A studio service
CRA vulnerability reporting workspace every deadline, signed off by a person.
Since 11 September 2026, a manufacturer who becomes aware of an actively exploited vulnerability in its product has 24 hours for an early warning and 72 hours for a notification, followed by a final report. We build the workspace where your team runs that: the clock, the drafts filled from your data, a named person who signs off, and a record of everything.

The regulation, quoted
24 hours
The manufacturer shall submit “an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available”.
72 hours
“… unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken …”
14 days
“… a final report, no later than 14 days after a corrective or mitigating measure is available, including at least … a description of the vulnerability, including its severity and impact”.
Quoted verbatim from Regulation (EU) 2024/2847 as published on EUR-Lex. We add no estimates of our own.
What it looks like
Aware since
Tue 09:40
Early warning due
Wed 09:40
Notification due
Fri 09:40
Steps signed
1 of 4
| Step | Deadline | Owner | Content | Status |
|---|---|---|---|---|
| Early warning | 24 hours | Product security | Product, Member States | Signed |
| Vulnerability notification | 72 hours | Product security | Product, exploit, measures taken | Draft |
| Final report | 14 days after the fix is out | Product security | Description, severity, impact | Open |
| Customer notice | With the fix | Customer service | Units and actions to take | Draft |
Interface concept with invented sample data, shown to illustrate the design. It is not a screenshot of a live system.
How it connects
SAP S/4HANA
- Materials, serial numbers, equipment
- Deliveries, customers, ship-to countries
- Core left standard, nothing changed inside
The app, in your tenancy
- SAP BTP, Azure or AWS, your region
- SBOMs, vulnerability data, audit trail
- Read-only from SAP in a Pilot
People and other systems
- Product security and service teams
- Your build pipeline and SBOM files
- Customers, each to their own units
SAP's clean-core rule, quoted: “Extensions must be developed using only released local or remote public SAP APIs, BAdIs, or ABAP RESTful application programming model business object (BO) extension points.” SAP PRESS, SAP S/4HANA Clean Core: Principles, Benefits, and Best Practices.
N° 01What SAP already holds
We start from SAP, not against it.
SAP S/4HANA holds the product, customer and delivery data a notification draws on. You submit the notification through the single reporting platform; this app prepares it, runs the deadlines and keeps the record. The app runs beside SAP and reads and writes it only through released APIs, leaving the core standard.
N° 02Where it helps
Four situations this app is built for.
01
Deadlines that start at awareness
Your team records when the manufacturer became aware. The 24-hour and 72-hour dates are set from that time and shown to everyone involved; the 14-day date is set once a corrective or mitigating measure is available.
02
Information spread across teams
Product, affected units, Member States and measures are pulled into one draft from the finder and the SBOM link.
03
Who approved what
Each step has a named approver. Nothing is marked as submitted without their sign-off, recorded with name and time.
04
Showing it later
Every draft, change, approval and submission time is kept as a record you can export.
N° 03What the app covers
Scope, in plain terms.
01
Case record
Awareness time, product, vulnerability, owner and approver.
02
Deadline clock
24-hour, 72-hour and 14-day dates with reminders to the owner and approver.
03
Drafts
Early warning, notification and final report prepared from the case, the finder and the SBOM link.
04
Sign-off
Named, time-stamped approval before a step is marked as submitted.
N° 04For each person in the decision
One page, six readers.
01
Product security lead
The scope above, three fixed-scope packages with prices, and a read-only Pilot on one product line before committing.
02
Compliance and legal
The regulation quoted word for word with its source, named sign-off on every step, and records you can export. What to report stays your decision.
03
IT and your SAP team
Released SAP APIs only, no changes inside SAP, one least-privilege technical user, deployed in your own tenancy and region.
04
Service and customer teams
Customer lists and notices drawn from the same records, with each customer seeing only their own units.
05
Procurement
Fixed scope and price per package, a written not-included list, and our vendor questionnaire answered in full on request.
06
Finance
The price shown is ours. SAP licences, including any SAP Digital Access for documents created in SAP, and hosting are yours and are listed as not included.
N° 05The Pilot, week by week
Eight to ten weeks, read-only from SAP.
01
Weeks 1–2: scope and access
Requirements workshop, the list of SAP APIs to be read, a technical user from your SAP team, and sample SBOMs and data agreed.
02
Weeks 3–5: build
The app built in your tenancy against your SAP test system, with a working demo every week.
03
Weeks 6–7: your data
Connected to the agreed SAP data and SBOM files, tested by your users, findings fixed.
04
Weeks 8–10: live on one product line
Go-live for up to 25 users, a handover session, and a written decision paper for the Production package.
N° 06Where our work ends
Software, not legal advice.
We build and run the software. Whether a product is in scope, how it is classified, and what to report and when are decisions for your product security and legal teams. We do not carry out conformity assessments or act as a notified body, and we do not submit reports: the manufacturer notifies via the single reporting platform.
N° 07AI assists
AI drafts, a named person decides.
Every AI output goes to a named person who edits and approves it. Nothing is submitted or sent to a customer by AI alone, models run in your tenancy, and your data is not used to train shared models.
01
Draft text
Drafts each step from the case record for the approver to edit and sign. It never submits anything.
02
Case timeline
Builds a timeline from the case record for the final report, checked by the owner.
N° 08Investment
Pilot, production, or audit-ready.
Pilot
From $28,000
One product line, read from SAP through released APIs, live in 8–10 weeks.
- Case record, deadline clock and reminders
- Early warning and notification drafts with named sign-off
- Read-only connection to SAP S/4HANA (OData APIs and CDS views), no core changes
- Audit trail on every record, role-based access, SSO with your identity provider
- One product line, up to 25 named users
- Not included: write-back to SAP, records for your CRA documentation, legal advice, SAP BTP licences
Production
From $46,000
Every product line in scope, two-way with SAP and your build pipeline.
- Everything in Pilot
- Drafts filled from the affected-customer finder
- Final report draft and full export of each case
- Two-way integration through SAP APIs or SAP Integration Suite, clean-core compliant
- Digital Access check with your SAP licence team before any write-back is switched on
- Up to 250 users across sites
- 60 days of hypercare after go-live
- Not included: records for your CRA documentation, legal advice, conformity assessment, SAP or BTP licences (including any SAP Digital Access your contract requires for documents created in SAP)
Audit-ready
From $66,000
Built and documented so its records can support your CRA documentation.
- Everything in Production
- Written description of how the app supports your vulnerability handling, for your documentation
- Time-stamped record exports with names and sign-offs, kept for the period you set
- Security testing of the app: dependency and code scans, support for your penetration test
- An SBOM of the app itself, in CycloneDX or SPDX
- Not included: legal advice, conformity assessment or notified-body work, submission to the single reporting platform (done by you), SAP licences
Before you buy
What you get
- An independent app that connects to SAP only through SAP's released APIs
- A read-only Pilot that creates nothing in SAP, so it carries no SAP licence exposure
- Records you can export for your CRA documentation
What we don’t do
- Legal advice, conformity assessment or notified-body work
- Submission of reports to the single reporting platform, which stays with you
- SAP licences, or SAP Digital Access for documents a two-way build creates in SAP
DesignKompanie is an independent studio and is not affiliated with, endorsed by or a partner of SAP SE. SAP and SAP S/4HANA are trademarks of SAP SE.
N° 09Questions
The answers we give most often.
- Does it submit to ENISA for us?
- No. The CRA has the manufacturer notify via the single reporting platform. The workspace prepares the content and keeps the record; your approver submits through the platform and records the time.
- When does the clock start?
- Article 14(2)(a) counts 24 hours from the manufacturer becoming aware. The workspace starts from the awareness time your team records; setting that time is your team's judgement.
- Is this legal advice?
- No. We build the software. What to report, and when, is decided by your product security and legal teams.
- Are you an SAP partner?
- No. We are an independent studio. We build beside SAP using its released APIs and work with your SAP partner, who stays responsible for SAP itself. If you need the integration certified by SAP, we scope that into the project.
Start your book
Ready to scope this app?
Tell us your products, where serial numbers and firmware versions are recorded, and who handles product security. You'll get a scoped plan and a fixed price within two business days.
