CRAnotify Documentation

User notice and upstream chain

Alongside the notification to the authority, the Regulation provides for two duties towards other recipients: informing affected users, and reporting to the maintainer a defect that sits in a third-party component. CRAnotify treats them as distinct activities, each with its own trace in the registry.

Notice to affected users · Art. 14(8)

Where an event affects the security of the product, the manufacturer informs the users of the product — and, where appropriate, all users — of the event and of the corrective or mitigating measures they can take.

The Notify users screen (reached from the filing path) lets you:

  • choose the audience: registered users, customers and distributors, all affected parties;
  • start from a base text already set out, to adapt to the case;
  • record the notice as issued, with its audience and moment.

CRAnotify does not send the notice to your customers: distribution happens through your own channels (security advisories, customer emails, release notes, product portal). What is recorded here is that it was done — which is what has to be demonstrated later.

Good practice. Always state in the notice: product and versions affected, what can happen, what the user must do now, and when the fix arrives. A notice that describes the problem without saying what to do only generates support calls.

Report to the maintainer · Art. 13(6)

Where the vulnerability concerns a third-party component included in the product — an open-source library, a supplier module — the manufacturer reports it to the person or entity maintaining it.

The Upstream report screen lists the components recorded in the product's bill of materials (see Product register), offers a base text and records that the report was made.

  • Report through the security channel the project declares (SECURITY.md, security.txt, private advisories), not a public one.
  • Agree a coordinated disclosure window before publishing details.
  • Keep the correspondence: it is the evidence that the upstream chain was activated.

In what order

The notification to the authority has the tightest deadlines and takes precedence. The other two follow, but do not wait for the final report: the user notice is more useful the earlier it lands, and the upstream report is often the precondition for the fix to exist at all.

awareness ──24 h──▶ early warning to the authority
      │
      ├─▶ notice to affected users        (Art. 14(8), without undue delay)
      └─▶ report to the upstream maintainer (Art. 13(6), as soon as identified)

What stays on the record

ActRegistry rowType
User notice recorded«Notice to affected users recorded», with the audiencenotification
Notice reopened«Notice to affected users reopened»notification
Upstream report recorded«Report to the maintainer recorded», referencing the componentsnotification

Both activities count towards the setup checklist: they are two of its seven steps.

Not to be confused

The notice to users does not replace the notification to the authority, and the notification to the authority does not replace the notice to users. They are distinct duties with different recipients and purposes: discharging only one leaves the other open.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu