EU Cyber Resilience Act Compliance

Know your CRA classification and what to build — reporting obligations start September 2026.

Built for EU manufacturers, importers, and distributors. In 6 minutes: your product's risk class, the exact CRA articles that apply, and a personalised action list. Free. No signup required.

Trusted by EU manufacturers, importers and compliance leads preparing for the CRA deadline

6 min classification
22 requirements mapped
494 days to full application
Built for EU manufacturers, importers, and distributors facing CRA deadlines
Based on EU Regulation 2024/2847

How It Works

From zero to CRA-ready in 3 steps

1

Take the Assessment

Answer 4 questions about your product. Get your EU risk classification in 6 minutes.

6 min
2

Review Your Requirements

See exactly which of the 22 CRA requirements apply to you — with plain-English guidance for each.

Prioritized for you
3

Track & Export

Mark requirements as done, generate a compliance report, and share it with your team or auditors.

Always up-to-date
22
CRA requirements covered
Free
to start, no credit card
Sept 2026
first CRA reporting deadline

Security Requirements

22 mandatory requirements for secure design, updates, and vulnerability handling

Deadline

December 2027 - products must be compliant to sell in EU

Risk

Up to EUR 15M fines plus banned from EU market

You'll get:

From first assessment to auditor-ready evidence.

The EU Cyber Resilience Act is an EU law requiring all software and connected hardware sold in Europe to meet security standards. If you sell digital products to EU customers, this likely applies to you - even if you're outside the EU. Key compliance dates you need to know. Track your progress against the official implementation schedule.

01Your product's risk classification
02Which requirements apply to you
03A prioritized action plan

Who Is This For?

Built for EU manufacturers, importers, and distributors facing CRA deadlines

Latest Guidance

View All Articles

Common Questions

Browse Full FAQ
What is the EU Cyber Resilience Act (CRA)?

The EU Cyber Resilience Act (CRA), officially EU Regulation 2024/2847, is a comprehensive EU regulation that establishes mandatory cybersecurity requirements for products with digital elements sold in the European Union.

Does the CRA apply to SaaS products?

It depends on your architecture. CRA Recital (12) explicitly excludes "cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements" — so pure browser-based SaaS is generally NOT covered by CRA. NIS2 applies to such services instead (for organizations of sufficient size).

When does CRA enforcement begin?

CRA enforcement happens in phases:

Pro — Core deliverable

Generate your CRA Technical File package

The document your auditor, notified body, and customers ask for — built from your assessment in minutes, not weeks.

  • Technical File (Annex VII compliant)
  • Declaration of Conformity
  • Coordinated Vulnerability Disclosure policy
  • SBOM generation and gap report

Simple, Transparent Pricing

Start free. Upgrade when you need more.

Free
EUR 0
  • CRA Assessment
  • Requirements Explorer
  • Security.txt Generator
  • VDP Template Download
  • Limited AI Chatbot
Get Started Free
Founding Member — First 20
Pro
EUR 29 /month
EUR 49/month after founding period
  • Everything in Free
  • Saved Workspaces
  • CRA Document Generator
  • SBOM Analysis
  • Unlimited AI Chatbot
  • PDF/Word Exports
View Pricing →

Ready to Start?

Take our 6-minute assessment to discover your product classification and get personalized compliance recommendations.

Start Assessment