CRA Readiness · Self-Check

How ready is your company
for the CRA?

EU Cyber Resilience Act reporting obligations take effect on 11 September 2026.
Answer 30 questions across 6 domains to see where you stand and what to fix first.

8–10 minBased on the official ENISA model (CC BY 4.0)Reference only · not a conformity assessment
This self-check is based on the official ENISA «SME Cyber Resilience Maturity Assessment Model» (© ENISA 2026, CC BY 4.0): 25 questions in their original wording Source: ENISA, plus 5 questions on CRA Article 14 reporting readiness written by ACE LABS Source: ACE LABS.

Not sure whether your product is in scope? — Start with the 1-minute scope self-check →

📋 30 questions · 6 domainsFor each question, pick the description that best matches your current practice.
📊 Instant resultsGet your ENISA maturity band (🟡🔵🟢), domain scores and priority actions right away.
🔒 Nothing is storedAnswers are processed in your browser only, and sent solely if you request an expert assessment.