Go to market
The credible path is compliance-led EU enterprise pulled by CRA/NIS2, seeded by free open-source tooling and research-credibility inbound.
For a Berlin-based technical founder with no sales team, exactly one of the five credible motions is buildable solo in year one — open-source/dev-led bottom-up — and exactly one regulatory tailwind makes the enterprise motion faster in the EU than in the US: CRA and NIS2 compliance deadlines that are already live. The sequencing that follows from that: give away detection for free, sell fixing and compliance evidence, and use design partners and published research to compress the credibility gap a two-person Berlin lab would otherwise take years to close.
#The five motions, and what each actually requires
#1. Open-source / developer-led bottom-up
What it costs: mostly time, not capital — an engineer's time to build a genuinely useful free CLI/scanner, community management, and documentation. Every AI-native code-security vendor checked (Snyk, Semgrep, Socket, Corgea, Aikido, Greptile) runs a real, functional free tier, not a trial Who buys, and what they pay. Socket's is unusually generous — unlimited developers and repos — precisely because a newer entrant needs the widest possible top-of-funnel against incumbents' installed base.
How long it takes: 12-24 months to build a credible open-source user base large enough to convert meaningfully — Snyk's 2015-2019 free-for-OSS motion is the canonical case study, and it took years before enterprise conversion became the dominant revenue driver.
Who has done it, and fit: Snyk (original playbook), Semgrep (open-source rule engine predates the commercial platform, giving it a pre-existing user base to convert), Socket. Standard practice in 2026 — every vendor does it, so it's table stakes, not a differentiator alone. Fit for a Berlin technical founder: strong. No sales team required, no enterprise credibility needed on day one, plays to a technical founder's comparative advantage. Tradeoff: the slowest path to revenue.
#2. Compliance-led enterprise, pulled by CRA/NIS2
What it costs: a founder-led or first-AE sales motion, SOC 2 Type II (roughly $20K-$50K plus ongoing audit costs, [unsourced] industry-standard estimate), and genuine EU-region/self-hosted deployment capability before the first enterprise conversation happens.
How long it takes: 3-9 months per deal at a 5,000+ person regulated company once the motion is running, per the sales-friction data in Who buys, and what they pay — but the regulatory calendar itself is the accelerant, not the deal cycle. EU regulation as a demand engine lays out five forcing functions creating dated, board-mandated budget right now, not hypothetically:
- CRA Article 14 vulnerability/incident reporting went live 11 September 2026 — every manufacturer of a "product with digital elements" sold into the EU must detect, triage, and report actively-exploited vulnerabilities to ENISA/CSIRT on an hours-to-days clock. This is operationally impossible to satisfy manually above a handful of products, and it's a hard, dated, EU-wide trigger.
- Germany's NIS2UmsuCG, in force since 6 December 2025, brought an estimated 15,000-30,000+ German mid-market and public-sector entities into scope for the first time, with personal management liability attached — a board member facing personal liability wants defensible, continuously-monitored controls, not an annual pentest PDF.
- DORA's threat-led penetration testing (TLPT) cycle, live since 17 January 2025, converts adversarial testing from an occasional audit line item into a recurring, mandated budget line for the largest EU financial entities and their critical ICT vendors — durable, repeat-purchase demand.
Compare this to the US: the equivalent flagship American forcing function, CMMC Phase II, was suspended in July 2026 rather than taking effect on its planned 10 November 2026 date. The EU's regulatory calendar is currently the more reliable near-term demand driver of the two — which is a genuinely unusual moment where the EU market is ahead of the US market as a go-to-market accelerant, not behind it. See EU regulation as a demand engine for the full forcing-function analysis.
Who has done it, and fit: every legacy AppSec incumbent's enterprise motion depends on this compliance pull, and it's the explicit rationale Aikido, Corgea, and ZeroPath give for building BYOK and self-hosted deployment into their Enterprise tiers. Fit for a Berlin technical founder: good, but not solo-executable. Requires at least one person doing sales/customer-facing work, and requires SOC 2 plus EU hosting in place before the first regulated-buyer conversation. Highest-value motion available, and the one most tied to the founder's Berlin location — but it cannot run on engineering time alone.
#3. Research-credibility-led inbound
What it costs: engineering time spent on things that don't ship revenue directly — publishing benchmark results, open-sourcing evaluation harnesses, writing up findings from real security research. Genuinely cheap in dollar terms, expensive in focus.
How long it takes: a single well-timed publication can generate inbound within weeks; a reputation that reliably generates inbound takes 6-18 months of consistent output.
Who has done it, and fit: this is the AIxCC playbook at the ecosystem level — all seven finalist teams were required to open-source their cyber reasoning systems, DARPA's explicit design goal being to seed the open-source ecosystem, not a classified capability AIxCC: the closest thing to a proof. At company level, XBOW's founder credibility (built GitHub Copilot) and RunSybil's founding story (OpenAI's first security hire) substitute for traction in fundraising — Who funds this and at what price documents that 2026 investors price pedigree and named-enterprise validation above product maturity or revenue scale. The same dynamic works on customers: a lab publishing credible, verifiable findings gets inbound from security teams who'd never answer a cold email. Fit: excellent, and underused. The second motion a solo founder can run without a sales team, and it compounds with #1.
#4. Channel: MSSP, MSP, Big-4
What it costs: partner enablement, revenue-share terms typically in the 15-30% range [unsourced, standard SaaS channel economics], and a partner-facing product (white-label reporting, multi-tenant dashboards) most early-stage products don't have. How long: 12+ months to sign a meaningful Big-4 or MSSP partnership and see deal flow; partners want a proven, referenceable product first. Who's done it, and fit: the underlying research came back thin here — AWS's own seller-fee percentage sits behind a signed-in portal, and CrowdStrike Marketplace's partner economics require direct sales contact. What's confirmed: marketplace-based procurement is real and used (Endor Labs, XBOW list it as a stated GTM option), because buyers want to draw down an existing cloud commit rather than run new procurement. Fit: weak, for now — requires reference customers and partnership headcount a five-person lab doesn't have. Revisit at Series A.
#5. Marketplace (AWS/Azure/GCP)
What it costs: engineering time for the listing/billing integration, plus a commonly-cited but unconfirmed ~3% listing fee [UNVERIFIED]. How long: weeks to list, but marketplace revenue ramps slowly and depends on a base motion already generating demand — a listing rarely creates demand on its own. Who's done it, and fit: Endor Labs and XBOW both list marketplace purchasability. Low-cost addition to a working motion, not a standalone strategy — fine as a checkbox, set it up once paying customers ask for it.
#Recommended sequencing
Run open-source and research-credibility together from day one — they're nearly free and they're the only two motions a solo technical founder can execute without a sales hire. Use the first 12-18 months of inbound and community traction to land 3-5 unpaid or lightly-paid EU design partners specifically in CRA/NIS2/DORA-exposed sectors, convert those into the first paid logos, and only then hire a first commercial person to run the compliance-led enterprise motion at scale. Channel and marketplace come after that, funded by Series A, not before.
#First 100 customers
The realistic path to the first 100 customers looks nothing like the eventual enterprise motion:
- Customers 1-20: free-tier open-source users who convert because the product genuinely saves them time — small-to-mid EU startups and scale-ups, self-serve, $25-60/dev/mo tier. This validates the product works before any sales conversation happens.
- Customers 20-40: design partners, ideally 3-5 named logos in CRA/NIS2-exposed sectors (see below) who get early access, heavy founder involvement, and meaningfully discounted pricing in exchange for real feedback and a case study. This is the Who funds this and at what price research's own advice for what makes a company fundable in 2026 — "a paid CISO design-partner pilot with a signed ROI memo" is described as the defining seed artifact, worth more to investors than raw ARR from mid-market accounts. Treat it as equally true for the product's own credibility with the next 60 customers.
- Customers 40-100: the compliance-pull motion starts working on its own — design-partner case studies plus the CRA/NIS2 deadline pressure generate inbound from similar-profile EU companies without a large outbound sales effort. This is where the first dedicated sales hire pays for themselves.
#Design-partner strategy
Target sectors where NIS2's "essential"/"important" categories create board-level urgency: financial infrastructure, digital infrastructure, health, and mid-market German Mittelstand companies newly in scope under NIS2UmsuCG (an estimated 15,000-30,000+ entities, most of which previously ran security as a part-time IT function per Germany: §202c and the Berlin question). These buyers have an unusually strong reason to say yes to an early-stage vendor: they need compliance evidence now, and hands-on founder support is often more attractive to a newly-regulated Mittelstand company than a slow sales cycle with an established but impersonal vendor.
#What to give away free, and why
Give away detection, sell fixing and compliance evidence. Who buys, and what they pay shows the market has already converged on this split — Corgea, Semgrep, and Aikido all meter AI-fix volume as a paid consumption unit layered on free or cheap scanning. A free scanner is also the cheapest possible top-of-funnel (see Unit economics and the compute bill for why it stays cheap to serve at real volume), and it's the mechanism that makes motions #1 and #2 the same funnel rather than two separate efforts. Stay paid: autofix, the SOC 2/DPA/BYOK enterprise package, and the specific artifacts a compliance buyer needs — a CRA Article 14-ready incident report, an SBOM tied to continuous vulnerability matching, evidence of "state of the art" secure development for an Annex I audit.
#How research output feeds the funnel
A lab publishing results against Cyber benchmarks and evals and AIxCC: the closest thing to a proof-style harnesses, or contributing to The open-source stack tooling, does three things at once: generates inbound from technical buyers who trust demonstrated results over vendor claims (directly answering the false-positive skepticism in Who buys, and what they pay); builds fundraising credibility, since Who funds this and at what price shows 2026 investors price pedigree and technical depth above early revenue; and opens a pipeline into design partners, since frontier-lab-adjacent credibility (the RunSybil/XBOW pattern) makes cold outreach land differently. Treat it as a GTM line item, not a side project — see The first 90 days for sequencing against product milestones.
#The EU angle: sovereignty as a wedge
EU data-residency and sovereignty preference is not a compliance checkbox — it's a genuine, exploitable go-to-market wedge against US incumbents (Snyk, GitHub/Microsoft, Checkmarx) for exactly the buyer segment the compliance-led motion targets.
- BYOK and self-hosting are Enterprise-tier table stakes — ZeroPath, Corgea, and Aikido gate them behind Enterprise specifically because regulated EU buyers ask "does our code leave our boundary to a third-party LLM provider, and can we turn that off" Who buys, and what they pay. Building this in from day one, rather than bolting it on at Series A, is a durable advantage in exactly the conversations that matter most.
- EU non-dilutive funding access compounds the story — ECCC/NCC-DE (hosted at BSI), Cyberagentur, SPRIND, and NATO Innovation Fund access as an EU-domiciled, NATO-country dual-use startup are real paths a US-incorporated competitor doesn't have Who funds this and at what price. Being visibly EU-domiciled and EU-hosted is a funding argument, not just a sales one.
- The regulatory calendar is the pitch. "EU-domiciled, EU-hosted, built for CRA/NIS2/DORA compliance evidence" is a more concrete, more urgent proposition to a German Mittelstand CISO in late 2026 than a US vendor retrofitting EU hosting can currently match — EU regulation as a demand engine and Germany: §202c and the Berlin question lay out why this 2026-2027 window is unusually favorable.
This wedge has a shelf life. Every US incumbent in this category already knows EU data residency is a requirement — Snyk, Checkmarx, and GHAS all list EU-region hosting or on-prem as Enterprise features. The advantage here is not "we can offer EU hosting and they can't" — it's speed, focus, and specificity: a company built EU-native from day one, with a founder story and product roadmap centered on CRA/NIS2 rather than a US roadmap with an EU hosting checkbox added later, wins on trust and depth of implementation, not on being the only option. That advantage narrows every quarter US vendors spend catching up.
#What this means for us
- Run open-source and research-credibility motions in parallel starting immediately — they're the only two a solo founder can execute without a sales hire, and they compound with each other.
- Don't attempt the channel or marketplace motions before Series A; they require reference customers and headcount the company won't have yet.
- Prioritize SOC 2 Type II and EU-region/self-hosted deployment ahead of the first enterprise conversation, not after — the compliance-led motion is the highest-value path available, but it's gated on having these in place first.
- Target 3-5 design partners specifically in NIS2/CRA-exposed German Mittelstand and financial-infrastructure sectors — they have board-level urgency and a real reason to work with an early-stage vendor.
- Give away detection free, charge for fixing and for compliance-evidence artifacts (CRA Article 14 reports, SBOM continuity) — the market has already converged on this split, don't reinvent it.
- Treat published benchmark/research output as a GTM line item, not a side project — it's the cheapest credibility lever available and it feeds fundraising, inbound, and design-partner conversations simultaneously.