# CRA Article 14 — 72-hour Notification

> **Purpose**: Second-stage notification providing general information and an initial assessment.  
> **Deadline**: Without undue delay, in any case **within 72 hours** of the manufacturer becoming aware.  
> **Precondition**: The Early Warning has already been submitted for this case.  
> **Source**: ENISA SRP FAQ Q16 (v. 03/08/2026). Fields marked **X = Obligatory**, **I = Obligatory if info available**, **C = Copied from previous step and updatable**, **O = Optional**.

---

## 1 · Metadata (copied from Early Warning — update if needed)

| # | Field | Value |
|---|---|---|
| 1 | Notification type | *Vulnerability / Incident* |
| 2 | Notification level | **72h Notification** |
| 7 | Name of manufacturer / OSS steward | |
| 8 | Product | |
| 9 | Product Type | |
| 10 | Product Category (Annex III / IV) | |
| 11 | Member States where product available | |
| 12 | Title | |

---

## 2 · Vulnerability track — obligatory fields (X)

| # | Field | Value |
|---|---|---|
| v13 | CVE ID (**O**) | *if assigned* |
| v14 | EUVD ID (**O**) | *if assigned* |
| v15 | General information (overview) | |
| v16 | a. General nature of the vulnerability | *e.g. authentication bypass in web management UI* |
| v17 | b. General nature of the exploit | *e.g. crafted HTTP POST triggers session takeover; no auth required* |
| v18 | Corrective / mitigating measures **taken** by the manufacturer | *e.g. temporary WAF rule pushed to cloud instances* |
| v19 | Measures **users can take** | *e.g. disable remote management until patch is available* |
| v20 | Considered sensitivity of information (**I**) | *e.g. Low / Medium / High — with rationale* |

---

## 3 · Incident track — obligatory fields (X)

*Fill only if this notification concerns an incident, not a vulnerability.*

| # | Field | Value |
|---|---|---|
| i13 | Suspected to be caused by unlawful / malicious acts | *Yes / No / Unknown* |
| i14 | General information about the nature of the incident | |
| i15 | Date & time when the incident was detected (UTC) | |
| i16 | Date & time when the incident occurred (UTC) | *if known* |
| i17 | Initial assessment (impact, scope, likely cause) | |
| i18 | Corrective / mitigating measures taken | |
| i19 | Measures users can take | |
| i20 | Considered sensitivity of information (**I**) | |

---

## 4 · Particularly Exceptional Circumstances (PEC) — CRA Art. 16(2)

- [ ] Not applied — ENISA receives the full 72 h notification content.
- [ ] Applied — flag one or more of Art. 16(2) points (a), (b), (c) as per Commission Delegated Regulation C(2025)8407. In this case ENISA initially receives only partial information.

**Justification for PEC (if applied):** *concise rationale*

---

## 5 · Approvals

| Role | Name | Signed off |
|---|---|---|
| Primary AR | | |
| Product Security Lead | | |
| Legal / Compliance | | |
| PR / Customer Comms | | |

---

*Template compiled by NexTech.Law from ENISA SRP FAQ Q16 and CRA Art. 14(2)(b) / 16(2). General guidance only — not legal advice.*
