Cyber Resilience Act: Meeting reporting obligations securely and on time

Prepare your business for the CRA reporting requirements effective September 11, 2026 – with clear processes, centralized documentation, and personal experts by your side.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
non-binding consultation
Awarded for excellent customer reviews.
Capterra Logo mit 4,9 von 5 Sternen Bewertung.
Compliance that scales with you

Clarity before the deadline hits.

2,500+
Customers in 20+ Markets
11.09.2026
Effective Date of CRA Reporting Requirements
24h
Deadline for the first early warning
72h
Full CRA Report
THE CHALLENGE

When an incident occurs, the clock starts immediately.

Mere suspicion does not in itself trigger the reporting requirement. What matters is your initial assessment of the incident – and you must not delay that assessment in order to postpone the start of the reporting period. That is precisely why the assessment process must take place first.

Is the product even affected?

Installable software, apps, browser extensions, agents, and connected devices may fall within the scope of this regulation. What matters is the specific product – not your industry or business model. And what you delivered years ago also counts: There is no grandfather clause for reporting requirements.

24 hours leaves little room for error

As a general rule, an initial early warning must be issued within 24 hours. A more detailed report follows within 72 hours. Without a predefined procedure, half of that time is wasted trying to figure out who is actually in charge of making the decision.

Information is spread across multiple teams

The Development, Product, IT Security, Legal, and Management teams each have a portion of the necessary information. In an emergency, there is no time to gather it all.

What you can manage with heyData for CRA reporting requirements

From documentation to audit preparation: heyData bundles all ISMS components into one system.

Already in use at
PRODUCTS

Centralized product tracking

Document any installable software, apps, browser extensions, agents, and connected hardware that you make available on the EU market under your name.

Product directory
Scope of application
RESPONSIBILITIES

Define responsibilities clearly

Determine who will assess incidents, provide technical information, approve decisions, and coordinate the reporting process.

Responsibility
Escalation
REPORTING PROCESS

Prepare the reporting process

Clearly outline the process from internal detection through early warning, the main report, and the final report.

24h Early Warning
72h notification
DOCUMENTATION

Keep information readily available

Keep product data, vulnerability assessments, actions taken, and internal decisions recorded in a centralized and traceable manner.

Evidence
Audit Trail
OTHER FRAMEWORKS

Reuse ISO 27001 and NIS2

Use existing risks, measures, policies, and incident response processes as the organizational foundation for the CRA.

Framework Engine
Control Mapping
USER INFORMATION

Inform your customers in good time, too

In addition to reporting the incident to the authorities, you must notify the affected users immediately. We will work with you to prepare communication channels, approvals, and distribution lists.

Art. 14 Para. 8
Customer communication
Verlaufshintergrund mit Blau- und Grüntönen, der von oben links nach unten rechts verläuft.

From product scope to a prepared CRA reporting process

Kein unübersichtliches Compliance-Projekt. Sondern ein klarer Einstieg in die Anforderungen, die ab September 2026 tatsächlich gelten.

01

Categorize products

List the hardware and software products that you make available on the EU market under your name. Together, we'll determine which product components may be relevant to the CRA.

02

Define responsibilities

Determine which roles from Development, Product, IT Security, Legal, and Management will be involved in the reporting process.

03

Prepare reporting process

Structure the detection, assessment, escalation, and approval processes according to the 24-hour, 72-hour, and final deadlines.

04

Coordinated action in an emergency

heyData provides you with relevant documents such as SoA, risk reports, policies, and evidence in one central location. After certification, the platform supports you with ongoing monitoring and preparation for follow-up audits.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
START CRA-CHECK

No-obligation consultation · Clear scope

Our experts

Your Information Security Expert

Kevin Queisser

Domain Expert ISO Standards
  • ISO 27001
  • Internal Auditor
  • NIS2
  • DORA

Regina Frey

Head of Domain Experts
  • ISO 27001
  • Legal Expert
  • NIS2
  • GDPR
  • nFADP
  • UK GDPR

Nabiullah Waziri

Domain Expert ISO Standards
  • ISO 27001
  • Internal Auditor
  • NIS2
  • DORA

Melike Sevim

Junior Domain Expert Security
  • ISO 27001
  • Legal Expert
  • NIS2
  • GDPR

Adrian Matusiak

Junior Domain Expert ISO Standards
  • ISO 27001
  • Legal Expert
  • NIS2
  • DORA

Dominik Appelt

Domain Expert Privacy and Security
  • DPO
  • Legal Expert
  • GDPR
  • AI Act
WHY HEYDATA

What our customers say

2,500+ customers trust heyData with their information security.

IT Service Providers
17.08.2026

From customer requirements to the ISO 27001 security standard

How Sprintwerk successfully achieves ISO 27001 certification with heyData and integrates information security into their daily workflow.

Learn more

With heyData, we save time, reduce risks, and actively strengthen our customers' trust.

Lara Schimweg
Founder & CEO, Xeno GmbH

Thanks to the platform, we can handle onboarding centrally and efficiently.

Julia Streichan
Co-Founder, Sprintwerk GmbH

What sets heyData apart is its responsiveness and fast execution.

Sandra Scherzer
Legal Team, Bioland

The software helps us document all IT security measures relevant to data protection and review them regularly.

Dennis Kuhlmann
CEO, KUMA IT-Solutions GmbH

ISO 27001, NIS2, and CRA: What are the main differences?

Cyber Resilience Act
NIS2
ISO 27001
Focus
Product
Company/Operator
Organization/ISMS
Scope of impact
Products with digital elements
Specific entities and sectors
Organizations with an ISMS
Risk management
Product-specific
Company-related
ISMS-related
Reporting channel
ENISA Single Reporting Platform
National reporting authorities
No statutory incident reporting
Reuse in heyData
Product-specific supplement
Organization and incident processes
Risks, controls, and policies
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Request now

Security is part of our operations.

EU data sovereignty, in-house legal counsel, ISO 27001-certified hosting

European Provider

German company, European law, no access by non-EU authorities.

Regular Security Audits

Continuously audited and securely developed.

Encryption & Access Control

Encrypted data, clearly defined access.

Vetted Experts

An ISO 27001-ready management system.

Verlaufshintergrund mit Blau- und Grüntönen, der von oben links nach unten rechts verläuft.

Which of your products fall under the CRA?

In einem kurzen Check betrachten wir dein Produktportfolio, deine Rolle als Hersteller und deine bestehenden Sicherheitsprozesse. Du erhältst eine erste Einschätzung, was du vor dem 11. September 2026 vorbereiten solltest.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
START CRA CHECK

No obligation. Just a clear assessment.

FAQ

Frequently asked questions about
Cyber Resilience Act

Can't find what you're looking for? Our team will get back to you within one business day.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Ask our team

What is the Cyber Resilience Act?

The Cyber Resilience Act is an EU regulation governing the cybersecurity of products with digital components. Among other things, it establishes requirements for secure product development, vulnerability management, security updates, documentation, reporting, and conformity assessment.

Does a CRA report replace a NIS2 report?

No. The CRA and NIS2 have different reporting channels and scopes of application. A report submitted via the CRA Single Reporting Platform does not automatically satisfy a potential NIS2 reporting obligation via national channels.

Where is a CRA report submitted?

The report is submitted once via the reporting platform operated by ENISA and is sent to the CSIRT designated as the coordinator for your EU main establishment, as well as to ENISA. Access is provided via an EU Login account, which you can set up in advance.

Does the CRA also apply to SaaS companies?

Pure browser-based SaaS offerings do not generally fall under the CRA solely on that basis. However, if a SaaS company also provides an installable client, app, browser extension, or agent under its own brand, that product component may be affected. The Commission clarified this distinction with examples in its guidelines dated July 27, 2026 (C(2026) 5252).

A proprietary remote processing solution can also be part of the product if the product in question would be unable to perform one of its functions without it.

Which companies are affected by the CRA?

This particularly affects companies that make hardware or software products with digital elements available on the EU market under their own name or brand. The industry and business model are less important than the specific product itself.

Does ISO 27001 make our product CRA-compliant?

No. While ISO 27001 provides a strong organizational foundation for information security, it does not replace the product-specific requirements of the CRA. However, existing risks, policies, incident processes, and documentation can be partially leveraged.

What does heyData currently offer for the CRA?

heyData is currently supporting companies in preparing for and implementing the reporting obligations under Art. 14 of the CRA. Our services focus on the requirements that will apply from September 11, 2026.

An expanded offering covering the full CRA requirements starting in December 2027 is currently in the pilot and development phase.

Does heyData also provide support for CE marking?

CE marking and full conformity assessment are not part of the currently available CRA reporting service. Support for the more comprehensive requirements starting in December 2027 is currently being defined as part of the pilot phase.

Must all incidents be fully reported within 24 hours?

No. An initial warning is generally required within 24 hours. A more detailed report follows within 72 hours. The final report is due thereafter: for an actively exploited vulnerability, no later than 14 days after a patch or mitigation measure becomes available – and for a serious security incident, within one month of the 72-hour report.

Which events must be reported?

In particular, actively exploited vulnerabilities and serious security incidents that impact the security of a product with digital elements must be reported. Not every common vulnerability or IT disruption automatically triggers a CRA notification.

Do the reporting obligations also apply to existing products?

Yes. The reporting obligations also apply to products with digital elements that were made available on the EU market before December 11, 2027. Even software you shipped years ago can trigger a 24-hour reporting deadline.

Are we considered the manufacturer if a service provider developed our software?

That is possible. Anyone who brings a product to market under their own name or brand can be considered a manufacturer – even if the development or production is carried out by third parties.

Does an installable app count as a product with digital elements?

In principle, mobile apps, desktop applications, browser extensions, and other installable software may fall under the CRA if they are made available on the EU market as part of a commercial activity and meet the other requirements of the CRA.

When does the Cyber Resilience Act take effect?

The reporting requirements under Article 14 take effect on September 11, 2026. Most of the other requirements take effect on December 11, 2027.

CRA reporting is the first step. With heyData, it becomes an integrated compliance system.

CYBERSECURITY
Verlauf von blau zu grün mit weichem, gebogenen Design.
Kreisdiagramm mit grünem Fortschrittsbalken, der 78 Prozent anzeigt.

NIS2 Compliance

Leverage ISMS structures for your NIS2 preparation: governance, risk analysis, supply chain security, incident processes, and documentation.

Learn more
INFORMATION SECURITY
Blauer und grüner Farbverlauf mit unregelmäßiger Wellenlinie in der Mitte.
Kreisdiagramm zeigt 38% in grün und 62% in grau.

ISO 27001 Compliance

Nutze Risiken, Controls, Policies und Verantwortlichkeiten als organisatorische Grundlage für deine CRA-Vorbereitung.

Learn more
AI & Governance
Kreisdiagramm mit grünem Abschnitt, der 22 Prozent anzeigt.

EU AI Act

If you are developing or using AI systems, you need clear governance, roles, and documentation. heyData builds the foundation early on.

Learn more