A studio service
Affected-customer finder for vulnerabilities customers and countries in one search.
When a vulnerability in one of your products is being exploited, the first questions are which units carry it, who has them and in which countries. The CRA early warning asks, where applicable, for the Member States where the product has been made available. We build the finder that answers those questions from your SBOMs and your SAP deliveries, in one search.

The regulation, quoted
24 hours
The manufacturer shall submit “an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available”.
Article 14(1)
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator … and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.”
11 Sep 2026
The Regulation “shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026”. Article 14 contains the reporting obligations.
Quoted verbatim from Regulation (EU) 2024/2847 as published on EUR-Lex. We add no estimates of our own.
What it looks like
Releases
3
Units
1,284
Customers
57
Member States
9
| Customer | Ship-to country | Units | Firmware | Status |
|---|---|---|---|---|
| Customer A (sample) | Germany | 412 | 4.2.1 | Affected |
| Distributor B (sample) | Netherlands | 301 | 4.1.7 | Affected |
| Customer C (sample) | Austria | 96 | 4.2.0 | Affected |
| Customer D (sample) | Germany | 18 | 4.3.0 | Updated |
Interface concept with invented sample data, shown to illustrate the design. It is not a screenshot of a live system.
How it connects
SAP S/4HANA
- Materials, serial numbers, equipment
- Deliveries, customers, ship-to countries
- Core left standard, nothing changed inside
The app, in your tenancy
- SAP BTP, Azure or AWS, your region
- SBOMs, vulnerability data, audit trail
- Read-only from SAP in a Pilot
People and other systems
- Product security and service teams
- Your build pipeline and SBOM files
- Customers, each to their own units
SAP's clean-core rule, quoted: “Extensions must be developed using only released local or remote public SAP APIs, BAdIs, or ABAP RESTful application programming model business object (BO) extension points.” SAP PRESS, SAP S/4HANA Clean Core: Principles, Benefits, and Best Practices.
N° 01What SAP already holds
We start from SAP, not against it.
SAP S/4HANA records which serial numbers left on which delivery, to which customer and ship-to country. This app starts from a vulnerability and works back through that record. The app runs beside SAP and reads and writes it only through released APIs, leaving the core standard.
N° 02Where it helps
Four situations this app is built for.
01
From a vulnerability to a customer list
Search by vulnerability ID, component and version range, or release, and get the affected units, customers and countries together.
02
Member States for the early warning
Ship-to countries come from SAP deliveries, ready for the early warning.
03
Units sold through distributors
Units sold through distributors are shown under the distributor, with end customers where you hold that data.
04
Units already updated
Units whose recorded firmware already contains the fix are left out, with the reason shown.
N° 03What the app covers
Scope, in plain terms.
01
Search
By vulnerability ID, component and version range, or release.
02
Affected units
Releases, serial numbers, deliveries, customers and ship-to countries in one result.
03
Exclusions
Units already updated or outside the affected range, each with the reason shown.
04
Exports
Country list for the report, customer list for the notices, full list for your records.
N° 04For each person in the decision
One page, six readers.
01
Product security lead
The scope above, three fixed-scope packages with prices, and a read-only Pilot on one product line before committing.
02
Compliance and legal
The regulation quoted word for word with its source, named sign-off on every step, and records you can export. What to report stays your decision.
03
IT and your SAP team
Released SAP APIs only, no changes inside SAP, one least-privilege technical user, deployed in your own tenancy and region.
04
Service and customer teams
Customer lists and notices drawn from the same records, with each customer seeing only their own units.
05
Procurement
Fixed scope and price per package, a written not-included list, and our vendor questionnaire answered in full on request.
06
Finance
The price shown is ours. SAP licences, including any SAP Digital Access for documents created in SAP, and hosting are yours and are listed as not included.
N° 05The Pilot, week by week
Eight to ten weeks, read-only from SAP.
01
Weeks 1–2: scope and access
Requirements workshop, the list of SAP APIs to be read, a technical user from your SAP team, and sample SBOMs and data agreed.
02
Weeks 3–5: build
The app built in your tenancy against your SAP test system, with a working demo every week.
03
Weeks 6–7: your data
Connected to the agreed SAP data and SBOM files, tested by your users, findings fixed.
04
Weeks 8–10: live on one product line
Go-live for up to 25 users, a handover session, and a written decision paper for the Production package.
N° 06Where our work ends
Software, not legal advice.
We build and run the software. Whether a product is in scope, how it is classified, and what to report and when are decisions for your product security and legal teams. We do not carry out conformity assessments or act as a notified body, and we do not submit reports: the manufacturer notifies via the single reporting platform.
N° 07AI assists
AI drafts, a named person decides.
Every AI output goes to a named person who edits and approves it. Nothing is submitted or sent to a customer by AI alone, models run in your tenancy, and your data is not used to train shared models.
01
Questions in plain language
Ask "which customers in Austria run 4.2.x?" and get the answer from the same records, with the query shown so it can be checked.
02
Exposure summary
A draft summary of the affected units for the case record, checked by product security before use.
N° 08Investment
Pilot, production, or audit-ready.
Pilot
From $32,000
One product line, read from SAP through released APIs, live in 8–10 weeks.
- Search by vulnerability, component or release for one product line
- Affected serial numbers, customers and ship-to countries from SAP deliveries
- Read-only connection to SAP S/4HANA (OData APIs and CDS views), no core changes
- Audit trail on every record, role-based access, SSO with your identity provider
- One product line, up to 25 named users
- Not included: write-back to SAP, records for your CRA documentation, legal advice, SAP BTP licences
Production
From $52,000
Every product line in scope, two-way with SAP and your build pipeline.
- Everything in Pilot
- All product lines in scope, distributors shown separately
- Exports for the reporting workspace and for customer notices
- Two-way integration through SAP APIs or SAP Integration Suite, clean-core compliant
- Digital Access check with your SAP licence team before any write-back is switched on
- Up to 250 users across sites
- 60 days of hypercare after go-live
- Not included: records for your CRA documentation, legal advice, conformity assessment, SAP or BTP licences (including any SAP Digital Access your contract requires for documents created in SAP)
Audit-ready
From $74,000
Built and documented so its records can support your CRA documentation.
- Everything in Production
- Written description of how the app supports your vulnerability handling, for your documentation
- Time-stamped record exports with names and sign-offs, kept for the period you set
- Security testing of the app: dependency and code scans, support for your penetration test
- An SBOM of the app itself, in CycloneDX or SPDX
- Not included: legal advice, conformity assessment or notified-body work, submission to the single reporting platform (done by you), SAP licences
Before you buy
What you get
- An independent app that connects to SAP only through SAP's released APIs
- A read-only Pilot that creates nothing in SAP, so it carries no SAP licence exposure
- Records you can export for your CRA documentation
What we don’t do
- Legal advice, conformity assessment or notified-body work
- Submission of reports to the single reporting platform, which stays with you
- SAP licences, or SAP Digital Access for documents a two-way build creates in SAP
DesignKompanie is an independent studio and is not affiliated with, endorsed by or a partner of SAP SE. SAP and SAP S/4HANA are trademarks of SAP SE.
N° 09Questions
The answers we give most often.
- What if we don't record firmware per serial number today?
- The SBOM link app builds that record. Without it, the finder can estimate the affected units from production and delivery dates, and marks the result as an estimate.
- Does it cover units sold through distributors?
- Yes, under the distributor. End customers appear where you hold their data.
- How fast is a search?
- A search runs on data that is already linked, so it does not wait for exports from SAP or anyone's spreadsheet.
- Are you an SAP partner?
- No. We are an independent studio. We build beside SAP using its released APIs and work with your SAP partner, who stays responsible for SAP itself. If you need the integration certified by SAP, we scope that into the project.
Start your book
Ready to scope this app?
Tell us your products, where serial numbers and firmware versions are recorded, and who handles product security. You'll get a scoped plan and a fixed price within two business days.
