Notification: the draft
The Notification screen prepares the content of the communication to the authority. Part of it is already written because it follows from the verdict; the rest are the facts, which only you know. Everything you type here carries into the later phases, so the 72-hour update does not start from a blank page.
What the engine decides
These fields cannot be edited, and it is good that they cannot: they are the consequence of the triage.
What you write
Nature of the event
What happened, in technical and verifiable terms. Worth including: the component or function affected, the versions involved, the attack vector, the CVE identifier if assigned, and — for an exploited vulnerability — the elements from which exploitation follows. Avoid unsupported severity judgements: facts are what is needed here.
Measures taken
What you have already done and what you are doing: temporary mitigations, guidance given to customers, functions disabled, expected timing of the fix. If at early-warning time you have no measure yet, say so: «analysis under way, mitigation expected by …» is a legitimate answer within 24 hours and beats an empty field.
Contact person
The person the authority can reach: name, role, email and a phone that is answered. It must be somebody who actually responds — out of hours too, in an active phase.
Good practice. Prepare three model texts in advance (exploited vulnerability, incident with outage, incident with data exposure) and keep them handy. At three in the morning, the difference between filing on time and missing the deadline is the time spent writing the first paragraph.
Preview and coherence
The screen shows the document as it will read, visually distinguishing engine-determined fields from the ones you filled in. Check before proceeding:
- the product is the right one (name and version match the register);
- the legal basis matches the nature of the event as you qualified it;
- the moment of awareness and the expiry are the ones you intend to defend;
- the contact is reachable now, not in general.
Saving the draft
The draft is saved with the case and stays available: you can come back to it, have a colleague read it, resume after an interruption. Each phase of the obligation (early warning, update, final) keeps its own draft, so the three texts stay distinct and reconstructable.
The draft is not transmitted to anyone: CRAnotify sends nothing to the authority. The next step, filing, happens on the ENISA platform with your own credentials.
What not to put in the draft
- Credentials, keys or tokens, not even revoked or example ones.
- Unnecessary personal data: if the case involved customer data, describe categories and volumes, not the individuals.
- Working exploits. Describe the vector; do not supply the weapon.
Next step
With the draft ready, go to Filing on the ENISA platform. Remember that in CRAnotify the filing counts as done only once you upload the receipt issued by the platform.