer

One workflow, three deadlines.

The sequence is agreed before anything happens. When a disclosure lands, nobody negotiates scope. Three checkpoints, agreed in writing before day one.

Hour 4: verified

ELTON attacks the disclosed vulnerability against your device model, and on the physical unit over TestLink™ where it matters. You know whether it is exploitable, with evidence attached.

Hour 24: determined

An early warning you can file: exploitable or not, affected releases, interim measures in place. Scoped to what the CRA actually asks for at this stage. If it is not exploitable, that determination is worth filing too.

Hour 72: reported

A complete, defensible report: verification evidence, affected versions, root cause, remediation plan, and the VEX update your customers are waiting on.

The timeline

From disclosure to defensible in 72 hours.

Retainer customers do not start with discovery calls. The twin is current, the contacts are named, and the report format is agreed. Hour zero is for verification, not paperwork. Timelines apply to devices under an active subscription with a current digital twin, measured from disclosure intake. That is the entire point of paying for readiness.

Retainer clock: disclosure to defensible Disclosure lands Early warning determination CRA, 24 hours 0h 4h 24h 72h verify determine report Exploitability verified on the real device, with evidence Full defensible report NIS2, 72 hours
Verification at hour 4 turns the 24 and 72 hour filings into determinations instead of guesses.
Standing ready

Before the disclosure

The retainer keeps the twin current with every release you ship, names the contacts on both sides, and agrees the report format with your regulatory team in advance. TestLink™ hardware can sit connected in your lab for on-demand runs.

At hour zero

When it lands

You send the advisory or we catch it in the feed, whichever comes first. Verification starts immediately against the twin, then on the real product when the finding demands it. Your team spends the window deciding, not investigating.

Get started

Have the answer before the deadline asks.

Put ELTON on retainer and the next disclosure starts a workflow, not a scramble: verified in 4 hours, determined in 24, reported in 72.

Questions

Common questions about incident response.

How fast do we have to respond when a vulnerability in our product goes public?

The CRA gives 24 hours to file an early warning and NIS2 gives 72 hours to notify, with MDR vigilance timelines running underneath both. Those clocks start when you become aware, not when a vendor has availability, and none of them pause for procurement.

What is a medical device incident response retainer?

An agreement that settles the workflow before anything happens, so nobody negotiates scope while a clock runs. The digital twin is kept current with every release you ship, contacts are named on both sides, and the report format is agreed with your regulatory team in advance. Timelines apply to devices under an active subscription with a current twin, measured from disclosure intake.

How can exploitability be verified within hours of disclosure?

Because the model of the device exists before the incident does. The digital twin already holds your firmware, software and interfaces, so verification starts at disclosure instead of after a scoping call and a signed statement of work. ELTON attacks the disclosed vulnerability against the twin, and on the physical unit over TestLink where it matters.

What should a 24 hour early warning actually say?

Something you can stand behind: exploitable or not, affected releases, and interim measures in place, scoped to what the CRA asks for at that stage. A determination that the product is not exploitable is worth filing too. An early warning filed on speculation creates one problem, and silence past the deadline creates another.

What goes into the 72 hour report?

Verification evidence, affected versions, root cause, remediation plan, and the VEX update your customers are waiting on. Verification at hour four is what turns the 24 and 72 hour filings into determinations instead of guesses, and it lets your team spend the window deciding rather than investigating.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON