Could you report an actively exploited vulnerability in your product within 24 hours?
The EU Cyber Resilience Act puts obligations on hardware and software with digital elements sold in the EU. Sixteen questions across five areas, mapped to Annex I and Articles 13 and 14 of Regulation (EU) 2024/2847. You get the gaps, the evidence that would close them, and the full assessment to take next.
Ready to see where you stand?
You'll get a computed readiness indicator across Product scope & classification, Secure by design & default, Vulnerability handling, Documentation & conformity, Reporting readiness, the evidence that would answer each gap, and the full assessment to take next. Any critical gap is called out on its own, even when the overall score looks strong.
Assessment methodology: aligned to Regulation (EU) 2024/2847, Annex I Parts I and II and Articles 13 and 14, with crosswalks to NIST SSDF v1.1. It reports a readiness indicator based on your answers; it does not decide whether a product is in scope, which class it falls in or which conformity route applies. Those are legal questions for counsel.
See your full results
Enter your email to unlock your readiness indicator, domain scores, top gaps, the evidence that would close them and recommended next steps.
- Overall readiness indicator and tier
- 5 domain scores with the EU Cyber Resilience Act (Regulation (EU) 2024/2847) mapping
- Your highest-priority gaps, critical ones flagged
- The evidence that would answer each gap
- Recommended next steps and an email copy
Your Cyber Resilience Act Quick Readiness Indicator
Executive summary
Domain scores
Weighted: Product scope & classification 15% · Secure by design & default 25% · Vulnerability handling 25% · Documentation & conformity 15% · Reporting readiness 20%. Expand a domain to see the contributing questions, your answers and the EU Cyber Resilience Act (Regulation (EU) 2024/2847) references they map to.
Your highest-priority gaps
Evidence that would answer each gap
What an assessor, a customer or an auditor would ask to see. Having it is the difference between a readiness indicator and a verified result.
Recommended next steps
Assessment methodology: aligned to Regulation (EU) 2024/2847, Annex I Parts I and II and Articles 13 and 14, with crosswalks to NIST SSDF v1.1. It reports a readiness indicator based on your answers; it does not decide whether a product is in scope, which class it falls in or which conformity route applies. Those are legal questions for counsel.
Please note: This assessment provides a readiness indicator based on the information provided. It does not constitute legal advice, a regulatory determination, or a guarantee of compliance. Regulatory applicability depends on facts, jurisdiction, and legal interpretation that should be confirmed with qualified counsel.
Recommended full assessment: EU Cyber Resilience Act Readiness Assessment
The Cyber Resilience Act puts cybersecurity obligations on products with digital elements sold in the EU: secure-by-design requirements, vulnerability handling, an SBOM, and reporting of actively exploited vulnerabilities and severe incidents. Reporting obligations apply from 11 September 2026 and the main obligations from 11 December 2027; the work starts with knowing which of your products are in scope and in which class. 30 minutes to scope. No obligation.