---
title: "Cyber Resilience Act (CRA) Readiness Assessment | Free Tool | FOSSA"
description: "Free EU Cyber Resilience Act readiness assessment. Assess your software supply chain and SBOM readiness, classify your product, and get a 30/60/90-day remediation plan for the September 2026 and December 2027 CRA deadlines, with an executive report."
canonical_url: "https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment/"
markdown_url: "https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment.md"
language: "en"
author: "FOSSA"
organization: "FOSSA"
---

# Cyber Resilience Act (CRA) Readiness Assessment | Free Tool | FOSSA

> Free EU Cyber Resilience Act readiness assessment. Assess your software supply chain and SBOM readiness, classify your product, and get a 30/60/90-day remediation plan for the September 2026 and December 2027 CRA deadlines, with an executive report.

## What the CRA Requires (Annex I, in Brief)

The essential cybersecurity requirements every in-scope product with digital elements must meet before CE marking.

### Secure by design & default

Ship with a minimized attack surface, hardened default configuration, and protection for the confidentiality, integrity, and availability of processed data.

### 24-hour vulnerability reporting

Report actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs within 24 hours, backed by a coordinated vulnerability disclosure policy.

### SBOM & supply chain governance

Maintain a machine-readable SBOM (CycloneDX or SPDX) covering top-level dependencies and continuously monitor open source components for new vulnerabilities.

### Security updates across the lifecycle

Provide free security updates for a defined support period, delivered separately from feature releases, for the expected product lifetime (typically at least five years).

## About This Assessment

This assessment maps your answers to the essential cybersecurity requirements in Annex I of the EU Cyber Resilience Act (Regulation (EU) 2024/2847), covering product classification, vulnerability handling and 24-hour reporting, secure-by-design defaults, SBOM and supply chain governance, and lifecycle security updates.

The readiness score is **severity-weighted**: each question counts in proportion to how central the requirement is to CRA compliance, so the 24-hour reporting mandate (Article 14) and the SBOM requirement move the score more than lifecycle details. A few requirements are legal must-haves; if one is missing (for example, no vulnerability reporting workflow or no machine-readable SBOM), it acts as a **knockout** that caps the grade regardless of your score elsewhere. Scoring runs entirely in your browser, and no answers leave your device. This is directional guidance for planning, not legal advice; consult qualified counsel for a formal conformity determination.

### Official sources

- [Regulation (EU) 2024/2847: full Cyber Resilience Act text (EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2024/2847/oj)
- [European Commission: The Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)
- [ENISA (European Union Agency for Cybersecurity)](https://www.enisa.europa.eu/)

Last reviewed July 9, 2026Maintained by the FOSSA software supply chain compliance team

## Cyber Resilience Act Compliance FAQ

Plain-English answers to the questions engineering and security leaders ask about the EU CRA.

## Get Started with FOSSA

Start managing your dependencies, licenses, and vulnerabilities today.

## Frequently asked questions

### What is the EU Cyber Resilience Act (CRA)?

The Cyber Resilience Act (Regulation (EU) 2024/2847) is an EU law that sets mandatory cybersecurity requirements for products with digital elements, meaning any hardware or software placed on the EU market. It requires manufacturers to build products that are secure by design, handle vulnerabilities responsibly, provide security updates across the product lifecycle, and supply supporting technical documentation including a software bill of materials.

### Does the CRA require an SBOM?

Yes. The CRA requires manufacturers to produce and maintain a software bill of materials (SBOM) in a commonly used, machine-readable format such as CycloneDX or SPDX as part of their technical documentation. The SBOM must cover at least the top-level dependencies of the product and support the manufacturer's obligation to identify and address vulnerabilities in third-party and open source components.

### What are the penalties for CRA non-compliance?

Non-compliance with the CRA's essential cybersecurity requirements can result in administrative fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher. Failing to meet other obligations, or supplying incorrect information to authorities, carries lower but still significant fines. Beyond fines, non-compliant products can be ordered withdrawn from the EU market.

### Does the CRA apply to companies based outside the EU?

Yes. The CRA applies based on where a product is placed on the market, not where its maker is based. Any company that makes a product with digital elements available on the EU market, whether directly or through importers and distributors, must meet the CRA's requirements. Manufacturers outside the EU typically work through EU-established importers, who carry their own duties to verify conformity before a product reaches the market, and may appoint an authorized representative in the EU.

### Is my data private when I use this assessment?

Yes. The assessment runs entirely in your browser and your answers are scored locally on your device; they are not sent to FOSSA or any third party. If you choose to receive the executive PDF report by email, only the email address you provide and your generated results are transmitted, so you stay in control of what you share.

## Source

Canonical page: https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment/
