Does the CRA apply to your product?
Find out in 6 minutes. Get your risk classification, see which requirements apply, and get a clear action plan — free, no signup required.
How It Works
From zero to CRA-ready in 3 steps
-
1
Take the Assessment
Answer 4 questions about your product. Get your EU risk classification in 6 minutes.
-
2
Review Your Requirements
See exactly which of the 22 CRA requirements apply to you — with plain-English guidance for each.
-
3
Track & Export
Mark requirements as done, generate a compliance report, and share it with your team or auditors.
Ask the CRA. Get answers that point to the Articles.
CRA Copilot answers your compliance questions in plain language — deadlines, SBOMs, reporting, technical files — drawing on the text of Regulation (EU) 2024/2847.
- Grounded in the regulation Answers draw on the official CRA text and point you to the Articles and Annexes behind them.
- Knows your product Complete the assessment and answers take your classification and open requirements into account.
- Try it free 10 free questions a month with a free account. Unlimited with Pro (fair use applies).
AI may be inaccurate — not legal advice.
Who Is This For?
Pick your role for guidance tailored to your CRA obligations
Building apps, SaaS, or desktop software sold to EU customers
Connected devices, smart home products, or embedded systems
Early-stage company wondering what minimum compliance looks like
Running vulnerability handling and security-by-design across the product portfolio
Maintaining an OSS project incorporated into commercial products
Reselling or distributing products made by another manufacturer
Scan your repository against the CRA from the terminal
cra-check reads your repository and shows what the Cyber Resilience Act (Annex I) expects and what your files do or do not evidence.
- Runs locally and read-only: no network access, no telemetry
- Checks SBOM, disclosure policy and reporting contact from repository files
- Everything else is marked "needs a human" — never a compliance verdict
A preparation aid, not legal advice or a conformity assessment. Requires Node 20+.
View on npm →$ npx cra-check
Simple, Transparent Pricing
Start free. Upgrade when you need more.
- CRA Assessment
- Requirements Explorer
- Security.txt Generator
- VDP Template Download
- Limited AI Chatbot
- Everything in Free
- Saved Workspaces
- CRA Document Generator
- SBOM Analysis
- Unlimited AI Chatbot (fair use)
- PDF/Word Exports
A practical 8-step roadmap to achieve EU Cyber Resilience Act compliance. From initial assessment to CE markin...
Read →Pure browser-based SaaS is generally exempt from CRA under Recital (12). Learn when CRA does apply to cloud pr...
Read →Hands-on comparison of the top SBOM generation tools for CRA compliance. Which format and tool should you choo...
Read →Common Questions
Browse Full FAQWhat is the EU Cyber Resilience Act (CRA)?
The EU Cyber Resilience Act (CRA), officially EU Regulation 2024/2847, is a comprehensive EU regulation that establishes mandatory cybersecurity requirements for products with digital elements sold in the European Union.
Key points:
- Applies to hardware and software products that connect to networks or process data
- Covers manufacturers, importers, and distributors
- Requires security throughout a product's lifecycle
- Includes vulnerability management, security updates, and transparent communication
- Full enforcement begins December 11, 2027
Does the CRA apply to SaaS products?
It depends on your architecture. CRA Recital (12) explicitly excludes "cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements" — so pure browser-based SaaS is generally NOT covered by CRA. NIS2 applies to such services instead (for organizations of sufficient size).
CRA does apply to:
- Downloadable components — mobile apps, desktop clients, SDKs, agents
- Cloud backends that support a product with digital elements (e.g., the cloud service behind an IoT device)
For in-scope components, typically 8-12 of 22 requirements apply. The free CRA assessment at cra-toolkit.com can determine your specific situation.
Source: EU Regulation 2024/2847, Recital (12)
When does CRA enforcement begin?
CRA enforcement happens in phases:
- November 20, 2024 - CRA published in Official Journal
- December 10, 2024 - CRA enters into force
- June 11, 2026 - Conformity assessment body notification requirements apply (Chapter IV)
- September 11, 2026 - Vulnerability and incident reporting obligations begin (Article 14)
- December 11, 2027 - Full enforcement of all requirements
Organizations should begin compliance preparations now to meet these deadlines.
Ready to Start?
Take our 6-minute assessment to discover your product classification and get personalized compliance recommendations.
Start Assessment