CRAnotify Documentation

Phases and deadlines

The Art. 14 obligation is not discharged with one communication: there are three, in sequence, each with its own deadline. CRAnotify keeps a clock for the current phase and opens the next one when the previous is filed.

The three phases

PhaseDeadlineRuns from
Early warning24 hoursThe moment of awareness fixed during triage.
Update72 hoursThe filing of the early warning.
Final reportSee below: it depends on the nature of the event.The filing of the update, with a different anchor for vulnerabilities and incidents.

The final report

Serious incidentOne month from the filing of the early warning. The countdown starts immediately.
Exploited vulnerabilityAnchored to the availability of the corrective measure: fourteen days from that date. Until the date is known, the clock shows «waiting for the corrective measure» instead of a countdown.

This is deliberate: showing an invented countdown for a deadline that depends on a future event would be worse than showing none. The availability date is entered when filing the 72-hour update; from then the expiry appears and the re-anchoring stays on the record.

How the clock works

The clock shows time left, the moment of awareness, the computed expiry and the reference window of the current phase. The countdown ticks in the browser but is anchored to the expiry computed by the server: reloading, changing device or changing time zone does not move it.

More than 4 hoursMore than 4 hours left.
Less than 4 hoursUnder 4 hours.
Deadline passedDeadline missed: the clock reads «expired» and does not reset. The delay stays visible and recorded.

Automatic reminders

For the current phase the scheduler evaluates the open deadlines periodically and sends alerts to the escalation chain. Each alert is sent once per case, phase and recipient, and leaves a registry row.

MomentWho receives itWhy
Clock startedContact, deputyThe deadline is running: everyone should know at once.
16 hours leftContactFirst reminder, still in time to organise.
4 hours leftContact, deputyThe window narrows: the deputy comes in.
1 hour leftContact, deputy, legal representativeReal risk of missing it: counsel must know before, not after.
No response on the caseContact, deputy, counselNobody has opened the case for too long while a deadline was running.
Deadline missedContact, deputy, counselAn overrun is documented, not hidden.
Re-check reminderContactA «suspended» verdict is still waiting for elements.

Declaring taking charge on the case suspends escalation towards the deputy and counsel for that deadline: use it when the contact really is on it.

Time zones and moments

Moments are stored in UTC and displayed in Italian local time; in the registry they appear as DD/MM HH:MM. The count is in whole hours from the moment of awareness: 24 hours from an event at 22:30 expire at 22:30 the next day, not at the end of the working day.

The 24 hours know nothing of weekends or public holidays. If the named contact cannot be reached on a Saturday, the cover does not exist: revise the escalation chain, not the clock.

If the moment of awareness changes

Correcting the moment of awareness immediately recomputes the early-warning expiry, requires a justification, stays on the record with old and new values, and generates an alert to the contact and the legal representative. If the shift puts the expiry in the past, the clock reads «expired» at once: that is information, not a software failure.

After fulfilment

Once the final report is filed, the case moves to fulfilled and has no running deadlines. The evidence remains: registry, receipts and dossier. An alert reminds you when the end of the dossier's retention period approaches (see Personal data and retention).

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu