For ChampionsFor the ISO / CISOFor the DPOFor Compliance OfficersFor StartupsFor Manufacturers
CRA Quick-CheckBoard Assurance ChecklistRequired Core ArtefactsAtelier
PricingAbout usContactTry for free
Language
DEENFR
trusttroiai
CRA Quick-Check

Where does your product stand under the Cyber Resilience Act?

This check shows you in about 20 minutes where you stand across the five ENISA maturity domains. Anonymous, no email required, nothing stored on our servers.

About 20 minutes if you answer from memory. Up to 2 hours if you check documentation and involve colleagues.

Your answers are temporarily stored in your browser so you can pause and resume the check anytime. You can clear them with a single click.

The Cyber Resilience Act applies to products with digital elements made available on the EU market. Full application begins on 11 December 2027. The reporting obligations under Article 14 already apply from 11 September 2026. Whether you build a device, a SaaS product, or a piece of firmware, the essential requirements are the same.

As the measurement basis we use the ENISA SME Cyber Resilience Maturity Assessment Model, published in July 2026. Twenty-five questions across five domains: Risk Management and Security by Design, Governance and Documentation, Vulnerability and Patch Management, Product Lifecycle, Awareness and Skills.

Prefer to work directly with the sources? Both ENISA publications are open and free.

  • ENISA SME Cyber Resilience Maturity Assessment Model, July 2026
  • ENISA Secure by Design and Default Playbook, Version 1.0