Know your CRA classification and what to build — reporting obligations start September 2026.
Built for EU manufacturers, importers, and distributors. In 6 minutes: your product's risk class, the exact CRA articles that apply, and a personalised action list. Free. No signup required.
Trusted by EU manufacturers, importers and compliance leads preparing for the CRA deadline
How It Works
From zero to CRA-ready in 3 steps
Take the Assessment
Answer 4 questions about your product. Get your EU risk classification in 6 minutes.
6 minReview Your Requirements
See exactly which of the 22 CRA requirements apply to you — with plain-English guidance for each.
Prioritized for youTrack & Export
Mark requirements as done, generate a compliance report, and share it with your team or auditors.
Always up-to-dateSecurity Requirements
22 mandatory requirements for secure design, updates, and vulnerability handling
Deadline
December 2027 - products must be compliant to sell in EU
Risk
Up to EUR 15M fines plus banned from EU market
From first assessment to auditor-ready evidence.
The EU Cyber Resilience Act is an EU law requiring all software and connected hardware sold in Europe to meet security standards. If you sell digital products to EU customers, this likely applies to you - even if you're outside the EU. Key compliance dates you need to know. Track your progress against the official implementation schedule.
How This Tool Helps You
You'll get:
Product Classification
Determine if your product is Standard, Class I, Class II, or Critical - and what conformity assessment applies.
Get startedPlain English Requirements
Understand CRA requirements without legal jargon. Get actionable implementation guidance for each requirement.
ExploreCompliance Tracking
Track your progress across all 22 requirements. See your readiness percentage and prioritized next steps.
View dashboardImplementation Tools
SBOM guidance, vulnerability disclosure policy builder, support period calculator, and more.
Open toolsReport Generation
Generate comprehensive readiness reports to share with stakeholders, auditors, or legal teams.
Generate reportWho Is This For?
Built for EU manufacturers, importers, and distributors facing CRA deadlines
Building apps, SaaS, or desktop software sold to EU customers
Connected devices, smart home products, or embedded systems
Early-stage company wondering what minimum compliance looks like
Maintaining an OSS project incorporated into commercial products
Reselling or distributing products made by another manufacturer
Latest Guidance
View All ArticlesA practical 8-step roadmap to achieve EU Cyber Resilience Act compliance. From initial assessment to CE markin...
Read →Pure browser-based SaaS is generally exempt from CRA under Recital (12). Learn when CRA does apply to cloud pr...
Read →Hands-on comparison of the top SBOM generation tools for CRA compliance. Which format and tool should you choo...
Read →Common Questions
Browse Full FAQThe EU Cyber Resilience Act (CRA), officially EU Regulation 2024/2847, is a comprehensive EU regulation that establishes mandatory cybersecurity requirements for products with digital elements sold in the European Union.
It depends on your architecture. CRA Recital (12) explicitly excludes "cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements" — so pure browser-based SaaS is generally NOT covered by CRA. NIS2 applies to such services instead (for organizations of sufficient size).
CRA enforcement happens in phases:
Simple, Transparent Pricing
Start free. Upgrade when you need more.
- CRA Assessment
- Requirements Explorer
- Security.txt Generator
- VDP Template Download
- Limited AI Chatbot
- Everything in Free
- Saved Workspaces
- CRA Document Generator
- SBOM Analysis
- Unlimited AI Chatbot
- PDF/Word Exports
Ready to Start?
Take our 6-minute assessment to discover your product classification and get personalized compliance recommendations.
Start Assessment