About CRA Tools
A free, independent set of practical tools for navigating the Cyber Resilience Act.
Built around decisions
CRA Tools helps developers, product teams, founders and supply-chain operators identify what to investigate about a specific product. Start with scope and role, then work through classification, conformity routes, changes and reporting.
Independent tool. Not affiliated with the European Commission or other EU institutions.
How the tools reach a result
The tools use deterministic rules: the same complete answers and calculation time produce the same result. Each assessment identifies the rules it uses, explains the reasoning and links to the official basis. No generative model or remote decision API evaluates your product.
We separate binding legislation from Commission and ENISA guidance. Uncertain facts and interpretative limits are surfaced rather than converted into a definitive compliance conclusion. Review dates describe a source check, not a guarantee that no later change exists.
Review and limitations
The initial source review is dated 2026-09-07. It includes Regulation (EU) 2024/2847, applicable technical category descriptions and the Commission’s July 2026 guidance. Automated tests exercise the decision rules and date calculations; they do not replace product-specific legal or technical review.
The tools do not perform certification, submit regulatory notifications or verify the security of a product. See the source registry and disclaimer before relying on a result.
Your assessment stays local
No account is required. Answers are processed in your browser and are not saved by the application. You can choose to export a result to your own device. Read the privacy information for details.