CRA reporting obligations apply from 11 September 2026View the timeline
A practical guide through Regulation (EU) 2024/2847

Cyber Resilience Act Tools

Free tools to check CRA scope, product classification, conformity routes and reporting deadlines.

Free to useEvidence-linked resultsNo account needed
The tool collection

Eight tools. A practical way forward.

Choose a starting point. Each tool explains its reasoning and links you to the relevant official sources.

A connected assessment

From product to evidence

A useful sequence for planning your CRA work. Revisit earlier decisions when the product changes.

01

Product

Define what you supply.

02

Scope

Check whether CRA applies.

03

Role

Identify your responsibilities.

04

Classification

Match core functionality.

05

Conformity

Find the assessment route.

06

Obligations

Plan security and reporting.

07

Evidence

Document your decisions.

Implementation timeline

The dates that matter

Full timeline & transitions
Framework

Entry into force

The Regulation enters into force. Its obligations have staged application dates.

Framework

Assessment bodies

Chapter IV starts applying: notification of conformity assessment bodies.

Application date

Reporting obligations

Article 14 reporting for actively exploited vulnerabilities and severe incidents.

Application date

General application

Most product requirements apply, subject to the transitional provisions.

Source: CRA Articles 69 and 71. Product transitions and reporting have different rules.

Understand the regulation

Less guesswork.
A clearer path through CRA.

The Cyber Resilience Act brings product cybersecurity into the full lifecycle of hardware and software supplied on the EU market. The right starting point is a clear product boundary and an understanding of your responsibilities.

These tools turn that first assessment into a structured set of questions. You get a qualified conclusion, the reasons behind it, points that need further review and a practical next step.

Read the practical CRA guide

Frequently asked questions

Does CRA apply to every software product?

No. You need to check the product boundary, relevant data connection, EU market supply, commercial context and exclusions. Specific rules also apply to FOSS and remote processing.

Are these tools free, and are my answers stored?

All eight tools are free. Answers and dates are processed in your browser, are not stored by the tools and are not sent to a decision API.

Can these tools certify my product?

No. They provide informational guidance based on your answers. They do not perform a conformity assessment, issue certification or establish legal compliance.

Is this an official EU website?

Independent tool. Not affiliated with the European Commission or other EU institutions.