DesignKompanie

A studio service

Cyber Resilience Act apps for SAP S/4HANA the 24-hour questions, answered from your data.

If you make connected products and run SAP S/4HANA, the Cyber Resilience Act's reporting duty has applied since 11 September 2026. An actively exploited vulnerability needs an early warning within 24 hours, naming where applicable the Member States where the product was made available, and the affected users must be informed. Your SBOMs know what is inside each release; SAP knows which serial numbers went to which customer and country. We build four apps beside SAP that join the two.

Cyber Resilience Act apps for manufacturers that run SAP S/4HANA

The regulation, quoted

11 Sep 2026

The Regulation “shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026”. Article 14 contains the reporting obligations.
Source: Regulation (EU) 2024/2847, Article 71(2).

24 hours

The manufacturer shall submit “an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available”.
Source: Regulation (EU) 2024/2847, Article 14(2)(a).

Annex I, Part II

Manufacturers shall “identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products”.
Source: Regulation (EU) 2024/2847, Annex I, Part II, point 1.

Article 14(8)

The manufacturer “shall inform the impacted users of the product with digital elements, and where appropriate all users, of that vulnerability or incident and, where necessary, of any risk mitigation and corrective measures that the users can deploy … where appropriate in a structured, machine-readable format that is easily automatically processable.”
Source: Regulation (EU) 2024/2847, Article 14(8).

Article 2(1)

“This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.”
Source: Regulation (EU) 2024/2847, Article 2(1).

EUR 15 m or 2.5 %

“Non-compliance with the essential cybersecurity requirements set out in Annex I and the obligations set out in Articles 13 and 14 shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover for the preceding financial year, whichever is higher.”
Source: Regulation (EU) 2024/2847, Article 64(2).

Quoted verbatim from Regulation (EU) 2024/2847 as published on EUR-Lex. We add no estimates of our own.

How it connects

SAP S/4HANA

  • Materials, serial numbers, equipment
  • Deliveries, customers, ship-to countries
  • Core left standard, nothing changed inside
released APIs only

The app, in your tenancy

  • SAP BTP, Azure or AWS, your region
  • SBOMs, vulnerability data, audit trail
  • Read-only from SAP in a Pilot
scoped access

People and other systems

  • Product security and service teams
  • Your build pipeline and SBOM files
  • Customers, each to their own units

SAP's clean-core rule, quoted: “Extensions must be developed using only released local or remote public SAP APIs, BAdIs, or ABAP RESTful application programming model business object (BO) extension points.” SAP PRESS, SAP S/4HANA Clean Core: Principles, Benefits, and Best Practices.

N° 01Who this is for

Manufacturers of connected products, running SAP S/4HANA.

These apps are for manufacturers whose products connect to a device or network, who ship serialised units and run SAP S/4HANA. Whether a given product falls under the CRA is for your legal team to decide; the scope article is quoted above with its source.

N° 02What SAP already holds

SAP knows the units. Your SBOMs know the software.

SAP S/4HANA manages your materials, serial numbers, deliveries and customers, and can keep an equipment record for each serialised unit. Your build pipeline knows what is inside each firmware release.

The reporting questions need both at once: which units carry the vulnerable component, which customers have them, and in which countries. We build that join as apps beside SAP that read and write it only through released APIs, upgrade-safe, on SAP BTP or your cloud.

N° 03The apps

Four apps, one 24-hour question.

01

SBOM linked to serial numbers, from $34,000

Import the SBOM of every firmware release and link it to the serial numbers in SAP S/4HANA, so each unit shows its components, open vulnerabilities and support period.

02

Affected-customer finder, from $32,000

Start from a vulnerability or a component version and get the affected releases, serial numbers, customers and ship-to countries, using SAP S/4HANA delivery data.

03

24-hour reporting workspace, from $28,000

A workspace for CRA Article 14 reporting: the deadline clock from the moment of awareness, drafts filled from SAP and SBOM data, named sign-off and a full record.

04

Customer security notices, from $26,000

Turn one security advisory into a notice for each affected customer, listing their own serial numbers and actions, with CSAF output and tracking of who has read and updated.

N° 04Where our work ends

Software, not legal advice.

We build and run the software. Whether a product is in scope, how it is classified, and what to report and when are decisions for your product security and legal teams. We do not carry out conformity assessments or act as a notified body, and we do not submit reports: under Article 14(1) the manufacturer notifies via the single reporting platform.

N° 05AI, with a person signing

AI drafts, a named person decides.

AI matches component names, reads supplier release notes and drafts notifications and customer notices. Every output goes to a named person who edits and approves it; nothing is submitted to the reporting platform or sent to a customer by AI alone. Models run in your tenancy, and your data is not used to train shared models.

N° 06Investment

Three ways to start.

CRA readiness assessment

$9,500

Three weeks to find where your data stands and what to build first.

  • Workshops with product security, engineering, service, IT and your SAP team
  • Map of where serial numbers, firmware versions, SBOMs and customer contacts are recorded today
  • A walk-through of one past or sample vulnerability against the 24-hour, 72-hour and 14-day steps
  • Integration and clean-core plan using released SAP APIs
  • Fixed price per app; fee credited against the first build
  • Not included: legal assessment of which products are in scope, any build, changes to your SAP configuration
Start the project
Recommended

24-hour response bundle

From $165,000

All four apps at the Production package level, on one shared core.

  • SBOM link, affected-customer finder, reporting workspace and customer notices at Production level
  • One shared core: identity, roles, audit trail, SAP connection
  • SAP plus your build pipeline, integrated once and shared
  • Up to 250 users across sites
  • 60 days of hypercare after go-live
  • Not included: Audit-ready documentation (quoted per app), legal advice, SAP licences
Start the project

Audit-ready line

From $235,000

All four apps at the Audit-ready level, rolled out in phases.

  • All four apps at the Audit-ready package level
  • Phased roadmap, one app live at a time
  • Quarterly review of the apps and their records for the first year
  • Not included: legal advice, conformity assessment or notified-body work, submission to the single reporting platform (done by you), SAP licences, hosting costs
Start the project

Before you buy

What you get

  • Independent apps that connect to SAP only through SAP's released APIs
  • Read-only Pilots that create nothing in SAP, so they carry no SAP licence exposure
  • Records you can export for your CRA documentation

What we don’t do

  • Legal advice, conformity assessment or notified-body work
  • Submission of reports to the single reporting platform, which stays with you
  • SAP licences, or SAP Digital Access for documents a two-way build creates in SAP

DesignKompanie is an independent studio and is not affiliated with, endorsed by or a partner of SAP SE. SAP and SAP S/4HANA are trademarks of SAP SE.

N° 07Questions

The answers we give most often.

Doesn't our SBOM tool already do this?
It knows what is inside each release and which releases carry a vulnerable component. The reporting questions also need the serial numbers, customers and countries, and that record is in SAP. These apps join the two, using the SBOM files your tools already produce.
Which deadlines apply now?
Under Article 71(2), the Regulation applies from 11 December 2027, but Article 14, which holds the reporting obligations, has applied since 11 September 2026. The wording is quoted on this page with its source.
Is this legal advice?
No. We build the software. Whether a product is in scope, how it is classified, and what to report and when are decisions for your product security and legal teams.
Do you submit reports for us?
No. Under Article 14(1) the manufacturer notifies via the single reporting platform. Our workspace prepares the content, runs the deadlines and keeps the record; your approver submits.
Are you an SAP partner?
No. We are an independent studio. We build beside SAP using its released APIs and work with your SAP partner, who stays responsible for SAP itself. If you need the integration certified by SAP, we scope that into the project.
Will this add SAP licence costs?
Reading data from SAP does not. When an outside app creates documents in SAP, SAP's Digital Access licence can apply. Pilots are read-only for that reason, and before any two-way build we check the position with your SAP licence team.
Where do the apps run?
On SAP BTP, or in your Azure or AWS tenancy if that is your standard. EU and Swiss data residency are available either way.
Can we start small?
Yes. Start with the readiness assessment, or a Pilot of one app on one product line, read-only from SAP, live in eight to ten weeks.

Start your book

Making connected products on SAP S/4HANA?

Tell us your products, where serial numbers and firmware versions are recorded, and who handles product security. We'll reply with an assessment plan and fixed prices within two business days.

Cyber Resilience Act Apps for SAP S/4HANA Manufacturers