Skip to content
ReadinessNavigator

Sample report

What a CRA readiness report looks like

This report was generated by the CRA Readiness Assessment from fictional answers for an illustrative connected product. Your own report is built the same way, entirely in your browser.

Illustrative data

The answers, score and gaps below are an example, not a benchmark and not a real product. Run the assessment to see where your own product stands.

Developing

Your CRA readiness profile

56%

Overall readiness

Developing

Readiness band

Real foundations exist, but there are material gaps in areas that have to be closed before a conformity claim is defensible. Prioritise the critical items, then the high ones.

Product class
Default category
Critical gaps
3

Guidance, not legal advice

This assessment samples selected requirements from Regulation (EU) 2024/2847; it does not check every obligation. It is not a conformity assessment, not an audit, and not legal advice. Scores are our weighting, not a figure defined anywhere in the Regulation. Even a full score does not establish that unasked requirements are met or that the product complies. Verify anything you intend to rely on against the Official Journal text and take qualified advice before making compliance decisions.

Read Regulation (EU) 2024/2847 in the Official Journal

Readiness by section

  • Product scope and classification

    75%

  • Essential cybersecurity requirements

    79%

  • Vulnerability handling

    58%

  • Software bill of materials

    25%

  • Coordinated vulnerability disclosure

    58%

  • Reporting obligations

    42%

  • Security updates and support period

    83%

  • Technical documentation and conformity

    33%

Prioritised gaps

Ordered by severity. Each gap names the provision it comes from so you can go straight to the source text, and gives the recommended next step.

  • Critical · SBOM · Partly in place

    Do you produce a software bill of materials for each product?

    Basis: Annex I Part II(1), Annex II(9)

    Next step: Generate an SBOM for each product covering at least top-level dependencies.

  • Critical · Reporting · Partly in place

    Can you issue an early warning notification within 24 hours of becoming aware of an actively exploited vulnerability?

    Basis: Article 14(2)(a), Article 14(4)(a)

    Next step: Build a 24-hour early-warning runbook with named on-call responsibility and a pre-registered submission route.

  • Critical · Documentation · Partly in place

    Do you compile and maintain technical documentation covering the Annex II and Annex VII requirements?

    Basis: Article 31, Annex VII

    Next step: Compile technical documentation to the Annex VII structure and keep it updated as the product changes.

  • High · Essential requirements · Partly in place

    Do products protect the confidentiality and integrity of stored, transmitted and processed data?

    Basis: Annex I Part I(2)(e), Annex I Part I(2)(f)

    Next step: Encrypt data at rest and in transit using current recommended algorithms, and add integrity checks to critical data.

  • High · Vulnerability handling · Partly in place

    Do you identify and document vulnerabilities in your products on an ongoing basis?

    Basis: Annex I Part II(1)

    Next step: Establish continuous vulnerability monitoring across the support period, with findings tracked in a single register.

  • High · Vulnerability handling · Partly in place

    Do you address and remediate vulnerabilities without delay, including by issuing updates?

    Basis: Annex I Part II(2)

    Next step: Define a remediation process with severity-based target times and a named owner for each stage.

  • High · Vulnerability handling · Partly in place

    Do you apply effective and regular security testing and review of your products?

    Basis: Annex I Part II(3)

    Next step: Establish a recurring security testing schedule and record findings and their resolution.

  • High · SBOM · Partly in place

    Is your SBOM in a commonly used machine-readable format?

    Basis: Annex I Part II(1)

    Next step: Emit SBOMs in SPDX or CycloneDX from your build pipeline rather than maintaining them by hand.

  • High · SBOM · Partly in place

    Do you monitor your SBOM against vulnerability databases on an ongoing basis?

    Basis: Annex I Part II(1), Annex I Part II(2)

    Next step: Connect your SBOM to automated vulnerability feed monitoring with alerts routed to a named owner.

  • High · Reporting · Partly in place

    Do you know which CSIRT is your coordinator and how to submit a notification?

    Basis: Article 14(1), Article 16

    Next step: Identify your coordinating CSIRT, confirm the submission route and record it in your incident runbook.

  • High · Reporting · Partly in place

    Can you submit a full vulnerability or incident notification within 72 hours?

    Basis: Article 14(2)(b), Article 14(4)(b)

    Next step: Prepare a 72-hour notification template capturing severity, impact and corrective measures.

  • High · Reporting · No, not in place

    Can you inform affected users about an exploited vulnerability or severe incident without undue delay?

    Basis: Article 14(8)

    Next step: Establish a user notification channel and confirm you can actually reach affected users, including via distribution.

  • High · Reporting · I do not know

    Do you have a process for identifying and escalating severe incidents affecting product security?

    Basis: Article 14(3), Article 14(4)

    Next step: Define severe incident criteria and an escalation path that reaches the reporting owner within hours.

  • High · Updates · Partly in place

    Is the support period, including its end date, communicated clearly to buyers before purchase?

    Basis: Article 13(8), Annex II(7)

    Next step: Publish the support end date in your product information and at the point of sale.

  • High · Documentation · No, not in place

    Do you draw up an EU declaration of conformity for each product?

    Basis: Article 28, Annex V

    Next step: Draw up an EU declaration of conformity to the Annex V content requirements and retain it for 10 years.

  • High · Documentation · Partly in place

    Do you affix CE marking correctly, following the rules in Article 30?

    Basis: Article 29, Article 30

    Next step: Apply CE marking per Article 30, including the notified body number where one was involved.

  • High · Documentation · Partly in place

    Have you selected and documented the conformity assessment procedure you will use?

    Basis: Article 32, Annex VIII

    Next step: Decide your conformity route now, and if a notified body is needed, approach one early — capacity is constrained.

  • Medium · Scope · Partly in place

    Do you have a defined process for judging when a change counts as a substantial modification?

    Basis: Article 3(41), Recital 39

    Next step: Write a decision rule for substantial modification and add it to your change-control process.

  • Medium · Scope · Partly in place

    Have you mapped your product plans against the Regulation’s application dates?

    Basis: Article 71

    Next step: Map each product’s release plan against 11 September 2026 and 11 December 2027, and identify what must be ready first.

  • Medium · Essential requirements · Partly in place

    Have you assessed and minimised any negative impact your product or connected devices could have on the availability of services provided by other devices or networks?

    Basis: Annex I Part I(2)(i)

    Next step: Assess how the product or connected devices could affect other devices’ or networks’ service availability; document applicability and mitigate credible impacts.

  • Medium · Essential requirements · Partly in place

    Do products record and monitor relevant internal security activity, with a user opt-out?

    Basis: Annex I Part I(2)(l)

    Next step: Add recording and monitoring of relevant internal activity with a user opt-out mechanism.

  • Medium · Vulnerability handling · No, not in place

    Do you publish information about fixed vulnerabilities once an update is available?

    Basis: Annex I Part II(4), Annex I Part II(6)

    Next step: Set up a public security advisory channel and publish an advisory with each security release.

  • Medium · SBOM · No, not in place

    Does your SBOM cover transitive dependencies, not only direct ones?

    Good practice — not required by the CRA

    Next step: Consider extending SBOM generation to the full dependency tree. The top level satisfies the Regulation; the deeper tree is what makes vulnerability triage fast.

  • Medium · SBOM · No, not in place

    Is SBOM generation automated as part of your build or release pipeline?

    Good practice — not required by the CRA

    Next step: Consider moving SBOM generation into CI so it is produced automatically for every build. The Regulation cares that the SBOM is accurate, not how it is produced — but a hand-maintained one rarely stays accurate.

  • Medium · SBOM · No, not in place

    Do you report vulnerabilities you find in third-party components to their maintainers?

    Basis: Annex I Part II(5)

    Next step: Define a route for reporting upstream findings to component maintainers and contributing fixes back.

  • Medium · Disclosure · Partly in place

    Is your disclosure policy and contact easy to find without prior knowledge of your company?

    Basis: Annex II(2), Annex I Part II(5)

    Next step: Link your security policy from the site footer and ensure it is reachable within one click from the homepage.

  • Medium · Disclosure · Partly in place

    Do you have a defined process for triaging and acknowledging incoming reports?

    Basis: Annex I Part II(5)

    Next step: Define triage steps with an acknowledgement target and a named responsible person.

  • Medium · Disclosure · No, not in place

    Do you publish terms giving good-faith researchers clarity on how reports will be handled?

    Basis: Annex I Part II(5), Recital 68

    Next step: Publish scope and good-faith handling terms alongside your disclosure policy.

  • Medium · Disclosure · Partly in place

    Do you coordinate disclosure timing with reporters and affected third parties?

    Basis: Annex I Part II(6)

    Next step: Add a coordination step to your disclosure process covering reporter agreement and, where relevant, other affected vendors.

  • Medium · Updates · Partly in place

    Do security updates remain available for at least 10 years after issue, or for the remainder of the support period if longer?

    Basis: Article 13(9)

    Next step: Set update artefact retention to at least 10 years after issue and prevent removal on product discontinuation.

  • Medium · Documentation · Partly in place

    Do you provide users with the information and instructions required by Annex II?

    Basis: Article 13(15), Annex II

    Next step: Review user documentation against the Annex II list and fill the missing items.

  • Medium · Documentation · I do not know

    Do you retain the technical documentation and declaration of conformity for 10 years after placing the product on the market?

    Basis: Article 13(13), Article 31(3)

    Next step: Add CRA technical documentation and declarations to your records retention policy with a 10-year minimum.

Answers you were unsure about

These are not necessarily gaps. They are the questions where nobody in the room knew the answer, which usually means the information exists somewhere but is not being tracked. Worth resolving first, because they may be hiding either good news or bad.

  • — Do you have a process for identifying and escalating severe incidents affecting product security?
  • — Do you retain the technical documentation and declaration of conformity for 10 years after placing the product on the market?

Get in touch

Get this reviewed against your actual product

This report is generated from the answers you gave. If you would like it checked against your real product documentation — or help acting on it — we work with manufacturers on exactly this.

We offer a paid consulting engagement: a review of your classification or gap result, a prioritised remediation plan, and support through conformity assessment.

Email

consulting@readinessnavigator.com

Web

readinessnavigator.com

Worth including in a first message

  • What the product is, and whether it contains software or connects to a network.
  • Which markets you sell into, and your role — manufacturer, importer, or distributor.
  • Any date you are working towards — a launch, an audit, or a customer deadline.

This report reflects the answers given on the date shown and is guidance, not legal advice. Answers were scored in your browser and were not transmitted or stored, so this document cannot be reissued — keep a copy if you need it.