Cyber Resilience Act Readiness Assessment
Assess your software supply chain against the EU Cyber Resilience Act, then generate a prioritized 30/60/90-day remediation plan and an executive-ready report.
What the CRA Requires (Annex I, in Brief)
The essential cybersecurity requirements every in-scope product with digital elements must meet before CE marking.
Secure by design & default
Ship with a minimized attack surface, hardened default configuration, and protection for the confidentiality, integrity, and availability of processed data.
24-hour vulnerability reporting
Report actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs within 24 hours, backed by a coordinated vulnerability disclosure policy.
SBOM & supply chain governance
Maintain a machine-readable SBOM (CycloneDX or SPDX) covering top-level dependencies and continuously monitor open source components for new vulnerabilities.
Security updates across the lifecycle
Provide free security updates for a defined support period, delivered separately from feature releases, for the expected product lifetime (typically at least five years).
About This Assessment
This assessment maps your answers to the essential cybersecurity requirements in Annex I of the EU Cyber Resilience Act (Regulation (EU) 2024/2847), covering product classification, vulnerability handling and 24-hour reporting, secure-by-design defaults, SBOM and supply chain governance, and lifecycle security updates.
The readiness score is severity-weighted: each question counts in proportion to how central the requirement is to CRA compliance, so the 24-hour reporting mandate (Article 14) and the SBOM requirement move the score more than lifecycle details. A few requirements are legal must-haves; if one is missing (for example, no vulnerability reporting workflow or no machine-readable SBOM), it acts as a knockout that caps the grade regardless of your score elsewhere. Scoring runs entirely in your browser, and no answers leave your device. This is directional guidance for planning, not legal advice; consult qualified counsel for a formal conformity determination.
Official sources
Cyber Resilience Act Compliance FAQ
Plain-English answers to the questions engineering and security leaders ask about the EU CRA.