CRA voluntary reporting is broader than mandatory Article 14 reporting. Article 15 permits notification of vulnerabilities, cyber threats, product-security incidents, and near misses by manufacturers and other natural or legal persons.
That breadth makes a decision procedure useful. Voluntary reporting should not become a way to downgrade a mandatory event, nor should it turn every weak signal into an uncontrolled external disclosure.
Finish the mandatory test first
Record whether the event concerns an actively exploited vulnerability contained in the manufacturer’s product or a severe incident affecting product security. If a mandatory trigger is met, use Article 14 and its deadlines. Do not choose the voluntary route because the facts are inconvenient or the mandatory packet is incomplete.
If the mandatory test is not met or the notifier is not the legal manufacturer, identify which Article 15 category remains: vulnerability, cyber threat affecting a product’s risk profile, incident below the severe threshold, or near miss.
State the coordination purpose
Write a one-sentence objective for the notification. Examples of legitimate purposes include alerting a coordinating body to a vulnerability spanning products, sharing a credible threat that could change product risk, or enabling coordination after a near miss with wider relevance.
Name the expected recipient action without assuming it will occur. A vague desire to “be transparent” is not enough to decide what sensitive technical material should leave the organisation.
Prepare a bounded packet
Include notifier identity and contact route, affected product or component as known, event category, evidence, technical description, dates, current status, coordination already attempted, and requested handling. Separate confirmed observations from analysis and third-party statements.
Remove unrelated personal data, credentials, secrets, and customer material. Article 15 requires confidentiality and appropriate protection by the receiving bodies, but the notifier still needs an internal disclosure review and an authorised transmission path.
If the notifier is not the manufacturer, preserve attempts to contact the manufacturer or maintainer and explain whether urgent risk changes the coordination plan. Avoid premature public disclosure.
Approve and track the choice
Assign product security to validate technical accuracy and legal or policy ownership to approve the external notification. Record why voluntary reporting is proportionate, why Article 14 does not control the filing, which information was withheld, and what would trigger reclassification.
Confirm the current official submission functionality and instructions before filing; operational availability can change independently of the legal permission in Article 15. Retain the submitted content, time, channel, reference, and any response.
Reassess new evidence
A voluntary report does not freeze the case. If later evidence establishes active exploitation or a severe incident for a manufacturer, create the mandatory decision and run the Article 14 sequence from the supported awareness point. Link the two records so authorities and internal reviewers can see the transition.
The result is a voluntary notification with a defined coordination purpose, controlled content, and a clear boundary against mandatory reporting.
Continue this workflow with the two-track triage and the non-reportable decision record.