DesignKompanie

A studio service

Customer security notices and advisories each customer told about their own units.

The CRA asks manufacturers to inform the users affected by an actively exploited vulnerability, and to send security updates with advisory messages. We build the app that turns one advisory into a notice for each affected customer, listing their own units and what to do, and tracks who has read it and who has updated.

Customer security notices and advisories

The regulation, quoted

Article 14(8)

The manufacturer “shall inform the impacted users of the product with digital elements, and where appropriate all users, of that vulnerability or incident and, where necessary, of any risk mitigation and corrective measures that the users can deploy … where appropriate in a structured, machine-readable format that is easily automatically processable.”
Source: Regulation (EU) 2024/2847, Article 14(8).

Annex I, Part II

Manufacturers shall “ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed … free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.”
Source: Regulation (EU) 2024/2847, Annex I, Part II, point 8.

EUR 15 m or 2.5 %

“Non-compliance with the essential cybersecurity requirements set out in Annex I and the obligations set out in Articles 13 and 14 shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover for the preceding financial year, whichever is higher.”
Source: Regulation (EU) 2024/2847, Article 64(2).

Quoted verbatim from Regulation (EU) 2024/2847 as published on EUR-Lex. We add no estimates of our own.

What it looks like

Advisory SA-2026-07 — Controller C200 firmware 4.2.x (sample)

Customers

57

Notices sent

49

Read

31

Units updated

612 of 1,284

CustomerContactUnitsChannelStatus
Customer A (sample)Security contact412Portal + CSAFRead
Distributor B (sample)Distribution desk301Portal + CSAFSent
Customer C (sample)Service manager96EmailSent
Customer E (sample)—22EmailMissing contact

Interface concept with invented sample data, shown to illustrate the design. It is not a screenshot of a live system.

How it connects

SAP S/4HANA

  • Materials, serial numbers, equipment
  • Deliveries, customers, ship-to countries
  • Core left standard, nothing changed inside
released APIs only

The app, in your tenancy

  • SAP BTP, Azure or AWS, your region
  • SBOMs, vulnerability data, audit trail
  • Read-only from SAP in a Pilot
scoped access

People and other systems

  • Product security and service teams
  • Your build pipeline and SBOM files
  • Customers, each to their own units

SAP's clean-core rule, quoted: “Extensions must be developed using only released local or remote public SAP APIs, BAdIs, or ABAP RESTful application programming model business object (BO) extension points.” SAP PRESS, SAP S/4HANA Clean Core: Principles, Benefits, and Best Practices.

N° 01What SAP already holds

We start from SAP, not against it.

SAP S/4HANA holds your customers, their contacts and what they bought. This app turns an advisory into a notice for each customer, using that data and the affected-customer finder. The app runs beside SAP and reads and writes it only through released APIs, leaving the core standard.

N° 02Where it helps

Four situations this app is built for.

01

Telling the right customers

Each notice goes to the customers whose units are affected and lists their own serial numbers.

02

Missing or outdated contacts

Customers without a security contact in SAP are flagged before the notice goes out.

03

Readable by people and machines

Each advisory is published as a document for people and, where you choose, as a CSAF file for automated processing.

04

Knowing who has acted

Read status and update status per customer, from the portal and your field-update records.

N° 03What the app covers

Scope, in plain terms.

01

Notice per customer

The advisory plus that customer's own affected units and the actions to take.

02

Channels

Email, a page on your customer portal, and a CSAF file per advisory.

03

Tracking

Sent, read and units updated, per customer.

04

Templates

Per product line, approved once by your product security and legal teams.

N° 04For each person in the decision

One page, six readers.

01

Product security lead

The scope above, three fixed-scope packages with prices, and a read-only Pilot on one product line before committing.

02

Compliance and legal

The regulation quoted word for word with its source, named sign-off on every step, and records you can export. What to report stays your decision.

03

IT and your SAP team

Released SAP APIs only, no changes inside SAP, one least-privilege technical user, deployed in your own tenancy and region.

04

Service and customer teams

Customer lists and notices drawn from the same records, with each customer seeing only their own units.

05

Procurement

Fixed scope and price per package, a written not-included list, and our vendor questionnaire answered in full on request.

06

Finance

The price shown is ours. SAP licences, including any SAP Digital Access for documents created in SAP, and hosting are yours and are listed as not included.

N° 05The Pilot, week by week

Eight to ten weeks, read-only from SAP.

01

Weeks 1–2: scope and access

Requirements workshop, the list of SAP APIs to be read, a technical user from your SAP team, and sample SBOMs and data agreed.

02

Weeks 3–5: build

The app built in your tenancy against your SAP test system, with a working demo every week.

03

Weeks 6–7: your data

Connected to the agreed SAP data and SBOM files, tested by your users, findings fixed.

04

Weeks 8–10: live on one product line

Go-live for up to 25 users, a handover session, and a written decision paper for the Production package.

N° 06Where our work ends

Software, not legal advice.

We build and run the software. Whether a product is in scope, how it is classified, and what to report and when are decisions for your product security and legal teams. We do not carry out conformity assessments or act as a notified body, and we do not submit reports: the manufacturer notifies via the single reporting platform.

N° 07AI assists

AI drafts, a named person decides.

Every AI output goes to a named person who edits and approves it. Nothing is submitted or sent to a customer by AI alone, models run in your tenancy, and your data is not used to train shared models.

01

Notice drafts

Drafts each customer's notice from the advisory, including other languages, for a person to approve before sending.

02

Replies to customer questions

Drafts answers from the published advisory only, for your team to check and send.

N° 08Investment

Pilot, production, or audit-ready.

Pilot

From $26,000

One product line, read from SAP through released APIs, live in 8–10 weeks.

  • Notices per customer for one product line, sent by email
  • Missing-contact check against SAP customer data
  • Read-only connection to SAP S/4HANA (OData APIs and CDS views), no core changes
  • Audit trail on every record, role-based access, SSO with your identity provider
  • One product line, up to 25 named users
  • Not included: write-back to SAP, records for your CRA documentation, legal advice, SAP BTP licences
Start the project
Recommended

Production

From $44,000

Every product line in scope, two-way with SAP and your build pipeline.

  • Everything in Pilot
  • Customer portal page and CSAF file per advisory
  • Read and update tracking per customer
  • Two-way integration through SAP APIs or SAP Integration Suite, clean-core compliant
  • Digital Access check with your SAP licence team before any write-back is switched on
  • Up to 250 users across sites
  • 60 days of hypercare after go-live
  • Not included: records for your CRA documentation, legal advice, conformity assessment, SAP or BTP licences (including any SAP Digital Access your contract requires for documents created in SAP)
Start the project

Audit-ready

From $62,000

Built and documented so its records can support your CRA documentation.

  • Everything in Production
  • Written description of how the app supports your vulnerability handling, for your documentation
  • Time-stamped record exports with names and sign-offs, kept for the period you set
  • Security testing of the app: dependency and code scans, support for your penetration test
  • An SBOM of the app itself, in CycloneDX or SPDX
  • Not included: legal advice, conformity assessment or notified-body work, submission to the single reporting platform (done by you), SAP licences
Start the project

Before you buy

What you get

  • An independent app that connects to SAP only through SAP's released APIs
  • A read-only Pilot that creates nothing in SAP, so it carries no SAP licence exposure
  • Records you can export for your CRA documentation

What we don’t do

  • Legal advice, conformity assessment or notified-body work
  • Submission of reports to the single reporting platform, which stays with you
  • SAP licences, or SAP Digital Access for documents a two-way build creates in SAP

DesignKompanie is an independent studio and is not affiliated with, endorsed by or a partner of SAP SE. SAP and SAP S/4HANA are trademarks of SAP SE.

N° 09Questions

The answers we give most often.

What is CSAF?
The Common Security Advisory Framework, an OASIS standard for machine-readable security advisories. Article 14(8) asks for the information to users, where appropriate, in a structured, machine-readable format.
Do customers see only their own units?
Yes. On the portal each customer sees only their own units, enforced in the data layer, with every access logged.
Who approves a notice?
Your team. Templates are approved once per product line, and each advisory is approved before any notice is sent.
Are you an SAP partner?
No. We are an independent studio. We build beside SAP using its released APIs and work with your SAP partner, who stays responsible for SAP itself. If you need the integration certified by SAP, we scope that into the project.

Start your book

Ready to scope this app?

Tell us your products, where serial numbers and firmware versions are recorded, and who handles product security. You'll get a scoped plan and a fixed price within two business days.

CRA Customer Security Notices & Advisories