Article 14 reporting obligations apply since 11 September 2026

Does the CRA apply to your product?

Find out in 6 minutes. Get your risk classification, see which requirements apply, and get a clear action plan — free, no signup required.

6 min classification
22 requirements mapped
436 days to full application See timeline →
Based on EU Regulation 2024/2847

How It Works

From zero to CRA-ready in 3 steps

  1. 1

    Take the Assessment

    Answer 4 questions about your product. Get your EU risk classification in 6 minutes.

    6 min
  2. 2

    Review Your Requirements

    See exactly which of the 22 CRA requirements apply to you — with plain-English guidance for each.

    Prioritized for you
  3. 3

    Track & Export

    Mark requirements as done, generate a compliance report, and share it with your team or auditors.

    Always up-to-date
AI Copilot

Ask the CRA. Get answers that point to the Articles.

CRA Copilot answers your compliance questions in plain language — deadlines, SBOMs, reporting, technical files — drawing on the text of Regulation (EU) 2024/2847.

  • Grounded in the regulation Answers draw on the official CRA text and point you to the Articles and Annexes behind them.
  • Knows your product Complete the assessment and answers take your classification and open requirements into account.
  • Try it free 10 free questions a month with a free account. Unlimited with Pro (fair use applies).

AI may be inaccurate — not legal advice.

Who Is This For?

Pick your role for guidance tailored to your CRA obligations

Pro — Core deliverable

Generate your CRA Technical File package

The document your auditor, notified body, and customers ask for — built from your assessment in minutes, not weeks.

  • Technical File (Annex VII compliant)
  • Declaration of Conformity
  • Coordinated Vulnerability Disclosure policy
  • SBOM generation and gap report
Free · Open source

Scan your repository against the CRA from the terminal

cra-check reads your repository and shows what the Cyber Resilience Act (Annex I) expects and what your files do or do not evidence.

  • Runs locally and read-only: no network access, no telemetry
  • Checks SBOM, disclosure policy and reporting contact from repository files
  • Everything else is marked "needs a human" — never a compliance verdict

A preparation aid, not legal advice or a conformity assessment. Requires Node 20+.

View on npm →
Terminal
$ npx cra-check

Simple, Transparent Pricing

Start free. Upgrade when you need more.

Free
EUR 0
  • CRA Assessment
  • Requirements Explorer
  • Security.txt Generator
  • VDP Template Download
  • Limited AI Chatbot
Get Started Free
Founding Member Pricing
Founding Member
EUR 29 /month
Price locked forever — limited to the first 20 customers
  • Everything in Free
  • Saved Workspaces
  • CRA Document Generator
  • SBOM Analysis
  • Unlimited AI Chatbot (fair use)
  • PDF/Word Exports
View Pricing →

Common Questions

Browse Full FAQ
What is the EU Cyber Resilience Act (CRA)?

The EU Cyber Resilience Act (CRA), officially EU Regulation 2024/2847, is a comprehensive EU regulation that establishes mandatory cybersecurity requirements for products with digital elements sold in the European Union.

Key points:

  • Applies to hardware and software products that connect to networks or process data
  • Covers manufacturers, importers, and distributors
  • Requires security throughout a product's lifecycle
  • Includes vulnerability management, security updates, and transparent communication
  • Full enforcement begins December 11, 2027
Does the CRA apply to SaaS products?

It depends on your architecture. CRA Recital (12) explicitly excludes "cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements" — so pure browser-based SaaS is generally NOT covered by CRA. NIS2 applies to such services instead (for organizations of sufficient size).

CRA does apply to:

  • Downloadable components — mobile apps, desktop clients, SDKs, agents
  • Cloud backends that support a product with digital elements (e.g., the cloud service behind an IoT device)

For in-scope components, typically 8-12 of 22 requirements apply. The free CRA assessment at cra-toolkit.com can determine your specific situation.

Source: EU Regulation 2024/2847, Recital (12)

When does CRA enforcement begin?

CRA enforcement happens in phases:

  • November 20, 2024 - CRA published in Official Journal
  • December 10, 2024 - CRA enters into force
  • June 11, 2026 - Conformity assessment body notification requirements apply (Chapter IV)
  • September 11, 2026 - Vulnerability and incident reporting obligations begin (Article 14)
  • December 11, 2027 - Full enforcement of all requirements

Organizations should begin compliance preparations now to meet these deadlines.

See the full CRA timeline →

Ready to Start?

Take our 6-minute assessment to discover your product classification and get personalized compliance recommendations.

Start Assessment
Need help with CRA? Ask the assistant.