CRAnotify Documentation

Filing on the ENISA platform

Filing is the only step that happens outside CRAnotify: the communication is transmitted on the Single Reporting Platform with your company's institutional credentials. CRAnotify takes you there with the text ready and records the outcome when you upload the receipt you obtain.

Why we do not file for you

The Art. 14 report is an act of the manufacturer, engaging its responsibility and going through its digital identity (EU Login and the authorisations held with the national CSIRT). Delegating it to a supplier would insert a link you could not prove you control. What we can guarantee — and what an inspection needs — is the evidence of what was filed and when.

Prerequisites

The screen shows a checklist with two entries:

EU Login accountEnabled for the single reporting platform. Activation takes days: do it before you need it.
Contact at the CSIRTThe person registered as your organisation's point of contact with the national CSIRT.

The ticks are informational: they never block a filing. They exist so you do not reach the 24-hour mark discovering the credentials are missing. They are also one of the conditions of the «Ready to file» step of the setup checklist.

The procedure

  1. Check the fields summarised on the screen: legal basis, type of communication, recipients, product, nature, measures, contact.
  2. Open the platform from the link on the page and transmit the communication with your own credentials.
  3. Download the receipt of the filing from the platform (PDF, image, or the confirmation email saved as .eml).
  4. Return to CRAnotify, upload the receipt and — if the platform assigned one — enter the protocol number.
  5. Confirm. The case changes state and the next phase opens.

The receipt is mandatory

Without the receipt file the filing is not recorded and the case state stays unchanged. This is not arbitrary rigidity: a filing that is claimed but not evidenced will not defend you in an inspection. Accepted formats: PDF, PNG, JPEG, .eml, up to 10 MB.

The file is stored with the case, tied to the phase it belongs to, and appears in the defence dossier together with the upload moment and the protocol number.

These are three distinct states: packaged is not transmitted, and transmitted is not acknowledged. Generating or packaging a PDF is not in itself a filing or an acknowledgement; only uploading the real receipt — a file stored write-once in the vault, with its protocol — records that the filing happened. Nothing is ever sent to the authority automatically.

What happens on confirmation

Phase filedThe case moves to…Deadlines that open
Early warningin progressThe 72-hour update. For a serious incident also the final report (one month); for a vulnerability the final report is anchored to the corrective measure.
72-hour updatein progress, phase «final report»For a vulnerability, this is where you state the date the corrective measure became available: the final-report deadline becomes that date plus 14 days.
Final reportfulfilledNone: the path is complete.

Each confirmation writes a registry row with the legal basis, the phase, the receipt file name and any protocol number, and sends the alert to the contacts (and to the legal representative, if they opted in).

Mind what «in progress» means. Filing the early warning does not close the obligation: the «fulfilled» state arrives only with the final report. It is a distinction that matters in audits.

If the upload is rejected

MessageCauseFix
«Attach the receipt…»No file selected.Select the file downloaded from the platform.
«Invalid receipt»Format not allowed, or a corrupt file.Use PDF, PNG, JPEG or .eml. A PDF print of the confirmation page is fine.
«The upload is too large»Over 10 MB.Recompress the PDF or save only the confirmation page.

After filing

The confirmation screen recalls the duties that remain — completing the information requested by the authority, updates, and preserving the evidence — and gives access to the dossier. If you have not done so yet, this is the moment to consider the notice to affected users.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu