≈ 20 minutes

Cyber Resilience Act compliance assessment

Around fifteen questions about your product and your practices. At the end: your product's CRA classification, the obligations attached to your economic role, and a gap register sorted by deadline and severity.

What you get at the end

A reasoned classification

Default category, class I, class II, critical product or out of scope — with the conformity assessment procedure that follows from it and the article or annex the conclusion rests on.

Your obligations by role

Manufacturer, importer, distributor or open-source steward: the list of obligations that fall to you, each with its deadline.

A prioritised gap register

Your current practices measured against the essential requirements across eight areas — component inventory, vulnerability management, reporting, security updates, secure design, documentation, support period, governance — sorted by deadline and severity, with an effort estimate.

What is worth having to hand

Nothing is mandatory, but the assessment is more accurate if you already know: what the product does and how it connects, whether it falls under sector-specific rules (medical, automotive, aviation, marine), what you do with it on the European market, and where your security practices stand.

Loading…

CRA compliance assessment — FirmVox