Notification type (vulnerability / incident)
Agree the occurrence-routing owner and preserve the decision basis.
FREE · BROWSER-ONLY · ENISA Q16 FIELDS
PRIVATE REHEARSAL · CHECKED 01 AUG 2026
Codes and field names follow ENISA's 17 July Q16 table. Preparation prompts are independent workflow suggestions.
Severe security incident
Agree the occurrence-routing owner and preserve the decision basis.
Map each stage to an approver and a submission handoff.
Keep the legal name and role source available to the reporting team.
Maintain an unambiguous product and version identifier.
Keep a current market list with a named source of truth.
Use a neutral internal naming convention that avoids unsupported conclusions.
Define the escalation path for a cautious, evidence-based first assessment.
PUBLISHED CODES
Required in the selected stage.
Required when the information is available.
Carried forward by default or updated.
Supplied by the platform and not visible.
May be supplied at this stage.
SECURITY + LEGAL BOUNDARY
PUBLIC EVIDENCE · VERIFIED 01 AUG 2026
FROM BRIEF TO FULL DRILL
The $59 CRA Incident Reporting Drill Kit is an offline browser workspace with a deadline engine, owner and evidence fields, JSON portability, tests, and a print packet.