Cyber Resilience Act: Meeting reporting obligations securely and on time

Prepare your business for the CRA reporting requirements effective September 11, 2026 – with clear processes, centralized documentation, and personal experts by your side.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
non-binding consultation
Awarded for excellent customer reviews.
Capterra Logo mit 4,9 von 5 Sternen Bewertung.
Compliance that scales with you

Clarity before the deadline hits.

2,500+
Customers in 20+ Markets
50+
Available Integrations
Audit-ready
Documentation Always at Hand
All-in-One
Data Protection, Risk & Evidence
THE CHALLENGE

When an incident occurs, the clock starts immediately.

Mere suspicion does not in itself trigger the reporting requirement. What matters is your initial assessment of the incident – and you must not delay that assessment in order to postpone the start of the reporting period. That is precisely why the assessment process must take place first.

Is the product even affected?

Installable software, apps, browser extensions, agents, and connected devices may fall within the scope of this regulation. What matters is the specific product – not your industry or business model. And what you delivered years ago also counts: There is no grandfather clause for reporting requirements.

24 hours leaves little room for error

As a general rule, an initial early warning must be issued within 24 hours. A more detailed report follows within 72 hours. Without a predefined procedure, half of that time is wasted trying to figure out who is actually in charge of making the decision.

Information is spread across multiple teams

The Development, Product, IT Security, Legal, and Management teams each have a portion of the necessary information. In an emergency, there is no time to gather it all.

What you can manage with heyData for CRA reporting requirements

From documentation to audit preparation: heyData bundles all ISMS components into one system.

Already in use at
PRODUCTS

Centralized product tracking

Document any installable software, apps, browser extensions, agents, and connected hardware that you make available on the EU market under your name.

Product directory
Scope of application
RESPONSIBILITIES

Define responsibilities clearly

Determine who will assess incidents, provide technical information, approve decisions, and coordinate the reporting process.

Responsibility
Escalation
REPORTING PROCESS

Prepare the reporting process

Clearly outline the process from internal detection through early warning, the main report, and the final report.

24h Early Warning
72h notification
DOCUMENTATION

Keep information readily available

Keep product data, vulnerability assessments, actions taken, and internal decisions recorded in a centralized and traceable manner.

Evidence
Schulungsnachweise
OTHER FRAMEWORKS

Reuse ISO 27001 and NIS2

Use existing risks, measures, policies, and incident response processes as the organizational foundation for the CRA.

Lieferantenqualität
Abweichungsmanagement
USER INFORMATION

Inform your customers in good time, too

In addition to reporting the incident to the authorities, you must notify the affected users immediately. We will work with you to prepare communication channels, approvals, and distribution lists.

Art. 14 Para. 8
Customer communication
WHY HEYDATA

What our customers say

2,500+ customers trust heyData with their information security.

IT Service Providers
17.08.2026

From customer requirements to the ISO 27001 security standard

How Sprintwerk successfully achieves ISO 27001 certification with heyData and integrates information security into their daily workflow.

Learn more

With heyData, we save time, reduce risks, and actively strengthen our customers' trust.

Lara Schimweg
Founder & CEO, Xeno GmbH

Thanks to the platform, we can handle onboarding centrally and efficiently.

Julia Streichan
Co-Founder, Sprintwerk GmbH

What sets heyData apart is its responsiveness and fast execution.

Sandra Scherzer
Legal Team, Bioland

The software helps us document all IT security measures relevant to data protection and review them regularly.

Dennis Kuhlmann
CEO, KUMA IT-Solutions GmbH

Who ISO 9001 is particularly relevant for

Technology & SaaS providers

Repeatable processes for development, implementation, support, and customer success—especially when enterprise clients require a certified QMS.

Manufacturing & engineering

Standardize production and delivery processes, improve supplier quality, reduce recurring errors, and demonstrate quality management to customers.

Consulting & professional services

Consistent project quality, seamless handovers, and structured customer feedback. Quality becomes less dependent on the knowledge of individual employees.

Logistics & construction

Organize quality-relevant processes, responsibilities, suppliers, and documentation across projects, locations, and teams.

B2B suppliers & contractors

Meet procurement and supply chain requirements and demonstrate through independent audits that quality is managed systematically.

Growing companies

Establish clear responsibilities and measurable processes before complexity leads to quality issues.

Verlaufshintergrund mit Blau- und Grüntönen, der von oben links nach unten rechts verläuft.

From product scope to a prepared CRA reporting process

Kein unübersichtliches Compliance-Projekt. Sondern ein klarer Einstieg in die Anforderungen, die ab September 2026 tatsächlich gelten.

01

Categorize products

List the hardware and software products that you make available on the EU market under your name. Together, we'll determine which product components may be relevant to the CRA.

02

Define responsibilities

Determine which roles from Development, Product, IT Security, Legal, and Management will be involved in the reporting process.

03

Prepare reporting process

Structure the detection, assessment, escalation, and approval processes according to the 24-hour, 72-hour, and final deadlines.

04

Coordinated action in an emergency

heyData provides you with relevant documents such as SoA, risk reports, policies, and evidence in one central location. After certification, the platform supports you with ongoing monitoring and preparation for follow-up audits.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
START CRA-CHECK

No-obligation consultation · Clear scope

Comparison

Why heyData.

A functional QMS requires more than just documents – and more than ad-hoc consulting.

Self-implementation
Traditional consulting
QMS software without guidance
Implementation
Guided tasks, mapped directly to standard requirements
Entirely internal
Project managed by consultants
Depending on product and setup
Experts
Personal ISO guidance included
Internal expertise required
Usually project- or hourly-based
Usually booked separately
Processes & documents
Integrated into a QMS
Folders, wikis, spreadsheets, various tools
Frequent document handover
Mostly well covered
Non-conformities & corrective actions
Linked with requirements, responsibilities, and effectiveness checks
Manual tracking
Often not part of ongoing support
Depending on the provider
Audit preparation
Evidence, tasks, and findings centralized
Manual compilation
Supported by consultants
Tool-supported, expertise varies
Multi-framework
ISO 9001, ISO 27001 and others connected
Manual assignment
Often separate projects
Depending on the provider
After certification
Recurring tasks, monitoring, improvement
Internal maintenance
New or ongoing mandate
Software remains, support varies
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Request now

Security is part of our operations.

EU data sovereignty, in-house legal counsel, ISO 27001-certified hosting

European Provider

German company, European law, no access by non-EU authorities.

Regular Security Audits

Continuously audited and securely developed.

Encryption & Access Control

Encrypted data, clearly defined access.

Vetted Experts

An ISO 27001-ready management system.

Verlaufshintergrund mit Blau- und Grüntönen, der von oben links nach unten rechts verläuft.

Which of your products fall under the CRA?

In einem kurzen Check betrachten wir dein Produktportfolio, deine Rolle als Hersteller und deine bestehenden Sicherheitsprozesse. Du erhältst eine erste Einschätzung, was du vor dem 11. September 2026 vorbereiten solltest.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
START CRA CHECK

No obligation. Just a clear assessment.

FAQ

Frequently asked questions about
Cyber Resilience Act

Can't find what you're looking for? Our team will get back to you within one business day.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Ask our team

What is the Cyber Resilience Act?

The Cyber Resilience Act is an EU regulation governing the cybersecurity of products with digital components. Among other things, it establishes requirements for secure product development, vulnerability management, security updates, documentation, reporting, and conformity assessment.

Does a CRA report replace a NIS2 report?

No. The CRA and NIS2 have different reporting channels and scopes of application. A report submitted via the CRA Single Reporting Platform does not automatically satisfy a potential NIS2 reporting obligation via national channels.

Where is a CRA report submitted?

The report is submitted once via the reporting platform operated by ENISA and is sent to the CSIRT designated as the coordinator for your EU main establishment, as well as to ENISA. Access is provided via an EU Login account, which you can set up in advance.

Does the CRA also apply to SaaS companies?

Pure browser-based SaaS offerings do not generally fall under the CRA solely on that basis. However, if a SaaS company also provides an installable client, app, browser extension, or agent under its own brand, that product component may be affected. The Commission clarified this distinction with examples in its guidelines dated July 27, 2026 (C(2026) 5252).

A proprietary remote processing solution can also be part of the product if the product in question would be unable to perform one of its functions without it.

Which companies are affected by the CRA?

This particularly affects companies that make hardware or software products with digital elements available on the EU market under their own name or brand. The industry and business model are less important than the specific product itself.

Does ISO 27001 make our product CRA-compliant?

No. While ISO 27001 provides a strong organizational foundation for information security, it does not replace the product-specific requirements of the CRA. However, existing risks, policies, incident processes, and documentation can be partially leveraged.

What does heyData currently offer for the CRA?

heyData is currently supporting companies in preparing for and implementing the reporting obligations under Art. 14 of the CRA. Our services focus on the requirements that will apply from September 11, 2026.

An expanded offering covering the full CRA requirements starting in December 2027 is currently in the pilot and development phase.

Does heyData also provide support for CE marking?

CE marking and full conformity assessment are not part of the currently available CRA reporting service. Support for the more comprehensive requirements starting in December 2027 is currently being defined as part of the pilot phase.

Must all incidents be fully reported within 24 hours?

No. An initial warning is generally required within 24 hours. A more detailed report follows within 72 hours. The final report is due thereafter: for an actively exploited vulnerability, no later than 14 days after a patch or mitigation measure becomes available – and for a serious security incident, within one month of the 72-hour report.

Which events must be reported?

In particular, actively exploited vulnerabilities and serious security incidents that impact the security of a product with digital elements must be reported. Not every common vulnerability or IT disruption automatically triggers a CRA notification.

Do the reporting obligations also apply to existing products?

Yes. The reporting obligations also apply to products with digital elements that were made available on the EU market before December 11, 2027. Even software you shipped years ago can trigger a 24-hour reporting deadline.

Are we considered the manufacturer if a service provider developed our software?

That is possible. Anyone who brings a product to market under their own name or brand can be considered a manufacturer – even if the development or production is carried out by third parties.

Does an installable app count as a product with digital elements?

In principle, mobile apps, desktop applications, browser extensions, and other installable software may fall under the CRA if they are made available on the EU market as part of a commercial activity and meet the other requirements of the CRA.

When does the Cyber Resilience Act take effect?

The reporting requirements under Article 14 take effect on September 11, 2026. Most of the other requirements take effect on December 11, 2027.