Skip to main content
FOSSA Logo
Free EU CRA Compliance Tool

Cyber Resilience Act Readiness Assessment

Assess your software supply chain against the EU Cyber Resilience Act, then generate a prioritized 30/60/90-day remediation plan and an executive-ready report.

Annex I coverage SBOM & supply chain coverage 30/60/90-day plan Runs entirely in your browser

What the CRA Requires (Annex I, in Brief)

The essential cybersecurity requirements every in-scope product with digital elements must meet before CE marking.

Secure by design & default

Ship with a minimized attack surface, hardened default configuration, and protection for the confidentiality, integrity, and availability of processed data.

24-hour vulnerability reporting

Report actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs within 24 hours, backed by a coordinated vulnerability disclosure policy.

SBOM & supply chain governance

Maintain a machine-readable SBOM (CycloneDX or SPDX) covering top-level dependencies and continuously monitor open source components for new vulnerabilities.

Security updates across the lifecycle

Provide free security updates for a defined support period, delivered separately from feature releases, for the expected product lifetime (typically at least five years).

About This Assessment

This assessment maps your answers to the essential cybersecurity requirements in Annex I of the EU Cyber Resilience Act (Regulation (EU) 2024/2847), covering product classification, vulnerability handling and 24-hour reporting, secure-by-design defaults, SBOM and supply chain governance, and lifecycle security updates.

The readiness score is severity-weighted: each question counts in proportion to how central the requirement is to CRA compliance, so the 24-hour reporting mandate (Article 14) and the SBOM requirement move the score more than lifecycle details. A few requirements are legal must-haves; if one is missing (for example, no vulnerability reporting workflow or no machine-readable SBOM), it acts as a knockout that caps the grade regardless of your score elsewhere. Scoring runs entirely in your browser, and no answers leave your device. This is directional guidance for planning, not legal advice; consult qualified counsel for a formal conformity determination.

Cyber Resilience Act Compliance FAQ

Plain-English answers to the questions engineering and security leaders ask about the EU CRA.

Get Started with FOSSA

Start managing your dependencies, licenses, and vulnerabilities today.