A studio service
SBOM management linked to SAP serial numbers what runs in every unit you shipped.
An SBOM tells you what is inside firmware 4.2.1. It does not tell you which of your units run 4.2.1 today. We build the link: the SBOM of every release, joined to the serial numbers in SAP and to every update applied in the field, so any unit, product line or customer can be checked against a new vulnerability.

The regulation, quoted
Annex I, Part II
Manufacturers shall “identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products”.
5 years
“… the support period shall be at least five years. Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time.”
Annex I, Part II
Manufacturers shall, “in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates”.
Quoted verbatim from Regulation (EU) 2024/2847 as published on EUR-Lex. We add no estimates of our own.
What it looks like
Firmware
4.2.1
Components
312
Open findings
2
Support until
Mar 2031
| Component | Version | Origin | Finding | Status |
|---|---|---|---|---|
| tls-lib | 3.0.13 | Third party | Sample-CVE-1 | Affected |
| web-ui | 2.8.0 | In-house | Sample-CVE-2 | Review |
| rtos-kernel | 10.4.6 | Third party | — | OK |
| json-parser | 1.2.9 | Third party | — | OK |
| modem-fw | 7.1 | Supplier | SBOM missing | Missing |
Interface concept with invented sample data, shown to illustrate the design. It is not a screenshot of a live system.
How it connects
SAP S/4HANA
- Materials, serial numbers, equipment
- Deliveries, customers, ship-to countries
- Core left standard, nothing changed inside
The app, in your tenancy
- SAP BTP, Azure or AWS, your region
- SBOMs, vulnerability data, audit trail
- Read-only from SAP in a Pilot
People and other systems
- Product security and service teams
- Your build pipeline and SBOM files
- Customers, each to their own units
SAP's clean-core rule, quoted: “Extensions must be developed using only released local or remote public SAP APIs, BAdIs, or ABAP RESTful application programming model business object (BO) extension points.” SAP PRESS, SAP S/4HANA Clean Core: Principles, Benefits, and Best Practices.
N° 01What SAP already holds
We start from SAP, not against it.
SAP S/4HANA manages your materials, bills of material and serial numbers, and can keep an equipment record for each serialised unit. This app adds the software side: the SBOM of each release, linked to those serial numbers. The app runs beside SAP and reads and writes it only through released APIs, leaving the core standard.
N° 02Where it helps
Four situations this app is built for.
01
SBOMs that stop at the release
The SBOM describes a firmware release, not the units running it. The link to SAP serial numbers closes that gap.
02
Field updates not recorded against the unit
Updates applied in the field are recorded against each serial number, so the record shows what the unit runs now, not only what it shipped with.
03
Support periods kept in a spreadsheet
The end of each product's support period is held with the product and shown on every unit and report.
04
Supplier components without an SBOM
Bought-in modules are tracked by supplier and version, and flagged until the supplier's SBOM arrives.
N° 03What the app covers
Scope, in plain terms.
01
SBOM import
CycloneDX and SPDX files per release, from your build pipeline or uploaded by your team.
02
Release-to-unit link
Each serial number linked to the release it shipped with and every update applied since.
03
Vulnerability matching
Components checked against public vulnerability records, including CVE entries and the CISA Known Exploited Vulnerabilities catalogue.
04
Support periods
End of support per product, shown on each unit and in exports.
N° 04For each person in the decision
One page, six readers.
01
Product security lead
The scope above, three fixed-scope packages with prices, and a read-only Pilot on one product line before committing.
02
Compliance and legal
The regulation quoted word for word with its source, named sign-off on every step, and records you can export. What to report stays your decision.
03
IT and your SAP team
Released SAP APIs only, no changes inside SAP, one least-privilege technical user, deployed in your own tenancy and region.
04
Service and customer teams
Customer lists and notices drawn from the same records, with each customer seeing only their own units.
05
Procurement
Fixed scope and price per package, a written not-included list, and our vendor questionnaire answered in full on request.
06
Finance
The price shown is ours. SAP licences, including any SAP Digital Access for documents created in SAP, and hosting are yours and are listed as not included.
N° 05The Pilot, week by week
Eight to ten weeks, read-only from SAP.
01
Weeks 1–2: scope and access
Requirements workshop, the list of SAP APIs to be read, a technical user from your SAP team, and sample SBOMs and data agreed.
02
Weeks 3–5: build
The app built in your tenancy against your SAP test system, with a working demo every week.
03
Weeks 6–7: your data
Connected to the agreed SAP data and SBOM files, tested by your users, findings fixed.
04
Weeks 8–10: live on one product line
Go-live for up to 25 users, a handover session, and a written decision paper for the Production package.
N° 06Where our work ends
Software, not legal advice.
We build and run the software. Whether a product is in scope, how it is classified, and what to report and when are decisions for your product security and legal teams. We do not carry out conformity assessments or act as a notified body, and we do not submit reports: the manufacturer notifies via the single reporting platform.
N° 07AI assists
AI drafts, a named person decides.
Every AI output goes to a named person who edits and approves it. Nothing is submitted or sent to a customer by AI alone, models run in your tenancy, and your data is not used to train shared models.
01
Component name matching
Suggests matches where a component's name in your SBOM differs from its name in public vulnerability records. A person confirms each match.
02
Supplier release notes
Reads supplier release notes and flags likely security fixes for your team to review.
N° 08Investment
Pilot, production, or audit-ready.
Pilot
From $34,000
One product line, read from SAP through released APIs, live in 8–10 weeks.
- SBOM import for one product line
- Link from SAP serial numbers to the release each unit shipped with
- Read-only connection to SAP S/4HANA (OData APIs and CDS views), no core changes
- Audit trail on every record, role-based access, SSO with your identity provider
- One product line, up to 25 named users
- Not included: write-back to SAP, records for your CRA documentation, legal advice, SAP BTP licences
Production
From $56,000
Every product line in scope, two-way with SAP and your build pipeline.
- Everything in Pilot
- Field-update records linked to each serial number
- Vulnerability matching and support-period tracking across product lines
- Two-way integration through SAP APIs or SAP Integration Suite, clean-core compliant
- Digital Access check with your SAP licence team before any write-back is switched on
- Up to 250 users across sites
- 60 days of hypercare after go-live
- Not included: records for your CRA documentation, legal advice, conformity assessment, SAP or BTP licences (including any SAP Digital Access your contract requires for documents created in SAP)
Audit-ready
From $78,000
Built and documented so its records can support your CRA documentation.
- Everything in Production
- Written description of how the app supports your vulnerability handling, for your documentation
- Time-stamped record exports with names and sign-offs, kept for the period you set
- Security testing of the app: dependency and code scans, support for your penetration test
- An SBOM of the app itself, in CycloneDX or SPDX
- Not included: legal advice, conformity assessment or notified-body work, submission to the single reporting platform (done by you), SAP licences
Before you buy
What you get
- An independent app that connects to SAP only through SAP's released APIs
- A read-only Pilot that creates nothing in SAP, so it carries no SAP licence exposure
- Records you can export for your CRA documentation
What we don’t do
- Legal advice, conformity assessment or notified-body work
- Submission of reports to the single reporting platform, which stays with you
- SAP licences, or SAP Digital Access for documents a two-way build creates in SAP
DesignKompanie is an independent studio and is not affiliated with, endorsed by or a partner of SAP SE. SAP and SAP S/4HANA are trademarks of SAP SE.
N° 09Questions
The answers we give most often.
- Do we need a new SBOM tool?
- No. If your build pipeline already produces SBOMs in CycloneDX or SPDX, we import them. If it does not, we quote setting that up separately.
- What does the CRA say about SBOMs?
- Annex I, Part II, point 1 asks manufacturers to draw up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies. The exact wording is quoted on this page with its source. Whether your products are in scope is for your legal team to decide.
- Where is the link stored?
- In the app, in your tenancy. Serial numbers are read from SAP. If your SAP team wants the release on the SAP equipment record as well, that is a write-back in the Production package.
- Are you an SAP partner?
- No. We are an independent studio. We build beside SAP using its released APIs and work with your SAP partner, who stays responsible for SAP itself. If you need the integration certified by SAP, we scope that into the project.
Start your book
Ready to scope this app?
Tell us your products, where serial numbers and firmware versions are recorded, and who handles product security. You'll get a scoped plan and a fixed price within two business days.
