CRAnotify Documentation

Notification: the draft

The Notification screen prepares the content of the communication to the authority. Part of it is already written because it follows from the verdict; the rest are the facts, which only you know. Everything you type here carries into the later phases, so the 72-hour update does not start from a blank page.

What the engine decides

These fields cannot be edited, and it is good that they cannot: they are the consequence of the triage.

Legal basisArt. 14(2)(a) for an actively exploited vulnerability, Art. 14(4)(a) for a serious incident.
Type of communicationEarly warning, 72-hour update or final report, according to the phase the case is in.
RecipientsCSIRT Italia and ENISA, through the single reporting platform.
CompanyLegal name and organisation code, from the company data.
ProductThe product with digital elements attached to the case.

What you write

Nature of the event

What happened, in technical and verifiable terms. Worth including: the component or function affected, the versions involved, the attack vector, the CVE identifier if assigned, and — for an exploited vulnerability — the elements from which exploitation follows. Avoid unsupported severity judgements: facts are what is needed here.

Measures taken

What you have already done and what you are doing: temporary mitigations, guidance given to customers, functions disabled, expected timing of the fix. If at early-warning time you have no measure yet, say so: «analysis under way, mitigation expected by …» is a legitimate answer within 24 hours and beats an empty field.

Contact person

The person the authority can reach: name, role, email and a phone that is answered. It must be somebody who actually responds — out of hours too, in an active phase.

Good practice. Prepare three model texts in advance (exploited vulnerability, incident with outage, incident with data exposure) and keep them handy. At three in the morning, the difference between filing on time and missing the deadline is the time spent writing the first paragraph.

Preview and coherence

The screen shows the document as it will read, visually distinguishing engine-determined fields from the ones you filled in. Check before proceeding:

  • the product is the right one (name and version match the register);
  • the legal basis matches the nature of the event as you qualified it;
  • the moment of awareness and the expiry are the ones you intend to defend;
  • the contact is reachable now, not in general.

Saving the draft

The draft is saved with the case and stays available: you can come back to it, have a colleague read it, resume after an interruption. Each phase of the obligation (early warning, update, final) keeps its own draft, so the three texts stay distinct and reconstructable.

The draft is not transmitted to anyone: CRAnotify sends nothing to the authority. The next step, filing, happens on the ENISA platform with your own credentials.

What not to put in the draft

  • Credentials, keys or tokens, not even revoked or example ones.
  • Unnecessary personal data: if the case involved customer data, describe categories and volumes, not the individuals.
  • Working exploits. Describe the vector; do not supply the weapon.

Next step

With the draft ready, go to Filing on the ENISA platform. Remember that in CRAnotify the filing counts as done only once you upload the receipt issued by the platform.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu