Skip to content
ReadinessNavigator

Questionnaires

Each assessment mapped to the requirement text

Every question traces back to a specific article or clause of the regulation or standard it covers, so the result tells you what to fix rather than how you scored.

Available
8 questionnaires
Format
No account needed
Output
Scored gap list

Cyber Resilience Act

Framework overview
  • Assessment 01

    Product Classification Check

    A short triage questionnaire that gives an initial indication of whether your product may fall within the CRA and, if so, which product category may apply. Check the indication against your product details and the regulation before choosing a conformity assessment route.

    Length
    4–6 minutes
    Questions
    Up to 14 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • Products with digital elements in scope
    • Remote data connection criteria
    • Annex III important product categories
    • Annex IV critical product categories
    • Applicable conformity assessment route
    • Exclusions and sector-specific carve-outs
  • Assessment 02

    CRA Readiness Assessment

    A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the Article 14 reporting obligations that apply from 11 September 2026 and the Annex I Part II vulnerability-handling requirements that apply from 11 December 2027.

    Length
    12–18 minutes
    Questions
    49 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • Product scope and Annex III / Annex IV classification
    • Annex I Part I essential cybersecurity requirements
    • Annex I Part II vulnerability handling processes
    • Software bill of materials coverage and format
    • Coordinated vulnerability disclosure policy
    • Actively exploited vulnerability reporting readiness
    • Security update delivery and support period
    • Technical documentation and conformity assessment route
  • Assessment 03

    SBOM Readiness Assessment

    A focused assessment of the software bill of materials your product ships with, reporting separately on what Annex I Part II(1) actually requires and how much operational use you get from the SBOM you have.

    Length
    5–8 minutes
    Questions
    14 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • SBOM coverage across the products you place on the EU market
    • Dependency depth, and why transitive coverage is not mandatory
    • Machine readability and the SPDX / CycloneDX question
    • Whether the SBOM matches the artefact you actually shipped
    • Build-time generation as the way accuracy is sustained
    • Vulnerability monitoring against the components you ship
    • Retention and disclosure to market surveillance authorities

IEC 62443-4-1

Framework overview
  • Assessment 04

    IEC 62443-4-1 Gap Assessment

    A practice-by-practice self-assessment against the eight practices of IEC 62443-4-1. Based on your answers, it provides an indicative maturity profile and highlights areas where evidence needs closer review before an audit.

    Length
    15–25 minutes
    Questions
    42 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • SM — Security management
    • SR — Specification of security requirements
    • SD — Secure by design
    • SI — Secure implementation
    • SVV — Security verification and validation testing
    • DM — Management of security-related issues
    • SUM — Security update management
    • SG — Security guidelines

IEC 62443-4-2

Framework overview
  • Assessment 05

    IEC 62443-4-2 Component Gap Assessment

    The technical counterpart to the 62443-4-1 process assessment: a self-assessment against the shared component requirements of IEC 62443-4-2. Based on your answers, it shows an indicative capability security level (SL-C 1–4) for each of the seven foundational requirements; these results have not been independently verified.

    Length
    15–25 minutes
    Questions
    39 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • FR 1 — Identification and authentication control
    • FR 2 — Use control
    • FR 3 — System integrity
    • FR 4 — Data confidentiality
    • FR 5 — Restricted data flow
    • FR 6 — Timely response to events
    • FR 7 — Resource availability
    • How your component profile feeds a 62443-3-3 system assessment
  • Assessment 06

    NIS2 Scoping Check

    A preliminary scoping check for operators, not a maturity score. It uses your answers on sector, size, and exceptions to indicate whether your organisation may fall within NIS2 and whether it may be an essential or important entity. Confirm the result under the applicable national law.

    Length
    3–5 minutes
    Questions
    Up to 6 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • Sectors in Annex I (high criticality) and Annex II
    • Size classification under Recommendation 2003/361/EC
    • The entities in scope regardless of size (Article 2(2))
    • Essential vs. important entity, and what the split changes
    • Registration, reporting, and management-liability duties that follow
    • DORA as lex specialis, CER overlap, and national transposition
    • How NIS2 makes you the buyer demanding CRA and IEC 62443 evidence

RED (EN 18031)

Framework overview
  • Assessment 07

    RED Cybersecurity Readiness

    A readiness assessment against the cybersecurity requirements the Radio Equipment Directive makes mandatory, as harmonised by EN 18031. It scores the network-protection, personal-data, and fraud-prevention objectives of RED Article 3.3 (d), (e) and (f) that apply to internet-connected radio equipment — much of the same connected hardware the CRA already reaches.

    Length
    12–18 minutes
    Questions
    37 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • RED Article 3.3 (d) network protection
    • Article 3.3 (e) protection of personal data and privacy
    • Article 3.3 (f) protection against fraud
    • EN 18031-1 / -2 / -3 security mechanism families
    • Access control, authentication, and secure update mechanisms
    • Secure storage, secure communication, and cryptography
    • Where CRA Annex I evidence can be reused for EN 18031

ISO/IEC 27001

Framework overview
  • Assessment 08

    ISO/IEC 27001 Annex A Readiness

    A readiness and gap self-assessment across the four Annex A:2022 control themes of ISO/IEC 27001. It shows your reported coverage and highlights possible links to NIS2, IEC 62443 and CRA requirements. Each link and its supporting evidence need separate review before being treated as covered.

    Length
    12–16 minutes
    Questions
    36 questions
    Open questionnaire

    No email address. No registration. No account.

    You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

    What it covers

    • Annex A.5 organizational controls (policy, supplier, incident, continuity)
    • Annex A.6 people controls (screening, awareness, remote working)
    • Annex A.7 physical controls (perimeter, equipment, media)
    • Annex A.8 technological controls (access, crypto, logging, backup)
    • The foundational controls that cap the readiness band
    • Crosswalk to NIS2 Article 21(2) management measures
    • Crosswalk to IEC 62443-4-1 and CRA technical obligations

Get in touch

Prefer to talk it through rather than answer a questionnaire?

The assessments give you a result in your browser with nothing sent to us. If you would rather have someone read your situation directly, describe what you build and we will tell you which route fits and where we would begin.

We reply within two working days.

Full contact details
consulting@readinessnavigator.com
Book a 30-minute call

Opens our scheduling page in a new tab — pick a slot that suits you.

Worth including in a first message

  • What the product is, and which assessment you were looking at.
  • Which markets you sell into, and your role — manufacturer, importer, or distributor.
  • Any date you are working towards — a launch, an audit, or a customer deadline.

Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.