Free · ~20 min · 25 questions

CRA Product Security
Maturity Check

Score your organisation's product security practices across five domains — based on the ENISA SME Cyber Resilience Maturity Assessment Model aligned to the EU Cyber Resilience Act (CRA), Regulation 2024/2847.

5 Domains 25 Questions CRA Aligned Enforced Dec 2027
Who this is for. Manufacturers, distributors, and importers of products with digital elements placed on the EU market — including software products, connected hardware, and IoT devices. Also useful for integrators and service providers involved in the product life cycle.
Domain 1
Governance & Documentation
Domain 2
Risk Management & Security by Design
Domain 3
Vulnerability & Patch Management
Domain 4
Product Life Cycle Management
Domain 5
Awareness, Competence & Skills