Reviewed 17 August 2026
CRA Article 14 reporting checklist for a tabletop exercise
Use this checklist for preparation, not as a substitute for the legal text or the Single Reporting Platform.
| Stage | Information to prepare |
|---|---|
| Scope and clock | Organisation role; product with digital elements; EU availability; awareness time; event type; main establishment; responsible owner and deputy. |
| 24-hour preparation | Event type; awareness time; Member States where the product is available; for severe incidents, an initial view of suspected unlawful or malicious acts; platform access; approval and routing. |
| 72-hour preparation | Product identification; affected versions; nature of vulnerability/exploitation or incident; initial severity and impact; measures taken/planned; user mitigation; sensitivity and handling; sources and approvers. |
| Final preparation | Corrective/security update for a vulnerability, or threat/root cause and complete mitigation for an incident; severity/impact; release and communication evidence; final owner. |
| Governance | RACI; safe evidence channel; correction process; supplier contacts; communications; after-action log. |
Unknown is a valid tabletop answer. It should become an assigned action, not a guessed fact. Never paste live exploit data into a generic checklist.
Reviewed 17 August 2026 · assessment version 1.0.0