Assessment 01
CRA Readiness Assessment
A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the vulnerability handling and reporting obligations that apply from September 2026.
- Length
- 12–18 minutes
- Questions
- 48 questions
What it covers
- Product scope and Annex III / Annex IV classification
- Annex I Part I essential cybersecurity requirements
- Annex I Part II vulnerability handling processes
- Software bill of materials coverage and format
- Coordinated vulnerability disclosure policy
- Actively exploited vulnerability reporting readiness
- Security update delivery and support period
- Technical documentation and conformity assessment route
Built for
Product security officers, compliance leads, engineering managers
What you get back
A scored readiness profile across eight domains, your likely product class, and a prioritised gap list mapped to specific CRA articles.
Complete the questionnaire
Answer as your product stands today rather than as you intend it to be. An accurate baseline produces a usable remediation plan.
No email address. No registration. No account.
You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.
CRA Readiness Assessment
Forty-eight questions across the eight areas the Cyber Resilience Act holds manufacturers to. You will get a score for each area, a prioritised list of gaps, and the specific article behind each one.
No email address, no registration, no account. Everything runs in your browser: nothing you enter is sent anywhere, stored on our servers, or seen by us.
Your answers are kept in this browser tab while you work, so a reload will not lose them. Closing the tab clears them.
Other assessments
Assessment 02
IEC 62443-4-1 Gap Assessment
A practice-by-practice gap assessment against all eight practices of IEC 62443-4-1, scored against the maturity levels used by certification bodies during audit.
OpenAssessment 03
Product Classification Check
A short triage questionnaire that determines whether your product falls in scope of the CRA, and if so, whether it is a default, important class I, important class II, or critical product.
OpenAssessment 04
SBOM Readiness Assessment
A focused assessment of the software bill of materials your product ships with, reporting separately on what Annex I Part II(1) actually requires and how much operational use you get from the SBOM you have.
Open