Skip to content
CRA Navigator

Questionnaires

Four assessments, each mapped to the requirement text

Every question traces back to a specific article of Regulation (EU) 2024/2847 or a requirement of IEC 62443-4-1, so the result tells you what to fix rather than how you scored.

Available
4 questionnaires
Format
No account needed
Output
Scored gap list
  • Assessment 01

    CRA Readiness Assessment

    A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the vulnerability handling and reporting obligations that apply from September 2026.

    Length
    12–18 minutes
    Questions
    48 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • Product scope and Annex III / Annex IV classification
    • Annex I Part I essential cybersecurity requirements
    • Annex I Part II vulnerability handling processes
    • Software bill of materials coverage and format
    • Coordinated vulnerability disclosure policy
    • Actively exploited vulnerability reporting readiness
    • Security update delivery and support period
    • Technical documentation and conformity assessment route
  • Assessment 02

    IEC 62443-4-1 Gap Assessment

    A practice-by-practice gap assessment against all eight practices of IEC 62443-4-1, scored against the maturity levels used by certification bodies during audit.

    Length
    15–25 minutes
    Questions
    42 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • SM — Security management
    • SR — Specification of security requirements
    • SD — Secure by design
    • SI — Secure implementation
    • SVV — Security verification and validation testing
    • DM — Management of security-related issues
    • SUM — Security update management
    • SG — Security guidelines
  • Assessment 03

    Product Classification Check

    A short triage questionnaire that determines whether your product falls in scope of the CRA, and if so, whether it is a default, important class I, important class II, or critical product.

    Length
    4–6 minutes
    Questions
    Up to 14 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • Products with digital elements in scope
    • Remote data connection criteria
    • Annex III important product categories
    • Annex IV critical product categories
    • Applicable conformity assessment route
    • Exclusions and sector-specific carve-outs
  • Assessment 04

    SBOM Readiness Assessment

    A focused assessment of the software bill of materials your product ships with, reporting separately on what Annex I Part II(1) actually requires and how much operational use you get from the SBOM you have.

    Length
    5–8 minutes
    Questions
    14 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • SBOM coverage across the products you place on the EU market
    • Dependency depth, and why transitive coverage is not mandatory
    • Machine readability and the SPDX / CycloneDX question
    • Whether the SBOM matches the artefact you actually shipped
    • Build-time generation as the way accuracy is sustained
    • Vulnerability monitoring against the components you ship
    • Retention and disclosure to market surveillance authorities