Skip to content
ReadinessNavigator

Assessment 02

CRA Readiness Assessment

A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the Article 14 reporting obligations that apply from 11 September 2026 and the Annex I Part II vulnerability-handling requirements that apply from 11 December 2027.

Length
12–18 minutes
Questions
49 questions

What it covers

  • Product scope and Annex III / Annex IV classification
  • Annex I Part I essential cybersecurity requirements
  • Annex I Part II vulnerability handling processes
  • Software bill of materials coverage and format
  • Coordinated vulnerability disclosure policy
  • Actively exploited vulnerability reporting readiness
  • Security update delivery and support period
  • Technical documentation and conformity assessment route

Built for

Product security officers, compliance leads, engineering managers

What you get back

A scored readiness profile across eight domains, your likely product class, and a prioritised gap list mapped to specific CRA articles.

Complete the questionnaire

Answer as your product stands today rather than as you intend it to be. An accurate baseline produces a usable remediation plan.

No email address. No registration. No account.

You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.

CRA Readiness Assessment

Forty-nine questions across eight areas of CRA readiness. This is a sample of selected requirements, not a check of every CRA obligation. You will get a score for each area, a prioritised list of gaps, and the legal basis where a question reflects a CRA requirement.

Your answers are kept in this browser tab while you work, so a reload will not lose them. Closing the tab clears them.

Other assessments