CRAnotify Documentation

Frequently asked questions

Short answers to the questions that come up most. Each one points to the page that covers the subject in full.

Does CRAnotify file the report with the CSIRT on our behalf?

No. CRAnotify qualifies the event, computes the deadlines, pre-fills the text and preserves the evidence; filing on the Single Reporting Platform remains an act of the manufacturer, who then uploads the platform's receipt into CRAnotify.

When do the 24 hours start running?

From the moment of awareness — the first documentable moment at which the company learnt of the fact: the first receipt of the report or the first internal finding. You set it in the third triage step, and every later change is recorded with its justification.

What is the difference between an exploited vulnerability and a serious incident?

An actively exploited vulnerability falls under Art. 14(2)(a) and requires evidence of actual use by third parties; a serious incident falls under Art. 14(4)(a) and requires that the event actually compromised the availability, integrity or confidentiality of the product or of the data it processes. A merely reported vulnerability does not trigger the obligation.

What happens after the early warning is filed?

The case moves to «in progress»: the 72-hour update and the final report are still due. For a serious incident the final report is expected within one month; for a vulnerability the deadline is anchored to the date the corrective measure becomes available, plus fourteen days.

Can the activity registry be edited?

No. Each row is chained to the previous one with a cryptographic digest: altering or removing a row breaks the chain, and the check reports the first inconsistent row. Rows are appended, never corrected.

Can we rehearse the flow without generating real communications?

Yes, with exercise mode: registry entries are marked «[esercitazione]» and the legal representative stays out of the escalation.

Who can see the data, and where is it stored?

Organisation data is separated per organisation and stored in the European Union. Within the organisation, access depends on the role: administrative actions require the Administrator role.

What happens when the subscription lapses?

When the trial or the subscription ends there are seven grace days during which writing is blocked but reading and export stay available; after that the organisation becomes read-only. The registry, dossiers and receipts remain exportable at all times.

Can the public reporting form be embedded in our website?

Yes: the page exposes a per-organisation address and a ready-to-paste <iframe> snippet. The form is the application's only public surface and has dedicated anti-abuse defences.

How do we reach support about a deadline that is running out?

Use the form with the category «Deadline running out / urgent» and, in parallel, the phone: +39 031 5478618. Written answers arrive within one working day.

Where to read more

How an event is qualifiedGuided triage and Verdict and legal basis.
Which deadlines applyPhases and deadlines.
What evidence remainsRegistry, Integrity and Defence dossier.
How to set up the organisationInitial setup and Users, roles and escalation.
Recurring problemsTroubleshooting.

Commercial questions (pricing, quotes, the partner programme) are handled on the public site: https://cranotify.eu/contatti. This page and the support form are about using the product.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu