A reporting runbook can fail before anyone reaches an external form. The usual reporter may be unavailable, an internal evidence store may be inaccessible, or the only approver may be in another time zone. Those are continuity problems the manufacturer can address without making assumptions about a provider’s current account or validation workflow.

Start from the governing clock

Article 14 sets a staged sequence. The manufacturer must submit an early warning without undue delay and, in any event, within 24 hours of awareness. A fuller notification follows without undue delay and, in any event, within 72 hours. A final report then follows on the timetable for the applicable vulnerability or severe-incident track.

Treat those limits as the boundary for an internal access plan. Do not subtract investigation time from a deadline and assume the remainder is available for resolving account ownership, internal permissions, or approvals.

Map access dependencies by role

Write down the internal actions required to take a case from a triage decision to retained submission evidence. A useful map distinguishes four roles:

  • the incident manager who owns the live clock and case record;
  • the reporter who converts approved facts into a submission;
  • the approver who authorises the external statement; and
  • the evidence custodian who retains the filed snapshot and receipt.

For each role, name a primary and a backup. Record the systems each person must reach, the internal permission owner, and the handoff condition. This is not an instruction to share credentials. Each person should use an individually governed access path under the organisation’s security rules.

Build a minimum handoff packet

The backup should not have to reconstruct the case from chat history. Prepare a controlled packet containing the legal manufacturer name, product identity, reporting track, awareness timestamp and basis, deadline calculation, approved facts, known unknowns, approver, and evidence-retention location.

Keep draft content separate from filed evidence. The draft may continue to change as the investigation develops. The retained snapshot must show exactly what the organisation authorised and submitted at a particular stage.

Exercise the failure, not an external service

Run an internal tabletop in which the primary reporter becomes unavailable shortly before a simulated handoff. Ask the backup to locate the packet, identify the remaining approval, and produce the evidence that would be retained after submission. Stop before sending anything externally.

Test a second scenario in which the evidence repository or normal communication channel is unavailable. The team should know the authorised fallback location and who can invoke it. Record gaps as owners and due dates rather than silently treating the exercise as passed.

Keep provider details outside the durable rule

Account setup, interface steps, and validation practices can change. Store any verified operational instructions in a dated appendix and recheck the official service guidance before a real filing. Do not elevate a screenshot or third-party walkthrough into the legal rule.

The durable part of the runbook is the responsibility chain: who owns the clock, who can prepare the approved statement, who can take over, and where the organisation preserves proof of the handoff and filing.

Continue this workflow with the responsibility map and the after-hours escalation chain.