GO
Overall Score
LongStop
1. One-liner
Freezes the build, patch and vulnerability history EU courts will presume against you if you cannot produce it.
2. Trend signal — why now?
On 9 December 2026 Directive (EU) 2024/2853 replaces the 1985 product liability regime across all 27 member states. For the first time, software — embedded and standalone — is legally a “product” and falls under strict liability, the same regime as a faulty ladder (Lexology, Gibson Dunn).
Three things in the new text matter commercially, and they all point at records:
- Court-ordered disclosure against the defendant. Article 9 lets a court compel the producer to disclose relevant evidence once the claimant makes a merely “plausible” case. Jones Day notes the plausibility threshold is left undefined, and that the rebuttable presumptions operate as “a de facto reversal of the burden of proof” for software and AI products (Jones Day, June 2026).
- You lose by default if you can’t produce. Where the claimant’s proof is “excessively difficult” due to technical complexity, defectiveness and causation are presumed. The exoneration route is evidentiary: the producer must show the defect didn’t exist when the product was placed on the market.
- A 10-year long-stop, 25 for latent injury. Liability runs ten years from placing on the market — restarting on substantial modification — which turns retention into a decade-long obligation.
Meanwhile the same firms get hit by the Cyber Resilience Act: vulnerability reporting to ENISA from 11 September 2026 (24-hour clock), machine-readable SBOM in the technical file from 11 December 2027, fines to €15M or 2.5% of turnover.
ECIPE models the cost: insurance up 40% for newly covered sectors, €586bn of EU imports pulled into scope, and it flags that “major insurers are actively seeking to introduce new policy exclusions for claims arising from the use of AI” (ECIPE).
The commercial trigger is not the lawsuit — it’s the OEM supplier questionnaire. CRA Article 13(5) forces manufacturers to do due diligence on third-party components, so “OEMs must impose documentation and traceability requirements on their component suppliers,” pushing “an enormous burden for cybersecurity on the furthest downstream providers” (ComponentSense, Eclypsium). That questionnaire lands monthly, not once a decade.
Provenance:
- Signal 1 (demand): PLD 2024/2853 applies 9 Dec 2026 — software is a "product", Art. 9 court-ordered disclosure against the defendant, presumption of defect where proof is "excessively difficult", 10-year long-stop / 25 for latent injury — https://www.jonesday.com/en/insights/2026/06/the-revised-eu-product-liability-directive-state-of-play-across-eu-member-states-and-evolving-risk-landscape — 2026-06
- Signal 2 (feasibility): CRA Art. 13(5) forces OEMs to demand documentation and traceability from component suppliers; ENISA vulnerability reporting from 11 Sep 2026, machine-readable SBOM from 11 Dec 2027 — https://www.componentsense.com/blog/cyber-resilience-act-2026-a-compliance-guide-for-oems — 2026
- Signal 3 (economic): ECIPE models +40% insurance for newly covered sectors, €586bn imports in scope, insurers adding AI exclusions; consultants charge €6,000–18,000 per product line to scope a CRA technical file — https://ecipe.org/publications/economic-burden-revised-pld/ + https://ecocomply.ai/blog/how-much-does-eu-compliance-cost — 2026
Category: Regulatory arbitrage (liability shift onto a population that was never a "manufacturer" before) + Underserved niche (vendors sell conformity-today; nobody sells the dated record that survives a claim in 2036)
3. The opportunity
Every existing vendor in this space sells the artifact you need today: an SBOM, a conformity assessment, a security posture score, a technical file. Anchore, FOSSA (from $52/mo), Finite State, Snyk, CRA Evidence, EcoComply (€3,800/product) — all of them answer “are you compliant right now?”
The PLD asks a completely different question, and it asks it eight years from now: “prove this specific defect did not exist in the version you shipped on 14 March 2027.”
That is not a posture score. It is a dated, tamper-evident, third-party-attested record of what you shipped, what was in it, what you knew about it, and when you knew it. Three specific failures make this unbuilt today:
- Scanners are current-state, not historical. An SBOM tool tells you today’s dependencies. Re-running it in 2034 against a 2027 tag tells you what that scanner now thinks, which is worthless as evidence — CVE databases are retroactively edited, package registries delete versions, and the scanner’s own rules changed.
- The evidence lives in systems that don’t survive a decade. Git history gets rewritten and repos migrate hosts. CI logs default to 90-day retention. Jira tickets get bulk-deleted on plan downgrade. Slack free tier eats the “should we patch this?” thread — the single most probative document in the case.
- Nobody timestamps the negative. The winning defence is usually “the CVE was published after we shipped” or “we assessed it and it was not exploitable in our configuration, here is the dated reasoning.” No tool captures a dated non-decision.
CRA Evidence is the nearest thing that exists and it is explicitly CRA-only — its own guide never mentions the Product Liability Directive. It sells conformity assessment, not litigation survivability.
This is the capture-vs-defense gap in its purest form: capture is solved, defence eighteen months later is not.
4. Target market
Primary customer: Founder/CTO or Head of Engineering at a 20–200 person EU software company that ships into a physical or regulated product — embedded firmware houses, industrial IoT and automation software, medical-adjacent device software, automotive tier-2 suppliers, robotics middleware, building-management and energy software. Revenue €2M–€40M. They sell components to a bigger OEM.
Secondary: EU-selling standalone SaaS in high-consequence verticals (fintech infrastructure, logistics optimisation, clinical decision support), where “data corruption” and “medically recognised psychological harm” are now compensable heads of damage.
Why they buy — in the mechanic’s terms: They are not afraid of a lawsuit. They are afraid of the Friday email from their biggest customer’s procurement team containing a 60-question supplier due-diligence pack with a two-week deadline, where question 41 is “describe your vulnerability handling process and evidence retention policy,” and a bad answer loses a contract they’ve had for six years. That happens several times a quarter and it currently eats a week of the CTO’s time each round.
Rough TAM reasoning: Eurostat’s enterprise survey covers 1.53 million enterprises, of which ~83% are small (Eurostat). I don’t need that number. The addressable slice is EU firms that both write software and sell into someone else’s CE-marked product — conservatively tens of thousands of firms across DE/NL/SE/DK/FI/IT alone, given Germany’s Mittelstand automation base. I need 420 of them at €200/mo for $1M ARR. That is a rounding error on the segment.
Why now for them: Three dates in fourteen months — ENISA reporting 11 Sep 2026, PLD 9 Dec 2026, CRA SBOM 11 Dec 2027 — and their OEM customers are already flowing the requirements down contractually ahead of each.
5. Product sketch (MVP)
- Release freeze. On every tagged release, capture an immutable, hash-chained snapshot: dependency manifest, resolved versions, build inputs, the CVE state of the world as it stood on that date, and the signed commit range. Timestamped via RFC 3161. This is the whole product in one bullet.
- Point-in-time CVE replay. Answer “what was publicly known about this component on the day we shipped?” — not what today’s scanner thinks. This is the single hardest thing for a defendant to reconstruct later and the single most exculpatory fact.
- Dated triage record. One-click “we assessed CVE-XXXX-YYYY on this date; not exploitable because [reason]; decided not to patch.” Captures the reasoned negative, which no tool stores today.
- Supplier questionnaire autofill. Point it at the OEM’s due-diligence PDF or spreadsheet; it drafts answers from the archive with citations back to specific frozen releases. This is the feature that gets it bought.
- Evidence pack export. Generates a court-ready PDF+ZIP for a named release and date range: what shipped, what was known, what was decided, who signed off — with the hash chain and timestamp receipts.
- Update-duty tracker. Flags shipped versions still in the field with unpatched known-exploited vulnerabilities, since the PLD’s post-market update expectation is where “we had no idea” stops working as a defence.
- CRA technical-file shelf. SBOM in CycloneDX/SPDX, vulnerability handling policy, and the ENISA 24-hour reporting log — because the buyer will not run two tools.
6. AI angle — what’s load-bearing
Strip the AI out and this is a glorified S3 bucket. Two places it does real work:
Questionnaire answering. Every OEM’s due-diligence pack is bespoke — different wording, different format, PDF or XLSX or a portal. Mapping “describe your process for handling reported vulnerabilities in third-party components” onto the right evidence in the archive, and drafting a defensible answer with citations, is exactly the semantic-matching job LLMs are now cheap and reliable at. This converts a week of CTO time into twenty minutes of review. It is the difference between a filing cabinet and a product.
Triage reasoning capture. Engineers will not write a paragraph of legal-grade justification for skipping a patch. They’ll write “not exploitable, we don’t call that path.” The model expands that into a structured, dated assessment record — reachability rationale, configuration assumptions, affected versions — that reads as due care to a court eight years later. Capturing the reasoned negative at the painless moment is the whole trick; if it takes more than fifteen seconds, nobody does it and the archive has holes exactly where the defence needs substance.
7. Localization angle
EU-only by construction — the product is an EU legal regime. Real localisation work sits in three places:
- Language. German first. The Mittelstand embedded-software base is the densest concentration of the target customer, and their OEM questionnaires arrive in German. Then Dutch, Italian, Swedish.
- Transposition divergence. This is the meaningful moat. Member states are transposing 2024/2853 separately and only Hungary has finished; Germany, the Netherlands, Poland, Sweden and six others are at draft stage. Disclosure scope and trade-secret protection will differ by country — the Netherlands has already raised concerns that safeguards for commercially sensitive information are insufficient. Tracking 27 divergent disclosure regimes is exactly the tedious work a specialist tool should absorb.
- Non-EU sellers. US and UK firms shipping into the EU are in scope with no local counsel. Same product, English-first, likely higher willingness to pay.
8. Business model — path to $1M–$5M ARR
- Pricing: €149/mo Solo (1 product line, 3 years retention) · €399/mo Team (5 product lines, full 10-year retention, questionnaire autofill) · €999/mo Multi-product (unlimited lines, 25-year retention, SSO, audit export)
- Anchor: consultants charge €6,000–18,000 per product line to scope a CRA technical file; EcoComply charges €3,800/product; Z-CMS runs €4,000/project/year. €399/mo = €4,788/yr sits below the cheapest incumbent alternative while covering a duty they don’t cover at all.
- ACV: ~€4,800 blended.
- $1M ARR: 420 customers at €399/mo × 12 ≈ €2.0M… more honestly, ~200 customers at a €4,800 blended ACV ≈ €960K. Two hundred firms across DE/NL/SE. That is a reachable list, not a market-share fantasy.
- $5M ARR: ~1,000 customers, or 500 customers plus a €1,500/mo tier for firms with 20+ product lines and an insurer-facing export. Requires the questionnaire-autofill feature to become the daily-use hook rather than the archive being write-only.
- Expansion path: priced per product line, so it grows mechanically as they ship more SKUs. Real expansion is retention duration (3yr → 10yr → 25yr, and the 25-year tier is nearly pure margin) and eventually an insurer channel — if a carrier will discount premiums for firms holding a verified archive, pricing power roughly doubles overnight.
Storage is trivial (manifests and hashes, not binaries). The cost line is point-in-time CVE data and LLM calls on questionnaires — both variable and small against a €399 seat.
9. Go-to-market wedge — first 100 customers
- Mine the CE-marking trail. Products with digital elements sold into the EU carry a Declaration of Conformity naming the manufacturer, and OEM supplier lists are semi-public via trade directories, VDMA/ZVEI member lists, and industrial marketplaces. Build a list of 2,000 EU embedded/industrial software suppliers. Personalised outreach in German, opening with their own most recent CVE exposure — not a pitch, a finding.
- Free “Article 9 exposure check.” Point it at a public repo or a submitted SBOM; return a one-page report: “for your v3.2 release shipped 14 March 2026, we can reconstruct 40% of the evidence a court would order you to disclose. Here’s what’s already unrecoverable.” Nothing sells a retention product like showing someone the hole. This is the top-of-funnel engine and it is genuinely useful standalone.
- Go through the OEM, not the supplier. A single large manufacturer flowing CRA 13(5) due diligence down to 200 suppliers is a 200-account channel from one conversation. Offer the OEM a free portal to collect supplier evidence; the suppliers pay for their own archives. This is the highest-leverage motion and worth pursuing from month one even though it’s slower.
- Sell where the panic already is. German industry associations, CRA/PLD compliance webinars, and the specific LinkedIn/forum threads where CTOs ask “what does the new PLD actually mean for us?” — the legal industry has produced enormous alarm-raising content and zero tooling. Show up as the tool underneath the alarm.
- Fractional-CTO and compliance-consultant referrals. The €6K–18K consultants scoping CRA technical files need a system of record to hand over at the end of the engagement. Revenue share. They have the trust and the list.
10. Build complexity — justification
Medium. Off-the-shelf: git/CI integrations, CycloneDX/SPDX generation via Syft, RFC 3161 timestamping, standard web stack, LLM APIs for questionnaires. The genuinely custom work is point-in-time CVE reconstruction — you must snapshot NVD/OSV/GHSA state continuously going forward and build a queryable historical index, because you cannot retroactively recover what a CVE record said in 2027 unless you stored it. That’s a data-engineering discipline problem, not a research problem, and it must start on day one. Call it 12–16 weeks to a v1 a design partner will use, for two people.
11. Gating checklist
| Gate | Pass? | Note |
|---|---|---|
| Legal in target market | ✅ | Record-keeping tooling. No licensed activity, no legal advice — draft evidence, reviewed by the customer. |
| Ethical — no harm / dark patterns | ✅ | Helps firms document genuine due care. Does not help anyone hide anything; the archive is append-only by design, which cuts against the buyer as often as for them. |
| Market exists (evidence above) | ✅ | Dated statutory duty, consultants already charging €6K–18K/product line, live CRA-only competitors validating the buying centre. |
| 1–5 person team can build this | ✅ | Two people, 12–16 weeks. |
| Launchable with <$50K / ₹40L | ✅ | Storage is manifests. Main cost is founder time plus CVE-mirror infrastructure. |
12. Feasibility score
| Axis | Weight | Score | Notes |
|---|---|---|---|
| Problem intensity | 20 | 15/20 | Real and dated, but honestly deferred — the lawsuit is hypothetical and years away. What saves this score is the OEM questionnaire, which is felt monthly. Without that wedge it’s a 10. |
| Demand evidence | 15 | 11/15 | Strong statutory and spend evidence (€6K–18K consultants, live CRA vendors, ECIPE cost modelling). Marked down because I could not find verbatim customer complaints — the buyer isn’t loudly asking for this yet, they’re being told about it by lawyers. |
| Build feasibility | 15 | 11/15 | Standard stack, but the historical CVE index is real infrastructure that must run from day one and compounds only with time. |
| Distribution clarity | 15 | 12/15 | Named lists (VDMA/ZVEI, CE Declaration trail), a genuinely good free diagnostic, and an OEM flow-down channel that’s one-to-many. Not a two-week sprint — German industrial sales is slower than that. |
| Revenue mechanics | 15 | 12/15 | Pricing anchors below existing spend, only ~200 customers needed for $1M, per-product-line expansion is mechanical. Retention-duration upsell is untested. |
| Time to first revenue | 10 | 8/10 | Pre-sellable now against a fixed December date; design partners payable within 8 weeks. Not instant — this is a considered purchase with a security review. |
| Defensibility | 10 | 7/10 | The moat compounds and is time-locked: a competitor launching in 2028 cannot manufacture a 2026 CVE snapshot or a customer’s 2027 release freeze. Plus 27-jurisdiction transposition knowledge. Weakened by GitHub or Snyk shipping “release attestation” as a feature. |
| Total | 100 | 76/100 |
13. Qualitative modifiers
Founder-fit tags
technical-heavy · domain-expertise-required
You need someone who can build a CVE time-machine and someone who can hold a credible conversation about Article 9 disclosure with a German CTO’s lawyer. A solo generalist will build the bucket and fail to sell it.
Key assumptions to validate (3–5)
- Assumption: OEM supplier questionnaires are already arriving with CRA/PLD evidence-retention questions in them, at least monthly. How to test: get 15 EU embedded-software CTOs to forward the last three questionnaires they received. Count the questions that the archive would answer. If it’s fewer than three per pack, the wedge is imaginary and the whole thing collapses to a deferred-pain product.
- Assumption: they’ll pay €399/mo for evidence whose value is contingent and years away. How to test: sell 5 pre-paid annual design-partner slots at €3,600 before writing the CVE indexer. Pre-payment or it doesn’t count.
- Assumption: point-in-time CVE reconstruction is actually the sharp end and not a nice-to-have. How to test: ask a product-liability litigator at a German firm what they’d most want from a defendant’s records. If they say “the dated triage decisions” and not “the historical CVE state,” reorder the roadmap.
- Assumption: transposition lands close enough to the Directive that a single product works across member states. How to test: read the German and Dutch draft bills on disclosure scope. If they diverge materially on trade-secret protection, the product needs per-country logic sooner than planned.
Risk flags
- Regulatory timing risk (the big one): only Hungary has fully transposed as of mid-2026, with roughly ten states at draft stage six months out. Late transposition means late enforcement means a soft market in 2027. This is the single most likely reason the idea underperforms — and it’s the reason confidence is Medium, not High.
- Deferred-pain risk: nobody has ever been sued under this regime. The entire commercial thesis rests on the OEM questionnaire converting a decade-away fear into a this-quarter purchase. If procurement teams accept hand-waved answers — and Daniel Miessler’s long-standing critique is that vendor security reviews rarely actually block a deal — willingness-to-pay craters.
- Platform dependency: GitHub shipping free build attestation and provenance as a default feature would gut the capture layer. Survivable — the defensible part is the historical CVE index and questionnaire mapping, not the hashing — but it would compress pricing hard.
- Insurance substitution: if carriers simply price the risk and sell a policy, some buyers will insure rather than document. Partially mitigated by the fact that ECIPE observes insurers adding AI exclusions rather than broadening cover, which pushes firms back toward self-documentation.
14. Structured verdict
Score: 76/100
Verdict: GO
Confidence: Medium
Best-fit builder: Technical co-founder pair — one who can build a CVE time-machine,
one who can sell compliance to German industrial CTOs. German
language is close to mandatory for the beachhead.
Time to revenue: 8–10 weeks to first paid design partner; 6 months to repeatable
Capital to launch: €15–25K ($17–28K) — mostly founder time plus CVE mirror infra
Top 3 assumptions to validate first:
1. OEM supplier questionnaires already contain evidence-retention questions —
collect 45 real questionnaires from 15 CTOs and count
2. €399/mo clears for contingent, deferred-value evidence —
pre-sell 5 annual slots at €3,600 before building the indexer
3. Point-in-time CVE state is the highest-value artifact —
interview 3 German product-liability litigators on what they'd want from a defendant
Kill criteria:
- Abandon if fewer than 3 of 15 CTOs can produce a questionnaire containing an
evidence-retention or vulnerability-history question
- Abandon if fewer than 2 of 20 qualified prospects pre-pay for an annual slot
- Abandon if GitHub or Snyk ships historical point-in-time SBOM attestation as a
free default before v1 ships
- Abandon if fewer than 8 member states have published transposition bills by
December 2026 — enforcement will slip past the runway
15. Next step — 1-week validation sprint
- Day 1–2: Build the list. 300 EU embedded/industrial software suppliers from VDMA/ZVEI member directories and CE Declaration of Conformity filings. Identify the CTO or Head of Engineering at each. Draft the German-language outreach — the ask is “can you forward me the last three supplier questionnaires you received?”, not a demo request. Nobody refuses that.
- Day 3–4: Send 150 emails. Book calls with anyone who replies. In parallel, hand-build the point-in-time CVE reconstruction for one popular dependency across 2024–2026 to prove the historical index is actually possible from archived NVD/OSV data — if the data isn’t recoverable, the product’s sharpest feature is fiction and this ends on Day 4.
- Day 5: Count two numbers. (a) Of the questionnaires received, what fraction contain an evidence-retention or vulnerability-history question? (b) Of the CTOs spoken to, how many will put €3,600 down today for an annual design-partner slot?
Go if: ≥30% of questionnaires contain a retention/history question and ≥2 prospects pre-pay. No-go if either fails — the first tells you the wedge is real, the second tells you the deferred pain converts. Neither is a matter of opinion, and one week is enough to know.
Interested in a detailed proposal?
Get a deep-dive with market research, competitive analysis, and implementation roadmap.
Contact usinfo@startupbasket.ai