Are your products ready for the CRA? A self-test in 20 questions

20 questions for manufacturers show how far you have come with the Cyber Resilience Act: secure development, vulnerabilities, reporting and documentation.

Summary: 20 questions in five areas show how far you as a manufacturer have come with the Cyber Resilience Act (CRA): scope and responsibility, secure development, vulnerabilities and reporting, support period and information, and conformity and documentation. The reporting obligation has applied since 11 September 2026 and the rest of the Regulation applies from 11 December 2027. The self-test takes 10–15 minutes, and the result appears straight away on a scale from red to green. It is an indication, not a legal opinion or an audit.

About this guide

Who it is for
Manufacturers of products with digital elements, hardware or software, placed on the EU market.
What you get
A self-test in five areas with four questions each, following the manufacturer’s obligations in the CRA, that takes 10–15 minutes and shows the result straight away with suggested next steps – guidance, not an audit.

The questions follow Regulation (EU) 2024/2847 (CRA) and concern the manufacturer’s obligations. A cloud service or SaaS is not in itself a product under the CRA; a cloud function is covered when a product with digital elements depends on it to work. Open-source software stewards have their own, lighter obligations. Importers and distributors have fewer obligations of their own, mainly checking the manufacturer’s; read more about the CRA. Answer yes only if you can show it, for example with a document, a procedure or a decision. “It should exist” counts as no. If you have several products, answer for the most important one.

Your answers stay in your browser and are not stored. We only count that a test was completed and which level it gave. If you would like to be contacted, you send the result yourselves with the form below the result.

First: do you place products with digital elements, hardware or software, on the EU market as a manufacturer? This question does not count in the result.

Area 1: Scope and responsibility

  1. Do you have an inventory of your products with digital elements covered by the CRA? (Article 2)
  2. Do you know which category each product belongs to: default, important Class I or II, or critical? (Articles 7 and 8, Implementing Regulation (EU) 2025/2392)
  3. Has it been decided who is responsible for product security and the CRA work?
  4. Do you check third-party components, including open source, so that they do not compromise the product’s security? (Article 13(5))

Area 2: Secure development

  1. Is there a documented cybersecurity risk assessment for each product? (Article 13(2)–(3))
  2. Does development follow a secure process, with threat modelling, code review and security testing? (Annex I)
  3. Are products delivered with a secure-by-default configuration? (Annex I, Part I)
  4. Can security updates be delivered separately from feature updates, and automatically where appropriate? (Annex I)

Area 3: Vulnerabilities and reporting

  1. Do you have a software bill of materials (SBOM) in a machine-readable format for each product? (Annex I, Part II)
  2. Is there a contact point and a coordinated vulnerability disclosure policy? (Annex I, Part II)
  3. Can you report an actively exploited vulnerability or a severe incident within 24 hours through ENISA’s reporting platform? The obligation has applied since 11 September 2026, also for products already on the market. (Articles 14 and 69(3))
  4. Are vulnerabilities fixed without delay, and do users get security updates free of charge? (Annex I, Part II)

Area 4: Support period and information

  1. Have you set the support period for each product, as a rule at least five years, and do you state it at the time of purchase? (Article 13(8))
  2. Does the product come with the information and instructions for users that Annex II requires?
  3. Does each security update remain available for at least ten years after its release, or for the rest of the support period if longer? (Article 13(9))
  4. Do you have a procedure for informing users when support for a product ends?

Area 5: Conformity and documentation

  1. Do you have technical documentation for each product under Annex VII?
  2. Do you know which conformity assessment procedure each product must follow? (Article 32)
  3. Is there a plan for the EU declaration of conformity and CE marking by 11 December 2027? (Articles 28 and 30)
  4. Are the technical documentation and the EU declaration kept for at least ten years, or the support period if longer? (Article 13(13))

Reading the result

  • Solid foundation, 18–20 yes: The basics are in place. Plan the technical documentation and the conformity assessment up to 11 December 2027.
  • Nearly there, 14–17 yes: Most of it is in place. The remaining gaps can usually be closed with a procedure or a decision.
  • Clear gaps, 10–13 yes: The foundation is partly there, but several parts are missing. Prioritise the areas with two yes answers or fewer.
  • Foundation missing, 9 yes or fewer: Several of the basics are missing. Start with reporting, which already applies, the product inventory and a risk assessment per product.

The same scale applies per area: four yes is a solid foundation, three nearly there, two clear gaps, and one or none means the foundation is missing.

The self-test is an indication. It shows whether the basics seem to be there, not that your products comply with the CRA. A gap analysis assesses each requirement with evidence. If you answer no or don’t know to the questions on risk assessment, the SBOM, reporting or the support period, it should be looked into whatever the total, and the result shows this below the scale. Reporting already applies.

What to do next

  • No to the question on reporting: start there, because the obligation has applied since 11 September 2026. CRA readiness for product companies starts with the reporting procedure.
  • Two yes or fewer in at least two areas: a gap analysis against the requirements and a plan up to 11 December 2027.
  • Gaps in secure development: a penetration test shows where the product is vulnerable today.
  • Solid foundation: plan the technical documentation and follow the work on harmonised standards, which have not yet been published.

Would you like to go through the result with us? Read more about the Cyber Resilience Act (CRA) or contact us.

Sources: Regulation (EU) 2024/2847 (CRA), Articles 2, 7, 8, 13, 14, 28, 30, 32, 69 and 71 and Annexes I, II and VII; Implementing Regulation (EU) 2025/2392; ENISA, Single Reporting Platform; European Commission, Cyber Resilience Act. Fact-checked on 4 October 2026.

This text is general information and does not constitute legal advice in an individual case.