InsideCRA
InsideCRA › Topics › User notification

Topic

User notification

Telling users, separately from telling authorities.

After becoming aware of an actively exploited vulnerability or a severe incident, the manufacturer informs impacted users — and where appropriate all users — about it and about corrective measures F-032. This runs separately from the authority-facing track with its 24-hour and 72-hour clocks F-028.

Two audiences, two jobs

The authority notification is structured and platform-mediated; the user notification is a communication problem: reach the people running the product, tell them what to do F-032. Annex II quietly sets up the channel in advance — the user information includes a single point of contact for vulnerability reporting and manufacturer contact details F-020.

What good looks like

A pre-written notification template, a tested delivery channel, and a decision tree for "impacted users" versus "all users" F-032. None of that can be improvised well at hour 20 of an incident.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

This area is still moving. Track changes with CEMarque Watch.