| Stage | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | without undue delay and within 24 hours of awareness | without undue delay and within 24 hours of awareness |
| Notification | without undue delay and within 72 hours of awareness | without undue delay and within 72 hours of awareness |
| Final report | no later than 14 days after a corrective or mitigating measure becomes available | within one month after the 72-hour notification |
Prepare
- manufacturer/steward legal name and contacts; product, versions and category;
- main establishment and Member States where the product was made available;
- detection time and organisational-awareness time;
- concise description, severity, impact, affected data, functions and users;
- for vulnerabilities, CVE/EUVD if available, nature of vulnerability/exploit and evidence of active exploitation;
- for incidents, probable cause and whether unlawful or malicious action is suspected;
- completed and planned measures, user guidance and expected fix availability;
- information-sensitivity assessment and an available contact.
Assign a process owner and backups, check who has assigned JISKB access, and rehearse an out-of-hours scenario. Select the correct entry point through the SK-CERT route page: a CRA-related vulnerability is directed to CVD, while the incident route differs according to JISKB access. ENISA’s SRP FAQ also describes the current information set. Follow the fields and instructions in the selected channel.