Skip to content
11 days until the Art. 14 reporting obligation (11 September 2026).
Documentation Support Risk class
00CRAnotify · Sample — fictional data

What a defensive dossier looks like

This is the document CRAnotify exports when an inspector asks you to prove what you did, and when. Below is a full, made-up case — an actively exploited vulnerability, a 24-hour early warning, a 72-hour notification to the national CSIRT and ENISA, the receipts and a register that is append-only, with detectable alterations. Every figure here is invented for the demo.

Print → Save as PDF

Sample This is a demonstration document with fictional data. It is not a real compliance record and does not refer to any real company or filing.

Defensive dossier · fictional data

Case file CRA-IT-2026-08-000184

Reg. (EU) 2024/2847
Art. 14
Fingerprint 7c1af93b
Masthead

Economic operator

Acme Controls S.r.l.
VAT IT-09821440158 · Via Meucci 14, 20090 Segrate (MI), Italy
Org. ID ORG-8F42-AC

Drawn up by

M. Ferri — Product Security
Generated on 06/08/2026 11:04 CEST

Awareness deadline (72h)

04/08/2026 09:12 CEST · Fingerprint 7c1af93b

Sample document reproducing the layout of a defensive copy generated from the activity register. It carries invented data, is for demonstration only, and does not replace any act filed with the authorities.

Contents
  1. Case and product record
  2. Report received, as it came in
  3. Triage: decision and legal basis
  4. The awareness clock and the deadlines
  5. Notification filed to CSIRT Italia and ENISA
  6. Register with chain of evidence
01

Case and product record

ProductAcme EdgeGate 200 — connected industrial gateway (PLC / edge controller)
Affected versionFirmware 3.4.1 and earlier (3.x branch)
IdentifierCVE-2026-41287 · CWE-288 (authentication bypass) · CVSS 9.8
QualificationActively exploited vulnerability (Art. 14(1))
Coordinator CSIRTCSIRT Italia (ACN) — ENISA single reporting platform
02

Report received, as it came in

Channel

coordinated vulnerability disclosure (PSIRT inbox)

Reference

ACME-VDP-2026-0044

Received

01/08/2026 09:12 CEST · reporter: external security researcher (PGP-signed)

“The web management interface of EdgeGate 200 (fw 3.4.1) accepts a crafted session token that skips the login check. I am attaching a proof of concept. I am also seeing the same request pattern in honeypot logs since 30 July, so this looks like it is already being used in the wild.”
03

Triage: decision and legal basis

Verdict

Reportable — actively exploited

Honeypot evidence of in-the-wild use since 30 July qualifies this as an actively exploited vulnerability, which triggers the reporting duty. Reference: (Art. 14(1)).

Obligations triggered
  • Early warning within 24h (Art. 14(2)(a))
  • Notification within 72h (Art. 14(2)(b))
  • Final report (Art. 14(2)(c))
  • Inform affected users (Art. 14(8))
04

The awareness clock and the deadlines

The deadlines run from the moment of awareness — fixed at 01/08/2026 09:12 CEST, when the report was received and read. Each step below was filed before its deadline.

01/08 · 09:12Awareness fixed — the clock startsT0 · Art. 14(2)
01/08 · 21:40Early warning filed (12h 28m — within 24h)Art. 14(2)(a) · prot. CSIRT IT-EW-2026-13720
03/08 · 15:2072h notification filed (54h 08m — within 72h)Art. 14(2)(b) · prot. CSIRT IT-NT-2026-13891
03/08 · 16:05Affected users informed (advisory ACME-SA-2026-07)Art. 14(8)
— scheduledFinal report — due within 14 days of the fixArt. 14(2)(c) · fw 3.4.2 in preparation
05

Notification filed to CSIRT Italia and ENISA

Filing receipt

CSIRT Italia (ACN) · ENISA

Status

Accepted

Platform

ENISA single reporting platform

Protocol

IT-NT-2026-13891

Filed

03/08/2026 15:20 CEST

Recipients

CSIRT Italia + ENISA (simultaneous, Art. 14(1))

Receipt fingerprint

e5d0a9f4c6b2e183…7b4e63

In the real product this row links to the downloadable PDF receipt returned by the platform. Here the file is omitted — it is a sample.

06

Register with chain of evidence

Every entry carries an identifier computed with sha256 over the previous identifier plus its own time, content and references. Change one field and its identifier changes, breaking every link after it — so reordering or deletion is detectable.

EntryEventprev_hash → hash
R-0001
01/08 09:12
Report received (ACME-VDP-2026-0044)00000000 → 7c1af93b
R-0002
01/08 10:48
Triage — actively exploited (Art. 14(1))7c1af93b → e5d0a9f4
R-0003
01/08 21:40
Early warning filed (Art. 14(2)(a))e5d0a9f4 → 1a4f6c3b
R-0004
03/08 15:20
72h notification filed (Art. 14(2)(b))1a4f6c3b → 9c7b4e63

Chain excerpt — entry R-0004 (full digests)

prev_hash  1a4f6c3b8e2d5a0f9c7b4e63d0a9f4c6b2e1837a4f1c9b3d6e0a2f8c5b7e9d21
hash       9c7b4e63d0a9f4c6b2e1837a4f1c9b3d6e0a2f8c5b7e9d1a4f6c3b8e2d5a0f97

Fictional but well-formed digests, for illustration only.

Sample fingerprint 7c1af93b · Acme Controls S.r.l. · 06/08/2026 11:04 CEST SAMPLE — FICTIONAL DATA

A real dossier reproduces the data retained in the CRAnotify activity register. Each entry carries an identifier computed from its time, content and references; any alteration produces a different identifier, so the chain is tamper-evident. This copy is a demonstration with fictional data.

01Your dossier

Yours would be built the same way — from your own case.

Catalogue your products, keep a receiving channel open, and CRAnotify assembles the register and the dossier as you go — exportable to PDF in one click, in a drill too.