CRA Initial AssessmentEU 2024/2847·Not signed in

50 days until Article 14 reporting applies · 11 September 2026

Is your product ready for the EU Cyber Resilience Act?

Four short forms, AI help from your own documents, and a cited PDF report you can hand to your board or a notified body. Under an hour, no CRA knowledge assumed.

Start your assessment

Sign in with a magic link. No password needed.

The assessment

Four short forms

Answer in plain language. The tool handles the legal mapping.

  1. 015 min

    Scope

    Does the CRA apply to your product at all?

  2. 025 min

    Classification

    Default, Important or Critical, and which conformity route follows.

  3. 0325 min

    Maturity

    25 ENISA questions on how ready your organisation is.

  4. 045 min

    Reporting

    A pre-flight check on the Article 14 obligations.

Grounded AI

Answers you can verify

Upload your documents

Datasheets, policies, SBOMs. They stay private to your workspace.

AI pre-fills the forms

Each suggestion carries a confidence badge. You confirm or correct.

Every claim is cited

Verbatim references to the regulation. If it cannot cite it, it does not say it.

Article 14(1), Regulation (EU) 2024/2847

The report

What you walk away with

Executive summary

One page for your board: scope verdict, product class, maturity band.

Detailed report

Every question, answer and citation in a single PDF.

Improvement roadmap

Prioritised next steps for your weakest domain.

Built on the actual texts

Every verdict traces to a paragraph in the regulatory library.

  • Regulation (EU) 2024/2847 (CRA)
  • Implementing Reg. (EU) 2025/2392
  • ENISA SME Cyber Resilience Maturity Model
  • BSI TR-03183 Parts 1-3
  • EN 40000 series
  • Commission CRA Guidance & FAQ
  • Blue Guide 2022

Find out where you stand

This tool is not a CE mark, a certificate, or legal advice. It tells you where you stand and what to do next. Formal conformity assessment is a separate step.