EU Regulation 2024/2847 β€” Enforcement begins 2027

Solve CRA Compliance
in Minutes, Not Months

Free self-assessment tool for the EU Cyber Resilience Act. Check if your product needs compliance, get your risk score, and generate required documentation β€” instantly.

See How It Works ↓
⏱️ Takes 3–5 minutes
πŸ”’ 100% client-side
πŸ’³ No registration
⚠️

Non-compliance can cost up to €15 Million or 2.5% of global turnover

The EU Cyber Resilience Act applies to nearly all products with digital elements sold in Europe. Deadlines are approaching fast.

Dec 2024
βœ… Done

CRA Entered Into Force

Regulation (EU) 2024/2847 officially applies across all EU member states.

Sep 2026
πŸ”Ά 11 months

Reporting Obligations Begin

Manufacturers must report actively exploited vulnerabilities to ENISA within 24 hours.

Dec 2027
πŸ”΄ 22 months

Full Compliance Required

All essential cybersecurity requirements must be met. Products without CE marking pulled from market.

Everything you need to start CRA compliance

From classification to documentation β€” our free tool guides you through the entire process.

🎯

Product Classification

Determine if your product is Default, Important (Class I/II), or Critical under CRA β€” and what that means for your obligations.

πŸ“Š

Compliance Scoring

Get a 0–100% compliance score based on your current security posture. See exactly where you stand and what needs work.

πŸ“„

Document Generator

Generate 4 essential CRA documents instantly: Technical Documentation, Security Policy, Vulnerability Disclosure, and EU Declaration of Conformity.

πŸ—ΊοΈ

Action Roadmap

Receive a prioritized list of actions with deadlines to achieve full compliance β€” tailored to your product's classification.

πŸ”’

Privacy-First

Everything runs in your browser. No data leaves your device. No accounts, no tracking, no cloud storage. Your data stays yours.

⚑

Instant Results

Complete the 7-step wizard in under 5 minutes and get your classification, score, and documents immediately. No waiting, no callbacks.

How it works

Three simple steps from uncertainty to clarity.

1

Answer the Wizard

Tell us about your product, its connectivity, data handling, and current security measures in our guided 7-step assessment.

β†’
2

Get Your Score

Receive your CRA classification, compliance score, gap analysis, and a prioritized action roadmap tailored to your product.

β†’
3

Generate Documents

Download pre-filled compliance document templates ready for your legal team to review and finalize.

2024/2847
EU Regulation
7 Steps
Assessment Wizard
4 Docs
Auto-Generated
0 Data
Sent to Servers
β˜…β˜…β˜…β˜…β˜…

"Finally a clear, no-nonsense tool that helped us understand where we stand with CRA. The document generator saved us weeks of work."

JM
Jan M.
CTO, IoT Startup β€” Munich
β˜…β˜…β˜…β˜…β˜…

"We used CRA-Check to quickly classify 12 products. The prioritized action roadmap made it easy to present a compliance plan to our board."

SK
Sarah K.
Head of Compliance, Software Company
β˜…β˜…β˜…β˜…β˜†

"Great starting point for CRA compliance. The fact that it's completely client-side was a must-have for us. Looking forward to PDF export!"

LR
Luca R.
Security Engineer β€” Zurich

Simple, transparent pricing

Start for free. Upgrade when you need more.

Free

€0
forever
  • βœ“ Full 7-step assessment
  • βœ“ Product classification
  • βœ“ Compliance score
  • βœ“ 4 document templates (Markdown)
  • βœ“ Action roadmap
  • βœ“ 100% client-side
  • β€” PDF export
  • β€” Save progress
  • β€” Multi-language

Enterprise

Custom
let's talk
  • βœ“ Everything in Pro
  • βœ“ API access
  • βœ“ CI/CD pipeline integration
  • βœ“ GitHub/GitLab repo scanning
  • βœ“ White-label option
  • βœ“ Multiple product portfolios
  • βœ“ Dedicated account manager
  • βœ“ Custom integrations
  • βœ“ SLA & premium support
Contact Sales

Frequently Asked Questions

What is the EU Cyber Resilience Act (CRA)?

The CRA (Regulation EU 2024/2847) is an EU regulation that sets mandatory cybersecurity requirements for all products with digital elements sold in the European single market. This includes hardware, software, IoT devices, and connected systems. It requires manufacturers to implement security-by-design, provide security updates, handle vulnerabilities, and maintain proper documentation.

Does the CRA apply to my product?

If your product contains or connects to any digital component and is sold (or made available) in the EU, the CRA almost certainly applies. This includes desktop software, mobile apps, IoT devices, network equipment, embedded firmware, and even open-source projects under certain conditions. Our assessment wizard will help you determine the exact classification.

What are the fines for non-compliance?

Non-compliance with essential cybersecurity requirements can result in fines of up to €15,000,000 or 2.5% of worldwide annual turnover, whichever is higher. Non-compliance with other CRA obligations can result in fines up to €10M or 2%. Even providing incorrect or incomplete information can lead to fines of up to €5M or 1%.

Is this tool legally binding?

No. CRA-Check is an educational and guidance tool designed to help you understand your CRA obligations and get started with compliance. The generated documents are templates that should be reviewed and finalized by your legal and security teams. Always consult with legal professionals for binding compliance decisions.

Is my data safe?

Absolutely. CRA-Check runs entirely in your browser. No data is sent to any server, no accounts are created, and nothing is stored in the cloud. Your assessment data exists only in your browser session and is gone when you close the tab. You can verify this β€” the tool works fully offline.

What product classifications exist under CRA?

Default: Most products with digital elements fall here β€” self-assessment is sufficient.
Important Class I: Operating systems, routers, VPNs, firewalls, password managers β€” self-assessment using harmonized standards or third-party assessment.
Important Class II: Hypervisors, industrial firewalls, tamper-resistant chips β€” mandatory third-party assessment.
Critical: Smart meter gateways, HSMs, smartcard readers for critical infrastructure β€” EU cybersecurity certification required.

Don't wait for the deadline.
Start your CRA compliance today.

Free assessment. No registration. Takes under 5 minutes.