Beatriz Albernaz

Beatriz Albernaz

Head of Growth @ Faultline security

Badges

Tastemaker
Tastemaker
Gone streaking
Gone streaking
Gone streaking 5
Gone streaking 5

Maker History

  • Faultline Security
    Faultline SecurityPenetration testing & AI Red Teaming for SaaS companies
    Jun 2026
  • 🎉
    Joined Product HuntApril 17th, 2026

Forums

The EU Cyber Resilience Act's reporting clock starts September 11. What is your team doing about it?

September 11 is coming up fast, and I've had the same conversation with four different founders this month: "does the Cyber Resilience Act apply to us?" Every one of them assumed yes. Two of them were wrong.

I run penetration testing and AI red teaming for SaaS companies at Faultline Security, so this is squarely in my lane, and I wanted to write the honest version of this instead of the vendor version, because the vendor version says "everyone is in scope" and that's just not accurate.

What's actually happening on September 11

The CRA's reporting obligations become enforceable. If you're a manufacturer of a "product with digital elements," you now have to report actively exploited vulnerabilities and severe security incidents through a single platform, on a real clock: 24 hours for the early warning, 72 hours for a fuller notification, then a final report within 14 days (vulnerabilities) or a month (severe incidents). Fines for getting reporting wrong run up to 15M or 2.5% of global turnover.

Microsoft's AI security model and the November deadline for SaaS teams

Microsoft announced two new security products at a small San Francisco event yesterday: MAI-Cyber-1-Flash, the company's first cybersecurity-specialized AI model, and Perception, an agentic security platform that deploys teams of AI agents to find and fix vulnerabilities.

The preview opens November 3. That's the useful clock.

What the two products do

MAI-Cyber-1-Flash is built specifically for finding vulnerabilities in complex codebases. It powers MDASH, Microsoft's harness for software vulnerability identification and remediation.

SOC 2 vs ISO 27001: What SaaS Startups Actually Need

SOC 2 is the right starting point for most SaaS startups selling to US-based businesses. ISO 27001 becomes relevant when you are selling to enterprise customers in Europe, the UK, or regulated industries that specifically require it. You rarely need both at the same stage, and choosing the wrong one wastes significant time and money.

TL;DR
SOC 2 is the US standard, faster to achieve (3 to 9 months for Type I or II), and what most US SaaS buyers ask for. ISO 27001 is the international standard, more rigorous, takes longer (9 to 18 months), and is expected by European enterprise buyers and regulated industries. Start with SOC 2 unless your primary market or a specific large customer requires ISO 27001. Both frameworks expect penetration testing in a complete program. One engagement from 3,000 can often support both if the same systems are in scope for your SOC 2 and ISO work (the SOC 2 in-scope system and the ISO 27001 ISMS boundary are not always identical, so align this with your auditors in scoping).

What Is SOC 2?

SOC 2 (System and Organization Controls 2) is a security audit framework developed by the American Institute of Certified Public Accountants (AICPA). It is not a certification but an audit report, produced by an independent CPA firm, that attests to whether your security controls meet the Trust Services Criteria.

View more