# Notification Log — CVD-2026-0012

**Incident:** CVD-2026-0012 — path-traversal in artifact-serving endpoint
**Organisation:** Meridian Systems
**Scribe:** Pieter van den Berg
**T0 (exploitation corroborated):** 2026-04-08 10:23 UTC
**Last updated:** 2026-04-11 11:00 UTC
**Classification:** Internal — incident-restricted. *All entities, companies, contacts, and regulatory details are fictional.*

---

## Stage 4 — Nine notification clocks

Six of the nine tasks carry statutory deadlines. The remaining three have no fixed clock but are tracked here as live obligations. The "due (UTC)" column is the hard deadline; "filed at (UTC)" is when the filing was actually submitted. The Scribe owns this table; the IC reviews it at the Stage 4 close.

| # | Task | Obligation | T0-relative due | Due (UTC) | Filed at (UTC) | Owner | Status |
|---|---|---|---|---|---|---|---|
| 1 | `notify-enisa-early-warning` | EU CRA Art. 14(2): early warning of actively exploited vulnerability to ENISA | T0+24h | 2026-04-09 10:23 | 2026-04-09 08:47 | Lena Hartmann | Filed |
| 2 | `notify-enisa-vuln-report` | EU CRA Art. 14(2): vulnerability report to ENISA | T0+72h | 2026-04-11 10:23 | 2026-04-11 10:01 | Lena Hartmann | Filed |
| 3 | `notify-nis2-early-warning` | NIS 2 Art. 23(1): early warning to competent authority | T0+24h | 2026-04-09 10:23 | 2026-04-09 09:15 | Lena Hartmann | Filed |
| 4 | `notify-nis2-incident` | NIS 2 Art. 23(4): incident notification to competent authority | T0+72h | 2026-04-11 10:23 | 2026-04-11 09:33 | Lena Hartmann | Filed |
| 5 | `notify-gdpr-authority` | GDPR Art. 33: notification to supervisory authority (BE DPA) | T0+72h | 2026-04-11 10:23 | **2026-04-11 10:17** | Rachel Stern | Filed — 6 minutes before deadline |
| 6 | `notify-data-subjects` | GDPR Art. 34 (if applicable): communication to data subjects | No fixed deadline | — | Pending | Rachel Stern | Pending legal assessment |
| 7 | `notify-customers` | Sint-Aldegonde and NDIA — see note below | T0+18h operational target | 2026-04-09 04:23 | **2026-04-08 19:22** | Carmen Vidal | Filed early — see note |
| 8 | `notify-funding-body` | Grant terms clause 14.2: NDIA programme notification | T0+48h | 2026-04-10 10:23 | 2026-04-09 14:30 | Carmen Vidal | Filed |
| 9 | `notify-reporter` | CVD acknowledgement and status update to reporter | No fixed deadline | — | 2026-04-09 10:00 | Lena Hartmann | Filed |

---

## Notes

**Row 5 — GDPR Art. 33 (6 minutes before the hard deadline):** The filing was ready by 09:00 on 2026-04-11, but it went through three legal review cycles due to uncertainty about whether Meridian holds personal data in its own capacity as a controller (separate from its processor role for Sint-Aldegonde). The confirmed position — that Meridian's own HR and recruitment data held on the compliance platform is in scope — was not established until 2026-04-11 06:00, after the Stage 3 audit log review ruled out any doubt. Rachel Stern filed at 10:17 UTC, 6 minutes before the T0+72h deadline. Corrective action CA-5 (RCA document) addresses the pre-mapping gap.

**Row 7 — Customer notification filed at T+8h59m:** Sint-Aldegonde Hospital Group is a NIS 2 essential entity. Under Art. 23, their own 24-hour early-warning clock starts from the moment they receive Meridian's notification — not from T0. Filing at T+18h would leave Sint-Aldegonde fewer than 6 hours to brief their security officer, prepare their filing, and submit. Stage 2 resolved that customer notification must clear by T+18h; Carmen Vidal filed at T+8h59m to give Sint-Aldegonde a full working shift. NDIA was notified in the same batch.

**What customers received:** Both customers received: (1) a plain-language description of the vulnerability and the exposure window (2026-03-12 to 2026-04-08 14:45 UTC); (2) a list of evidence records accessible to the exposed token that belong to their account, with hash-verification status; (3) Meridian's assessment of what was accessed during the exposure window (three targeted reads, no write operations detected); (4) confirmation that the vulnerable endpoint had been taken offline and all exposed credentials rotated (the customer-facing patch was still in preparation under the release freeze at the time of notification); (5) a copy of the regulatory scope memo, redacted to their own regulatory position. Sint-Aldegonde received these materials at 19:22 UTC on 2026-04-08, giving their legal and security teams the overnight hours to prepare their own Art. 23 early-warning filing.

---

**Prepared by:** Pieter van den Berg, Scribe
**Reviewed by:** Lena Hartmann (IC) at Stage 4 close, 2026-04-11 11:00 UTC
**Status:** Stage 4 complete. Row 6 (`notify-data-subjects`) remains open pending Rachel Stern's Art. 34 assessment, tracked outside this flow.
