Free Cyber Resilience Act Quick Check

Could you report an actively exploited vulnerability in your product within 24 hours?

The EU Cyber Resilience Act puts obligations on hardware and software with digital elements sold in the EU. Sixteen questions across five areas, mapped to Annex I and Articles 13 and 14 of Regulation (EU) 2024/2847. You get the gaps, the evidence that would close them, and the full assessment to take next.

5 CRA areas · 16 questions · ~8 minutes

Ready to see where you stand?

You'll get a computed readiness indicator across Product scope & classification, Secure by design & default, Vulnerability handling, Documentation & conformity, Reporting readiness, the evidence that would answer each gap, and the full assessment to take next. Any critical gap is called out on its own, even when the overall score looks strong.

Assessment methodology: aligned to Regulation (EU) 2024/2847, Annex I Parts I and II and Articles 13 and 14, with crosswalks to NIST SSDF v1.1. It reports a readiness indicator based on your answers; it does not decide whether a product is in scope, which class it falls in or which conformity route applies. Those are legal questions for counsel.