EU Cyber Resilience Act · Regulation 2024/2847 · Enforcement 11 Dec 2027

CRA compliance,
without the guesswork.

CRA Studio guides EU and non-EU manufacturers through every step of EU Cyber Resilience Act compliance — from Annex III classification to audit-ready dossier. 28 requirements pre-loaded. No legal background required.

FreeNo credit card required10-minute setupHosted in the EU · GDPR-compliant

Full enforcement in

432

days

07

hrs

03

min

15

sec

11 Dec 2027 · CE marking mandatory · Annex I required

28

CRA requirements pre-loaded

3

Product classes covered

5

Years min. support obligation

1

Click audit export

EU-hosted (Frankfurt) GDPR by design AES-256 · TLS 1.2+ Aligned with CRA Annex I/III/VII Built by people who actually had to comply

The compliance challenge

The CRA is here. Most manufacturers aren't ready.

Complex legal text

The CRA regulation spans 100+ pages of legal text. Understanding which of the 28 Annex I requirements apply to your product — and how to evidence them — is not straightforward.

Hard deadline approaching

Full enforcement begins 11 December 2027. Article 14 reporting has applied since 11 September 2026. Non-compliant products cannot be placed on the EU market. Penalties reach €15 million or 2.5% of global annual turnover.

No single source of truth

Teams juggle spreadsheets, email threads, and shared drives. Tracing which evidence covers which requirement — and keeping it current across product versions — becomes unmanageable.

Industry snapshot

Only 2% feel ready for CRA vulnerability & incident reporting

When a recent CRA webinar asked attendees how prepared their organisation is for the Cyber Resilience Act's vulnerability-handling and Article 14 incident-reporting obligations, the picture was clear — almost no one is fully there yet.

98%

are not yet fully prepared

Just 2% say their vulnerability-handling and reporting processes are already in place.

Very prepared — processes already in place2%
Somewhat prepared — planning underway40%
Early stage — still assessing requirements36%
Not prepared yet22%

Source: live attendee poll, CRA compliance webinar. Figures rounded; total may not sum to 100%.

Timeline

When the CRA actually applies

The CRA applies in phases. Only one obligation lands on 11 September 2026 — Article 14 reporting — and it covers products already on the market. Everything else follows on 11 December 2027.

✓ DoneAll actors
11 Dec 2024

Entry into force

Regulation (EU) 2024/2847 enters into force. The phased application clock starts.

✓ DoneNotified bodies
11 Jun 2026

Conformity assessment bodies (Chapter IV)

The rules on notifying authorities and notified bodies start to apply. This sets up who may certify products — it places no new obligation on manufacturers themselves.

✓ DoneManufacturers
11 Sep 2026

Article 14 reporting obligations

Manufacturers must report actively exploited vulnerabilities and severe incidents : early warning within 24h, notification within 72h, final report 14 days after a fix (vulnerabilities) or one month after the notification (incidents). This is the only manufacturer obligation that lands on this date — and it applies to all products already on the market, including legacy products.

○ PlannedManufacturers
11 Dec 2027

Full application

Everything else applies: Annex I essential requirements, conformity assessment, technical documentation, CE marking and the Declaration of Conformity. Non-compliant products may no longer be placed on the EU market.

What is CRA Studio?

One workspace for your entire CRA assessment.

CRA Studio is a purpose-built compliance platform for the EU Cyber Resilience Act. Classify your product, open a dossier with all 28 requirements pre-loaded, upload your SBOM and technical documentation, and export an audit package for your notified body — all in one place, in days instead of months.

No CRA expertise required Built around the actual regulation Audit-export in one click

Platform features

Everything you need for CRA compliance

Built specifically for the CRA — not a generic GRC tool adapted after the fact.

CRA Classification Wizard

Answer 12 guided questions. The wizard automatically determines Default, Class I, or Class II — with the exact Annex III rationale.

28 Requirements Pre-loaded

All Annex I (Part I & II), Article 10, and Annex VII requirements are seeded with plain-language guidance for every classification.

Gap Analysis & Golden Thread

See exactly what is missing for audit readiness — missing documents, non-compliant requirements, and a full traceability chain.

Global Policy Inheritance

Assess your SDL, CVD Policy, or Incident Response once at organisation level. Changes propagate instantly to all linked products.

SBOM & Evidence Management

Upload CycloneDX/SPDX SBOMs with auto-parsing. Tag every document to a specific CRA article for a court-proof evidence trail.

Lifecycle & EOL Tracking

CRA mandates 5 years of support. Track end-of-life dates, receive warnings, and archive dossiers while keeping them audit-accessible.

Free · No signup required

Try our free CRA tools right now

Don't commit to anything. Start with the same tools we use ourselves.

ENISA CRA Maturity Assessment

Score your product security maturity in five ENISA domains — governance, risk, vulnerabilities, lifecycle and awareness. Based on the official ENISA SME Maturity Assessment Model (June 2025). 25 questions, band + gap analysis, prioritised action list, Excel import. Everything stays in your browser.

Assess your maturity

CRA Classification Agent

Find out in 60 seconds whether your product is Default, Class I, or Class II under the CRA. 12 questions, deterministic Annex III rule engine, no AI guessing, no email required.

Run the classifier

CRA Overview & Reference

A plain-language guide to the EU Cyber Resilience Act — articles, annexes, deadlines, and what each obligation actually means for a manufacturer. Browseable, searchable, free.

Open the reference

SBOM Vulnerability Scanner

Upload an SPDX SBOM and we'll check every component against the OSV.dev vulnerability database — known CVEs ranked by severity. Same engine our paid scanner uses. Scanned in memory, never stored.

Scan an SBOM

CVD Policy Generator

The CRA requires a publicly available Coordinated Vulnerability Disclosure policy. Generate a ready-to-publish policy — including your PSIRT structure and the statutory 24h / 72h / 14-day reporting timeline. No email required.

Build a CVD policy

security.txt Generator

Make your security contact easy to find. Generate an RFC 9116 compliant security.txt to publish at /.well-known/security.txt — the perfect companion to your CVD policy. Free, no sign-up.

Build a security.txt

Article 14 Readiness Check

The CRA requires manufacturers to report actively exploited vulnerabilities on a 24h / 72h / 14-day timeline. Answer a short self-assessment to see how ready you are, get a prioritised gap list, and download a reporting runbook. No sign-up.

Check your readiness

Threat Modeling

The CRA requires a risk assessment mapping your attack surface, threat actors and attack vectors to security requirements. This guided STRIDE-light tool produces a documented threat model — methodology included — in four steps. No sign-up.

Model your threats

EU Declaration of Conformity Generator

CRA Annex V requires an EU Declaration of Conformity for every product placed on the EU market. Generate a compliant DoC in three minutes — Markdown or print-to-PDF. Registered users save it per product dossier under audit.

Build a DoC

CRA Role Check

Six yes/no questions grounded in CRA Article 3 tell you whether your organisation is a manufacturer, importer, distributor, authorised representative or OSS steward — and which obligations apply. An organisation can hold more than one role. Registered users save the outcome to their workspace.

Find your role

Product Lifecycle Policy Generator

CRA Article 10(2) requires a documented support period, security-patch response window and end-of-life communication for every product. Build a compliant policy in minutes. Registered users save it as a Global Policy that propagates to every product dossier automatically.

Build a Lifecycle policy

Technical Documentation Generator (Annex VII)

CRA Article 31 requires a technical file covering eight areas — product description, design, risk assessment, standards, testing, SBOM, vulnerability handling, user info. This wizard walks you through all of them with live Markdown preview. Registered users save each section per dossier with a full audit trail.

Build your technical file

ISO 27001 → CRA Coverage Mapper

Already ISO 27001 certified — or on the way? Score the 93 Annex A controls and see instantly how much of the CRA your existing ISMS already covers, and where the delta sits. 52 % of SMEs surveyed by ENISA in June 2026 hold the certification; this mapper closes the CRA-specific gap.

Map ISO 27001 → CRA

All tools are completely free — sign up only if you want to save your results, build a dossier, and export an audit package.

Free · Offline · No account

The CRA self-check as Excel — free to download

All the core capture and assessment features, running entirely on your own computer. Excel is the database; a small HTML/JS tool sits next to it.

  • Capture and assess offline in your browser — nothing is uploaded.
  • Excel export/import with a management dashboard, threat modeling and SBOM.
  • Compliance score, vulnerabilities and tasks — all in one file.

≈ 270 KB · CycloneDX/SPDX · works in any modern browser

Process

From registration to audit-ready in 4 steps

01

Register your product

The classification wizard asks 12 questions about your product and auto-assigns the correct CRA class based on Annex III.

02

Open a compliance dossier

All 28 requirements are pre-loaded. The checklist, tasks, and document tabs are ready immediately — no setup required.

03

Assess & collect evidence

Work through requirements, upload your SBOM and technical documentation, and link every file to a specific CRA article.

04

Export your audit package

One click generates a timestamped compliance report and evidence manifest. Hand it to your notified body or market surveillance authority.

Built for

Who uses CRA Studio

Manufacturers, service providers, and open-source maintainers — all in the same workspace.

Manufacturers

Hardware & software manufacturers

Product managers, compliance leads, and engineering teams running the CRA assessment for one or many products. One workspace for classification, evidence, SBOMs, and audit export.

  • Multi-product workspace
  • Per-dossier audit log
  • CE marking documentation
Service providers

Consultancies, auditors & advisors

Manage multiple manufacturer clients in one place. Multi-tenant access, white-label reporting on the roadmap, and a partner program for referrals and co-delivered assessments.

  • Multi-client tenant model
  • Partner program available
  • Co-branded audit exports (planned)
Open source

Open-source maintainers

Document your project's CRA stance, classification rationale, and security disclosure policy in a public-friendly dossier — even if you fall under the open-source steward exemption.

  • Public CVD policy hosting
  • Steward exemption documentation
  • Free for non-commercial projects

Comparison

Why not just spreadsheets or generic GRC?

You can technically do the CRA without dedicated tooling. Here is what that costs you.

FeatureSpreadsheetsGeneric GRCCRA Studio
CRA-specific workflow
Annex III classification wizard~
All 28 requirements pre-loaded
SBOM auto-parse (CycloneDX / SPDX)~
Cross-product policy inheritance~
One-click audit export~
Setup time
EU-hosted, GDPR by design~~

Full support  ~ Partial / DIY   Not supported

Security & data

Your compliance data, properly protected

CRA Studio is hosted in the EU, encrypted end-to-end, and built on GDPR-compliant infrastructure. You stay in control of your dossiers, evidence, and SBOMs at all times.

EU-hosted infrastructure

Application and database operated in the European Union. Data residency compliant with GDPR and CRA Article 13.

Encrypted in transit & at rest

TLS 1.2+ for all traffic. AES-256 at rest. Row-level security ensures tenant isolation between organisations.

You own your data

Export your dossiers, evidence, and SBOMs at any time as PDF or structured archive. No vendor lock-in.

Role-based access control

Granular roles for owner, contributor, and reviewer. Audit log on every state change for legal defensibility.

Pricing

Free. Locked-in early-adopter pricing.

No credit card. No trial period that quietly converts. Use the platform now and keep your tier price when paid plans launch.

Available now

Free

€0 / month

No credit card required.

  • Full classification wizard
  • Unlimited products & dossiers
  • All 28 CRA requirements
  • SBOM upload & parsing
  • PDF audit export
  • GDPR-compliant EU hosting

Pro

Coming soon

Early adopters users stay free.

  • Everything in Free
  • Extended audit-log retention
  • SSO / SAML
  • Advanced policy inheritance
  • Priority support
  • Custom branding on exports

Service Provider

Custom

For consultancies & auditors.

  • Multi-client tenant management
  • Co-branded audit exports
  • Partner program (referral & co-delivery)
  • Dedicated onboarding
  • DPA on request
  • Volume pricing

Questions about pricing? Email us — real human reply within one business day.

Built by people who had to comply themselves.

Every workflow — Annex III classification, dossier assessment, SBOM upload, policy inheritance, gap analysis, and audit export — is shaped around the actual text of Regulation 2024/2847, not a generic GRC checklist re-skinned for the CRA. We continually incorporate feedback from manufacturers running their first CRA assessment.

Ecosystem

Certified Service Partners

Independent consultants, law firms, and CRA experts who help manufacturers achieve compliance.

FAQ

Frequently asked questions about CRA Studio

Everything you need to decide whether CRA Studio fits your compliance workflow.

Don't see your question? info@cra-studio.eu

What's next

A roadmap built around CRA deadlines

We ship features so they land before the regulation requires them — not after.

  • Article 14 vulnerability reporting workflowLive since July 2026
  • Threat-modelling & risk assessment moduleLive since June 2026
  • Notified Body submission export formatLive since July 2026
  • SSO / SAML & enterprise multi-tenant2026 H2

Start your CRA compliance journey today

Free to start. No credit card. Your first product and dossier are ready in under 10 minutes.

432 days until full enforcement