Assessment 01
CRA Readiness Assessment
A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the vulnerability handling and reporting obligations that apply from September 2026.
- Length
- 12–18 minutes
- Questions
- 48 questions
What it covers
- Product scope and Annex III / Annex IV classification
- Annex I Part I essential cybersecurity requirements
- Annex I Part II vulnerability handling processes
- Software bill of materials coverage and format
- Coordinated vulnerability disclosure policy
- Actively exploited vulnerability reporting readiness
- Security update delivery and support period
- Technical documentation and conformity assessment route
Built for
Product security officers, compliance leads, engineering managers
What you get back
A scored readiness profile across eight domains, your likely product class, and a prioritised gap list mapped to specific CRA articles.
Complete the questionnaire
Answer as your product stands today rather than as you intend it to be. An accurate baseline produces a usable remediation plan.
Questionnaire not connected
CRA Readiness Assessment is ready for its Tally form
This section will render the live questionnaire as soon as a Tally form ID is supplied. The embed, loading behaviour, and dynamic height handling are already wired up.
- 01Build the questionnaire at tally.so using the question outline listed on this page.
- 02Copy the ID from the share link — for tally.so/r/wA1b2C the ID is wA1b2C.
- 03Paste it into lib/site.ts under TALLY_FORMS The form goes live immediately.
Other assessments
Assessment 02
IEC 62443-4-1 Gap Assessment
A practice-by-practice gap assessment against all eight practices of IEC 62443-4-1, scored against the maturity levels used by certification bodies during audit.
OpenAssessment 03
Product Classification Check
A short triage questionnaire that determines whether your product falls in scope of the CRA, and if so, whether it is a default, important class I, important class II, or critical product.
Open