Tool Free self-assessment

Check your product's CRA readiness without sending your answers.

Twenty-five questions organise five areas. The result is calculated in your browser and distinguishes existing material, unsupported assertions and genuine gaps.

This is an initial self-assessment, not a conformity assessment or legal opinion. · Last updated: July 2026 · Basis: Regulation (EU) 2024/2847

CRA maturity self-assessment

28 questions, about 10 minutes. Instant on-screen result.

Scored in your browser. We do not store your answers.

Does the Cyber Resilience Act apply to my company?

The CRA, or Cyber Resilience Act (Regulation (EU) 2024/2847), applies to manufacturers, importers and distributors of products with digital elements made available on the EU market: hardware, IoT devices, embedded systems and software that connects to a device or network. If you only buy and use such products, the manufacturer obligations do not fall on you.

What product classes does the CRA define?

The product class determines the conformity assessment route. The CRA distinguishes:

Product classWhat it meansConformity assessment
Default productProducts not listed in Annex III or IV (most products with digital elements)Usually the manufacturer's self-assessment
Important product (class I or II)Higher-risk categories listed in Annex IIIDepending on the class: harmonised standards or the involvement of a notified body
Critical productCategories listed in Annex IVThird-party certification

Classifying a specific product family requires an individual analysis; the check assesses process maturity, while product classification is part of the CRA Snapshot service.

What are the CRA deadlines?

  • The Regulation entered into force on 10 December 2024.
  • The vulnerability and incident reporting obligations (art. 14) apply from 11 September 2026.
  • The provisions on notified bodies apply from 11 June 2026.
  • Full application and CE marking from 11 December 2027.

What does this self-assessment measure?

The self-assessment methodology is based on the SME Cyber Resilience Maturity Assessment Model published by ENISA (the EU Agency for Cybersecurity) in July 2026. The check assesses maturity across the 5 domains of that model: governance and documentation, risk management and security by design, vulnerability and patch management, product lifecycle management, and awareness and competence. You rate each question on a 1–5 scale, and the result is the average of your answers mapped to one of three levels: BASIC (1.0–2.5), INTERMEDIATE (2.6–3.9), ADVANCED (4.0–5.0). The result does not constitute an assessment or endorsement by ENISA.

Frequently asked questions about the CRA check

Does the check result mean CRA compliance?

No. The result is indicative and informational only. It is not a conformity assessment, certification or legal advice. It helps identify gaps and plan preparations; a binding assessment requires an individual product analysis.

Are my answers stored?

No. The result is calculated in your browser and your answers are not sent to the server. Only if you request the full report by email do you share your email address and the self-assessment result with us.

How long does it take and what do I get?

About 10 minutes: 3 scope questions and 25 practice questions. You immediately see your maturity level, a chart of the 5 domains and the biggest gaps. Optionally, you can request a free email report with an action map matched to your level.

How is the check different from the CRA Snapshot?

The check is a free self-assessment of your processes. The CRA Snapshot is a paid service: classification of a specific product family, gap analysis against Annex I, art. 14 readiness and a 60–90 day action plan.

Book a short call →