What the assessment covers
27 questions across six areas, each referencing the relevant CRA article or annex. Answer honestly — the report is only useful if the gaps are real.
- 1
Governance & Security by Design
CRA Article 13 — Manufacturer obligations — security by design
- 2
Risk & Asset Management
CRA Annex I — Essential cybersecurity requirements
- 3
Vulnerability Management
CRA Article 14 — Vulnerability handling and reporting
- 4
Incident Management
CRA Article 15 — Incident notification duties
- 5
Recovery & Operational Resilience
CRA Annex I — Availability and resilience requirements
- 6
Supply Chain & Third Parties
CRA Annex I — Third-party components and supplier assurance
This assessment is intended as a general Cyber Resilience Act readiness tool and should not be considered legal, regulatory or compliance advice. Completing this assessment does not certify compliance with the Cyber Resilience Act.
