Skip to content
CRA Navigator

Assessment 01

CRA Readiness Assessment

A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the vulnerability handling and reporting obligations that apply from September 2026.

Length
12–18 minutes
Questions
48 questions

What it covers

  • Product scope and Annex III / Annex IV classification
  • Annex I Part I essential cybersecurity requirements
  • Annex I Part II vulnerability handling processes
  • Software bill of materials coverage and format
  • Coordinated vulnerability disclosure policy
  • Actively exploited vulnerability reporting readiness
  • Security update delivery and support period
  • Technical documentation and conformity assessment route

Built for

Product security officers, compliance leads, engineering managers

What you get back

A scored readiness profile across eight domains, your likely product class, and a prioritised gap list mapped to specific CRA articles.

Complete the questionnaire

Answer as your product stands today rather than as you intend it to be. An accurate baseline produces a usable remediation plan.

Questionnaire not connected

CRA Readiness Assessment is ready for its Tally form

This section will render the live questionnaire as soon as a Tally form ID is supplied. The embed, loading behaviour, and dynamic height handling are already wired up.

  1. 01Build the questionnaire at tally.so using the question outline listed on this page.
  2. 02Copy the ID from the share link — for tally.so/r/wA1b2C the ID is wA1b2C.
  3. 03Paste it into lib/site.ts under TALLY_FORMS The form goes live immediately.