Assessment 01
CRA Readiness Assessment
A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the vulnerability handling and reporting obligations that apply from September 2026.
- Length
- 12–18 minutes
- Questions
- 48 questions
What it covers
- Product scope and Annex III / Annex IV classification
- Annex I Part I essential cybersecurity requirements
- Annex I Part II vulnerability handling processes
- Software bill of materials coverage and format
- Coordinated vulnerability disclosure policy
- Actively exploited vulnerability reporting readiness
- Security update delivery and support period
- Technical documentation and conformity assessment route