Zweite Schicht DE, Deutsche Fassung Book a call

Use cases

Updated

When the clock is running: reporting duties that a workflow handles from the very first minute.

We build the software your team uses to meet statutory reporting duties on time: for manufacturers of connected products, operators of important facilities and every company that holds personal data. Not the legal advice, and not the notification on your behalf. The trigger is always the same: a partner reports a vulnerability in your controller, a laptop with customer data has gone missing, a dealer counts three overheated devices from one batch, and from now on a deadline of 24 hours, 72 hours or seven days is running. Today that rests with one person with a spreadsheet, an inbox and a telephone. The workflow we build for it takes in the report, proposes the classification, keeps the clock, informs those affected in stages after your approval, prepares the notification to the authority and logs every step. Eight use cases, starting with the Cyber Resilience Act.

Sketch of an alarm board on the wall with a bell, a wall clock and three compartments holding form cards, labelled 24 H, 72 H and 14 TAGE, below it a shelf with a book and a telephone.

Cases

Eight use cases, each with its own clock

Each page describes the duty, the workflow hour by hour, the cascade, what stays with your people, the systems and the evidence. In three groups: for manufacturers, for every company, for regulated industries. The Cyber Resilience Act is the lead case, because its reporting duty has applied since 11 September 2026.

For manufacturers

  • A manufacturer of controllers learns that a vulnerability in its firmware is being actively exploited. Early warning to the CSIRT and ENISA within 24 hours, notification within 72, users informed in stages, final report 14 days after the update. The lead case, with the most detailed cascade.

    Read the use case
    24 h, 72 h, 14 dayssince 11 September 2026
  • Three complaints about the same batch, one with burn marks. Spot the cluster, assess the risk, stop the dealers, reach identifiable buyers directly, publish the recall notice in the prescribed format, notify the authority via the Safety Business Gateway, track the return rate.

    Read the use case
    without delayGPSR and EU product law
  • A hospital reports that a pump stopped without an alarm. Depending on the classification, two, ten or fifteen days to report to the BfArM, a field safety notice to exactly the hospitals with these serial numbers, confirmation tracked hospital by hospital, trend analysis across all complaints.

    Read the use case
    2, 10 or 15 daysArticles 87 to 89 MDR

For every company

  • A mail merge with payslips goes to the wrong distribution list. Three levels of classification, 72 hours to the supervisory authority, data subjects informed in plain language where the risk is high, and the register of all cases, including those not reported.

    Read the use case
    72 hArticles 33 and 34 GDPR
  • A report of irregularities in supplier invoices arrives on a Friday evening. Acknowledgement of receipt within seven days, feedback within three months, and a cascade with barriers: who learns the facts, who learns the identity, who learns nothing. The workflow runs separately from the inbox.

    Read the use case
    7 days, 3 monthsHinSchG, from 50 employees
  • Ransomware paralyses production planning overnight. For important and essential entities, the clock runs from the moment of awareness: 24 hours to the early warning to the BSI, 72 hours to the notification, one month to the final report. Management has to be kept informed.

    Read the use case
    24 h, 72 h, 1 monthBSIG, since December 2025

For regulated industries and providers

  • A payment institution's contract system stops responding, and the day's direct debits are stuck. Two clocks at once: four hours from classification and 24 hours from awareness to the initial notification to the BaFin, an intermediate report after 72 hours, a final report after one month, and customers with affected payments to be informed.

    Read the use case
    4 h, 24 h, 72 h, 1 monthArticle 19 DORA
  • A deployer reports that the system has systematically screened out one group. Keep provider and deployer apart, establish the causal link, two, ten or fifteen days to the market surveillance authority, inform every deployer of the same model version. Applies to Annex III from December 2027.

    Read the use case
    2, 10 or 15 daysArticle 73 AI Act

Pattern

Six steps that all these duties have in common

The laws differ in trigger, deadline and authority. The workflow behind them is always the same, and that is exactly why it pays to build it properly once.

  1. Event

    The report arrives, whatever the channel

    Email, form, phone call, a report from a partner or service provider, an alert from your own monitoring. The workflow opens a case, reads the report, extracts product, system, time and those affected, and records receipt with a timestamp. From here, the clock is running.

  2. Classification

    A proposal with reasons, the decision with a person

    Does the case fall under the duty, and if so, at which level? The workflow sets the criteria from the law next to the relevant passages of the report and makes a proposal. Your responsible person confirms or changes it. This decision is the moment every authority will later be interested in, which is why it is in the log with a name and the reasons.

  3. Clock

    Deadlines, reminders, escalation

    The deadlines follow from the classification. The workflow shows them, sends reminders in stages and escalates to the next level if a draft is left waiting for approval. Whatever comes in overnight or at the weekend does not wait until Monday for someone to look at it.

  4. Cascade

    Informing those affected in stages

    First those at the highest risk, in person. Then partners and dealers. Then all users, then the public, if the law requires it. Each wave has a draft in the recipient's language, a person who approves it and a point in time. Anyone who does not confirm receives a reminder or goes onto the call-back list.

  5. Authority

    The notification comes out of the case

    Early warning, notification, final report: each stage has mandatory details, and all of them are in the case. The workflow fills in the draft, asks for whatever is missing and, after approval, hands it over to the authority's portal. Where there is no interface, a person enters the finished text.

  6. Evidence

    The log instead of a search through the inbox

    Every step with a timestamp, every approval with a name, every email with its list of recipients and confirmations. From this come the final report, the export for the authority, the auditor and the insurer, and the register of cases that were checked and did not need to be reported. Twice a year, a trial run with a made-up case.

Tool

What the workflow does, and what it does not do

A custom tool, built on the building blocks of our other services: reading and assigning what comes in, applying rules, texts at scale from templates, cases with a log. It spares your people the gathering of information and leaves the decisions to them.

What it does

  • Turns every incoming report into a case and records it with a timestamp, from email, form, telephone note, partner portal and monitoring.
  • Extracts product, version, system, those affected and the circumstances from the report and matches them against your data: installed base, serial numbers, contracts, software bill of materials (SBOM).
  • Proposes the classification with reasons, derives the deadlines from it, sends reminders and escalates.
  • Prepares each wave of the cascade: list of recipients, draft in the recipient's language, channel, call-back list. Matches confirmations and questions to the case and follows up.
  • Drafts every notification to the authority from the case data, flags gaps and hands it over after approval.
  • Produces the final report, exports and the register of checked cases from the log. Runs a trial run twice a year.

What it does not do

  • It does not decide whether a case must be reported. It makes a proposal; the decision is made by your responsible person, in case of doubt with your legal department or law firm.
  • It sends nothing outside without approval, neither to the authority nor to customers; only the internal alert goes out immediately, according to your list. Escalation makes sure someone approves, not that things happen without people.
  • It does not replace legal advice or crisis management. It gives the crisis team the case with every point in time.
  • It does not put data in other hands. Incident data, customer lists and reports stay on your server or in a German data centre; the AI components run on open models on your own servers or via EU data centres.
  • It does not hold conversations with authorities or critical customers. It puts the list and the call note in front of the person who does.
  • It is not staffed around the clock, it runs around the clock. At night and at the weekend it alerts your on-call list; as part of ongoing operation we monitor on working days that it is running. If it fails, the list, templates and data are ready as an export.

Experience

What we bring

The building blocks of these reporting chains have been running at our customers for years: routing enquiries from twelve sites across Europe to the right team according to rules at a technology distributor; applying a set of rules to several thousand pages and presenting every finding with a classification and reasons at a fuel cell manufacturer, whose service portal with returns process and ticketing system we also built; cases with log, approval and emails at scale in our own operations. We put the chain under a statutory deadline, from the incoming report to the authority's platform, into operation together with you. That is why the trial run with a made-up case is the acceptance test, and we show you a sample log in the first call.

Read the case studies

Price

Price and scope

The order of magnitude first: the workflow analysis costs €4,900 at a fixed price and takes three days. Based on our projects, a custom tool typically costs between €25,000 and €60,000, as a fixed price that becomes binding after the analysis; the first version is ready in about six weeks. Ongoing operation after that starts at €2,900 a month and can be cancelled monthly. A more precise range in advance would be guesswork, because a reporting chain for one duty and one product is something different from one for four duties, twelve countries and nine languages. What determines the price: the number of duties the workflow covers, the incoming channels, the systems from which those affected are identified, and the languages and recipient groups of the cascade. It often pays to build several duties into one workflow, because an attack on remote maintenance can trigger the Cyber Resilience Act, NIS2 and the GDPR at the same time: one case, three clocks, three authorities.

In the analysis we set today's effort (who reads, who makes the calls, who pieces the timeline together at the end) next to the fixed price and tell you whether it pays off for your number of cases. For a duty that applies once every three years, the answer is sometimes no, and then the list says so. Data flow per service.

Deadlines

The deadlines at a glance

As of October 2026, as an overview for operations. Whether a case falls under a duty is for your legal department or law firm to decide; the workflow keeps the clock they give you.

Reporting duties with trigger, deadlines and recipients at a glance
DutyTriggerDeadlinesRecipient
Cyber Resilience Act, Art. 14actively exploited vulnerability or severe incident affecting a product with digital elements24 h early warning, 72 h notification, final report 14 days after the corrective measure or after 1 monthCSIRT (in Germany at the BSI) and ENISA via the reporting platform; affected users
NIS2, BSIGsignificant security incident at an important or essential entity24 h early warning, 72 h notification, 1 month final reportBSI; recipients of the services when ordered by the BSI
GDPR, Art. 33 and 34personal data breach with a risk72 h from awareness; data subjects without undue delay where the risk is highsupervisory authority of the federal state; data subjects
Product safety, GPSR Art. 9, 20, 35 to 37; commercial products: EU harmonisation legislation and Regulation (EU) 2019/1020 Art. 4(3)unsafe product, accident involving a productwithout delaymarket surveillance via the Safety Business Gateway; dealers; identifiable consumers
Medical devices, MDR Art. 87 to 89serious incident, field safety corrective action15 days; 10 days in case of death or serious deterioration; 2 days in case of a threat to public healthBfArM or PEI via EUDAMED; users by field safety notice
Whistleblower protection, HinSchG Section 17report to the internal reporting office7 days acknowledgement of receipt, 3 months feedbackwhistleblower; documentation under Section 11
AI Act, Art. 73serious incident involving a high-risk AI system15 days; 10 days in case of death; 2 days in case of a widespread infringement or critical infrastructuremarket surveillance authority of the member state; deployers inform provider, importer or distributor and the market surveillance authority (Art. 26(5))
DORA, Art. 19major ICT-related incident at a financial entityinitial notification 4 h after classification and 24 h after awareness, 72 h intermediate report, 1 month final reportBaFin; customers where their financial interests are affected

The same pattern applies to duties without a page of their own: the accident report within three days under Section 193 of Book VII of the Social Code (SGB VII), the immediate report of a major incident under Section 19 of the 12th Federal Immission Control Ordinance (12. BImSchV), the suspicious activity report under Section 43 of the Money Laundering Act (GwG) and the complaints procedure under Section 8 of the Supply Chain Due Diligence Act (LkSG). Ask us if your duty is missing here.

Questions

Questions about reporting chains with deadlines

What management, IT and the legal department ask before they have a reporting chain built. More answers under Questions and answers.

Don't we need a lawyer for this rather than software?

Both, in this order: your legal advisers tell you which duties apply to you and how cases are to be classified. Those rules become the rules of the workflow. After that, the tool keeps the clock, gathers the details, prepares notifications and customer information, and keeps the log. When it gets serious, your law firm has the complete case in front of it instead of an inbox.

We may have a case like this once a year. Is it worth it?

We work that out honestly in the analysis. For a duty with very rare cases, the answer can be no. Often, however, several duties draw on the same data and channels, and the workflow covers them together; then what counts is not the number of cases but what a missed day costs, in fines, customer trust and night shifts. On top of that comes the trial run, which shows whether your installed base is right before you need it.

Can the workflow report directly to the authorities' portals?

Where a portal offers an interface, we check it in the analysis. Most authority portals have none. In that case the workflow pre-fills the notification with all mandatory details, a person enters it after approval, and the timestamp of the acknowledgement of receipt goes into the log. The workflow keeps the deadline, not the interface.

Where is the data from an incident kept?

With you. Reports, vulnerability descriptions, customer lists and logs stay on your server or in a German data centre. The AI components, meaning reading, assigning, the classification proposal and drafts, run on open models on your own servers or via EU data centres. No incident data goes to a model that trains on it; that is in the contract.

Handover

The first step is a 30-minute call.

You tell us about the workflow that costs you the most time. We tell you honestly whether AI pays off there and what the next step would be. Whether a workflow analysis follows is up to you.

Book a callApproach and prices