Cyber Resilience Act: Meeting reporting obligations securely and on time
Prepare your business for the CRA reporting requirements effective September 11, 2026 – with clear processes, centralized documentation, and personal experts by your side.

.avif)
Clarity before the deadline hits.
When an incident occurs, the clock starts immediately.
Mere suspicion does not in itself trigger the reporting requirement. What matters is your initial assessment of the incident – and you must not delay that assessment in order to postpone the start of the reporting period. That is precisely why the assessment process must take place first.
Is the product even affected?
Installable software, apps, browser extensions, agents, and connected devices may fall within the scope of this regulation. What matters is the specific product – not your industry or business model. And what you delivered years ago also counts: There is no grandfather clause for reporting requirements.
24 hours leaves little room for error
As a general rule, an initial early warning must be issued within 24 hours. A more detailed report follows within 72 hours. Without a predefined procedure, half of that time is wasted trying to figure out who is actually in charge of making the decision.
Information is spread across multiple teams
The Development, Product, IT Security, Legal, and Management teams each have a portion of the necessary information. In an emergency, there is no time to gather it all.
CRA reporting with heyData. Three reasons why.
A prepared process
Alles, was dein Team für den CRA-Meldeprozess benötigt:
- Centrally record affected products
- Define responsibilities
- Prepare internal escalation paths
- Structure required information
- Document decisions and reports in a traceable way
Experts by your side
Support when a purely technical analysis is not enough:
- Dedicated contacts from our team, not an anonymous hotline
- We classify your product scope and stand by this assessment
- We verify responsibilities and escalation paths against your organization
- Differentiation from NIS2 and ISO 27001 – by our in-house legal team
- Our experts maintain regulatory changes for you
Reuse existing work
CRA doesn't always start from scratch:
- Reuse risks from ISO 27001
- Use incident processes from NIS2 as a foundation
- Map responsibilities across frameworks
- Connect supplier and vulnerability processes
- What you implement once also counts for ISO 27001 and NIS2








What you can manage with heyData for CRA reporting requirements
From documentation to audit preparation: heyData bundles all ISMS components into one system.
Centralized product tracking
Document any installable software, apps, browser extensions, agents, and connected hardware that you make available on the EU market under your name.
Define responsibilities clearly
Determine who will assess incidents, provide technical information, approve decisions, and coordinate the reporting process.
Prepare the reporting process
Clearly outline the process from internal detection through early warning, the main report, and the final report.
Keep information readily available
Keep product data, vulnerability assessments, actions taken, and internal decisions recorded in a centralized and traceable manner.
Reuse ISO 27001 and NIS2
Use existing risks, measures, policies, and incident response processes as the organizational foundation for the CRA.
Inform your customers in good time, too
In addition to reporting the incident to the authorities, you must notify the affected users immediately. We will work with you to prepare communication channels, approvals, and distribution lists.

From product scope to a prepared CRA reporting process
Kein unübersichtliches Compliance-Projekt. Sondern ein klarer Einstieg in die Anforderungen, die ab September 2026 tatsächlich gelten.
Categorize products
List the hardware and software products that you make available on the EU market under your name. Together, we'll determine which product components may be relevant to the CRA.
Define responsibilities
Determine which roles from Development, Product, IT Security, Legal, and Management will be involved in the reporting process.
Prepare reporting process
Structure the detection, assessment, escalation, and approval processes according to the 24-hour, 72-hour, and final deadlines.
Coordinated action in an emergency
heyData provides you with relevant documents such as SoA, risk reports, policies, and evidence in one central location. After certification, the platform supports you with ongoing monitoring and preparation for follow-up audits.
No-obligation consultation · Clear scope
Your Information Security Expert
What our customers say
2,500+ customers trust heyData with their information security.

From customer requirements to the ISO 27001 security standard
How Sprintwerk successfully achieves ISO 27001 certification with heyData and integrates information security into their daily workflow.
With heyData, we save time, reduce risks, and actively strengthen our customers' trust.
Thanks to the platform, we can handle onboarding centrally and efficiently.
What sets heyData apart is its responsiveness and fast execution.
The software helps us document all IT security measures relevant to data protection and review them regularly.
ISO 27001, NIS2, and CRA: What are the main differences?
Security is part of our operations.
EU data sovereignty, in-house legal counsel, ISO 27001-certified hosting
European Provider
German company, European law, no access by non-EU authorities.
Regular Security Audits
Continuously audited and securely developed.
Encryption & Access Control
Encrypted data, clearly defined access.
Vetted Experts
An ISO 27001-ready management system.

Which of your products fall under the CRA?
In einem kurzen Check betrachten wir dein Produktportfolio, deine Rolle als Hersteller und deine bestehenden Sicherheitsprozesse. Du erhältst eine erste Einschätzung, was du vor dem 11. September 2026 vorbereiten solltest.
No obligation. Just a clear assessment.
Frequently asked questions about
Cyber Resilience Act
Can't find what you're looking for? Our team will get back to you within one business day.
What is the Cyber Resilience Act?
What is the Cyber Resilience Act?
The Cyber Resilience Act is an EU regulation governing the cybersecurity of products with digital components. Among other things, it establishes requirements for secure product development, vulnerability management, security updates, documentation, reporting, and conformity assessment.
Does a CRA report replace a NIS2 report?
Does a CRA report replace a NIS2 report?
No. The CRA and NIS2 have different reporting channels and scopes of application. A report submitted via the CRA Single Reporting Platform does not automatically satisfy a potential NIS2 reporting obligation via national channels.
Where is a CRA report submitted?
Where is a CRA report submitted?
The report is submitted once via the reporting platform operated by ENISA and is sent to the CSIRT designated as the coordinator for your EU main establishment, as well as to ENISA. Access is provided via an EU Login account, which you can set up in advance.
Does the CRA also apply to SaaS companies?
Does the CRA also apply to SaaS companies?
Pure browser-based SaaS offerings do not generally fall under the CRA solely on that basis. However, if a SaaS company also provides an installable client, app, browser extension, or agent under its own brand, that product component may be affected. The Commission clarified this distinction with examples in its guidelines dated July 27, 2026 (C(2026) 5252).
A proprietary remote processing solution can also be part of the product if the product in question would be unable to perform one of its functions without it.
Which companies are affected by the CRA?
Which companies are affected by the CRA?
This particularly affects companies that make hardware or software products with digital elements available on the EU market under their own name or brand. The industry and business model are less important than the specific product itself.
Does ISO 27001 make our product CRA-compliant?
Does ISO 27001 make our product CRA-compliant?
No. While ISO 27001 provides a strong organizational foundation for information security, it does not replace the product-specific requirements of the CRA. However, existing risks, policies, incident processes, and documentation can be partially leveraged.
What does heyData currently offer for the CRA?
What does heyData currently offer for the CRA?
heyData is currently supporting companies in preparing for and implementing the reporting obligations under Art. 14 of the CRA. Our services focus on the requirements that will apply from September 11, 2026.
An expanded offering covering the full CRA requirements starting in December 2027 is currently in the pilot and development phase.
Does heyData also provide support for CE marking?
Does heyData also provide support for CE marking?
CE marking and full conformity assessment are not part of the currently available CRA reporting service. Support for the more comprehensive requirements starting in December 2027 is currently being defined as part of the pilot phase.
Must all incidents be fully reported within 24 hours?
Must all incidents be fully reported within 24 hours?
No. An initial warning is generally required within 24 hours. A more detailed report follows within 72 hours. The final report is due thereafter: for an actively exploited vulnerability, no later than 14 days after a patch or mitigation measure becomes available – and for a serious security incident, within one month of the 72-hour report.
Which events must be reported?
Which events must be reported?
In particular, actively exploited vulnerabilities and serious security incidents that impact the security of a product with digital elements must be reported. Not every common vulnerability or IT disruption automatically triggers a CRA notification.
Do the reporting obligations also apply to existing products?
Do the reporting obligations also apply to existing products?
Yes. The reporting obligations also apply to products with digital elements that were made available on the EU market before December 11, 2027. Even software you shipped years ago can trigger a 24-hour reporting deadline.
Are we considered the manufacturer if a service provider developed our software?
Are we considered the manufacturer if a service provider developed our software?
That is possible. Anyone who brings a product to market under their own name or brand can be considered a manufacturer – even if the development or production is carried out by third parties.
Does an installable app count as a product with digital elements?
Does an installable app count as a product with digital elements?
In principle, mobile apps, desktop applications, browser extensions, and other installable software may fall under the CRA if they are made available on the EU market as part of a commercial activity and meet the other requirements of the CRA.
When does the Cyber Resilience Act take effect?
When does the Cyber Resilience Act take effect?
The reporting requirements under Article 14 take effect on September 11, 2026. Most of the other requirements take effect on December 11, 2027.
CRA reporting is the first step. With heyData, it becomes an integrated compliance system.


NIS2 Compliance
Leverage ISMS structures for your NIS2 preparation: governance, risk analysis, supply chain security, incident processes, and documentation.


ISO 27001 Compliance
Nutze Risiken, Controls, Policies und Verantwortlichkeiten als organisatorische Grundlage für deine CRA-Vorbereitung.


EU AI Act
If you are developing or using AI systems, you need clear governance, roles, and documentation. heyData builds the foundation early on.







