Cyber Resilience Act compliance assessment
Around fifteen questions about your product and your practices. At the end: your product's CRA classification, the obligations attached to your economic role, and a gap register sorted by deadline and severity.
- Deterministic classification: identical answers, identical verdict.
- Every conclusion points to the article or annex of Regulation (EU) 2024/2847.
- Free, no sign-up. Your answers stay in your browser until you save the report.
What you get at the end
A reasoned classification
Default category, class I, class II, critical product or out of scope — with the conformity assessment procedure that follows from it and the article or annex the conclusion rests on.
Your obligations by role
Manufacturer, importer, distributor or open-source steward: the list of obligations that fall to you, each with its deadline.
A prioritised gap register
Your current practices measured against the essential requirements across eight areas — component inventory, vulnerability management, reporting, security updates, secure design, documentation, support period, governance — sorted by deadline and severity, with an effort estimate.
What is worth having to hand
Nothing is mandatory, but the assessment is more accurate if you already know: what the product does and how it connects, whether it falls under sector-specific rules (medical, automotive, aviation, marine), what you do with it on the European market, and where your security practices stand.
Loading…