Reportable — actively exploited
Honeypot evidence of in-the-wild use since 30 July qualifies this as an actively exploited vulnerability, which triggers the reporting duty. Reference: (Art. 14(1)).
This is the document CRAnotify exports when an inspector asks you to prove what you did, and when. Below is a full, made-up case — an actively exploited vulnerability, a 24-hour early warning, a 72-hour notification to the national CSIRT and ENISA, the receipts and a register that is append-only, with detectable alterations. Every figure here is invented for the demo.
Sample This is a demonstration document with fictional data. It is not a real compliance record and does not refer to any real company or filing.
Defensive dossier · fictional data
Economic operator
Acme Controls S.r.l.
VAT IT-09821440158 · Via Meucci 14, 20090 Segrate (MI), Italy
Org. ID ORG-8F42-AC
Drawn up by
M. Ferri — Product Security
Generated on 06/08/2026 11:04 CEST
Awareness deadline (72h)
04/08/2026 09:12 CEST · Fingerprint 7c1af93b
Sample document reproducing the layout of a defensive copy generated from the activity register. It carries invented data, is for demonstration only, and does not replace any act filed with the authorities.
| Product | Acme EdgeGate 200 — connected industrial gateway (PLC / edge controller) |
|---|---|
| Affected version | Firmware 3.4.1 and earlier (3.x branch) |
| Identifier | CVE-2026-41287 · CWE-288 (authentication bypass) · CVSS 9.8 |
| Qualification | Actively exploited vulnerability (Art. 14(1)) |
| Coordinator CSIRT | CSIRT Italia (ACN) — ENISA single reporting platform |
Channel
coordinated vulnerability disclosure (PSIRT inbox)
Reference
ACME-VDP-2026-0044
Received
01/08/2026 09:12 CEST · reporter: external security researcher (PGP-signed)
“The web management interface of EdgeGate 200 (fw 3.4.1) accepts a crafted session token that skips the login check. I am attaching a proof of concept. I am also seeing the same request pattern in honeypot logs since 30 July, so this looks like it is already being used in the wild.”
Honeypot evidence of in-the-wild use since 30 July qualifies this as an actively exploited vulnerability, which triggers the reporting duty. Reference: (Art. 14(1)).
(Art. 14(2)(a))(Art. 14(2)(b))(Art. 14(2)(c))(Art. 14(8))The deadlines run from the moment of awareness — fixed at 01/08/2026 09:12 CEST, when the report was received and read. Each step below was filed before its deadline.
| 01/08 · 09:12 | Awareness fixed — the clock starts | T0 · Art. 14(2) |
|---|---|---|
| 01/08 · 21:40 | Early warning filed (12h 28m — within 24h) | Art. 14(2)(a) · prot. CSIRT IT-EW-2026-13720 |
| 03/08 · 15:20 | 72h notification filed (54h 08m — within 72h) | Art. 14(2)(b) · prot. CSIRT IT-NT-2026-13891 |
| 03/08 · 16:05 | Affected users informed (advisory ACME-SA-2026-07) | Art. 14(8) |
| — scheduled | Final report — due within 14 days of the fix | Art. 14(2)(c) · fw 3.4.2 in preparation |
Filing receipt
CSIRT Italia (ACN) · ENISA
Status
Accepted
Platform
ENISA single reporting platform
Protocol
IT-NT-2026-13891
Filed
03/08/2026 15:20 CEST
Recipients
CSIRT Italia + ENISA (simultaneous, Art. 14(1))
Receipt fingerprint
e5d0a9f4c6b2e183…7b4e63
In the real product this row links to the downloadable PDF receipt returned by the platform. Here the file is omitted — it is a sample.
Every entry carries an identifier computed with sha256 over the previous identifier plus its own time, content and references. Change one field and its identifier changes, breaking every link after it — so reordering or deletion is detectable.
| Entry | Event | prev_hash → hash |
|---|---|---|
| R-0001 01/08 09:12 | Report received (ACME-VDP-2026-0044) | 00000000 → 7c1af93b |
| R-0002 01/08 10:48 | Triage — actively exploited (Art. 14(1)) | 7c1af93b → e5d0a9f4 |
| R-0003 01/08 21:40 | Early warning filed (Art. 14(2)(a)) | e5d0a9f4 → 1a4f6c3b |
| R-0004 03/08 15:20 | 72h notification filed (Art. 14(2)(b)) | 1a4f6c3b → 9c7b4e63 |
Chain excerpt — entry R-0004 (full digests)
prev_hash 1a4f6c3b8e2d5a0f9c7b4e63d0a9f4c6b2e1837a4f1c9b3d6e0a2f8c5b7e9d21 hash 9c7b4e63d0a9f4c6b2e1837a4f1c9b3d6e0a2f8c5b7e9d1a4f6c3b8e2d5a0f97
Fictional but well-formed digests, for illustration only.
A real dossier reproduces the data retained in the CRAnotify activity register. Each entry carries an identifier computed from its time, content and references; any alteration produces a different identifier, so the chain is tamper-evident. This copy is a demonstration with fictional data.
Catalogue your products, keep a receiving channel open, and CRAnotify assembles the register and the dossier as you go — exportable to PDF in one click, in a drill too.
No result for “”.
Try an article of the regulation (Art. 13, Art. 14), a product term (dossier, registry, SBOM), or write to support@cranotify.eu.