Free tool
Where do you stand against the CRA obligations?
Fifteen statements across five domains, drawn from Articles 13 and 14 and Annex I. You get an overall level and a domain-by-domain breakdown.
Indicative, non-binding self-assessment based on the CRA (EU 2024/2847). Does not replace a full gap analysis.
Domain 1 of 5
Governance and documentation
A product security policy is written and approved
Technical documentation is kept up to date for every product
Cybersecurity roles and responsibilities are assigned
Answer all three statements to continue.
