Find out where you stand on the Cyber Resilience Act. Today.

Seven connected compliance domains, one assessment classification through conformity, scored and exportable in under 90 minutes.

22
Annex I reqs scored
3
Reports tracked
7
Assessment stages
60-second check

Is this assessment actually worth your time?

Answer four quick questions. If CRA doesn't apply to you, we'll say so no hard sell.

CRA Scope Qualifier
Interactive readiness check
Question 1 of 4
01 Digital elements

Does your product include digital elements such as software, firmware, or any networked/connected component?

Why this assessment, why now

The Cyber Resilience Act is not a future problem anymore

Article 14 vulnerability and incident reporting obligations apply to products with digital elements placed on the EU market from 11 September 2026. Annex I essential cybersecurity requirements become fully binding on 11 December 2027.

11 Sep 2026

Reporting live

Article 14 early warning, notification, and final report deadlines start applying.

11 Dec 2027

Essential requirements

Annex I product-security and vulnerability-handling requirements become fully binding.

Art. 64

Real exposure

Penalties scale with the failure up to a percentage of global annual turnover for serious cases.

Most teams are still using spreadsheets and whoever last read the regulation carefully. That works until a CVE in your product gets actively exploited and someone asks: do we know our classification, our deadline, and what we're required to say? This assessment answers that question before it's asked under pressure.

Seven connected domains

One assessment not seven disconnected forms

Unlike a static questionnaire, each answer feeds the next domain, so by the end you have a connected picture of one product's compliance posture.

01
Classify
Product risk classification
02
Search CVE
CVE / CVSS / KEV lookup
03
Assess & KEV
Reporting-obligation logic
04
Case details
18-point structured case file
05
Report timeline
Deadlines + compliance log
06
Annex I register
22 essential requirements
07
Conformity & market
DoC, CE, Annex II, lifecycle

01 · Classification

Places your product into Standard, Important Class I/II, or Critical and carries the correct CVSS reporting threshold through every later step automatically.

Product tier Auto threshold

02 · CVE Search & Severity

Pulls CVSS score, vector string, and cross-checks CISA/ENISA KEV because active exploitation overrides every other reporting threshold under Article 14(1).

CVE lookup KEV check

03 · Reporting Obligation

Runs the Article 14 decision tree: exploited-in-the-wild override, Critical always-report rule, or classification-specific CVSS floor with a cited determination.

Art. 14 logic Cited verdict

04 · Case Documentation

An 18-section structured case file manufacturer ID, SBOM table, root cause, preventive measures, cross-border impact across 27 Member States, and more.

18 sections SBOM table

05 · Report Timeline

Calculates 24-hour, 72-hour, and 14-day deadlines from awareness with live countdown, audience-aware drafting, and an on-time / late / overdue compliance log.

Live countdown Compliance log

06 · Annex I Register

Full scored register against all 22 Part I (product security) and Part II (vulnerability handling) requirements with applicability, justification, and linked evidence.

22 requirements Evidence links

07 · Conformity & Market

Conformity routing, auto-drafted EU Declaration of Conformity, CE marking, importer/distributor checklists, tech docs index, market surveillance, and 10-year retention.

DoC draft CE tracker
What you get at the end

Leave with something in hand, not just a score

Concrete, exportable outputs you can take into legal review, GRC, or your Single Reporting Portal workflow.

EU Declaration of Conformity

Generated, editable draft

Annex II User Instructions

Generated, editable draft

Annex I Register Score

22 requirements, item by item

Deadline Compliance Log

On-time / late / overdue

Structured JSON Export

Ready for SRP / GRC / CSIRT

Portfolio Dashboard View

Across every saved product

Why this isn't just another questionnaire

Built on the actual mechanics of the regulation

Correct thresholds, automatically

The CVSS floor that triggers a mandatory report differs by product tier. The assessment applies the right one instead of leaving it to whoever fills the form.

KEV-aware by default

Active exploitation is a hard override under Article 14(1). The assessment checks this first every time — so a low-CVSS but actively exploited vulnerability never slips through.

Linked domains, not silos

Classification sets the threshold. The CVE pre-fills the case. The case drives deadlines. Register, conformity, and Annex II stay attached to the same product.

Private by design + market placement

Data stays in local private storage. And unlike tools that stop at incident reporting, this covers conformity, CE marking, economic-operator obligations, and product lifecycle.

Grounded in the regulation

Mapped directly to Regulation (EU) 2024/2847

The assessment's structure follows the regulation's own structure — so what you fill in corresponds to what a reviewer will look for.

Article 13–14

Manufacturer obligations

Risk assessment, technical documentation, essential requirements, and reporting duties.

Article 14(2)–(4)

The three deadlines

Early warning within 24 hours, notification within 72 hours, final report within 14 days.

Article 16 / 64

Retention & penalties

10-year documentation retention; fines up to €15M or 2.5% global turnover for essential-requirement breaches.

Annex I · Part I & II

Essential requirements

14 product-security requirements and 8 vulnerability-handling requirements, tracked per product.

Annex II / IV

User info & DoC

Information to the user, and the EU Declaration of Conformity content requirements.

Annex V / VIII

Tech docs & assessment

Technical documentation index, and conformity assessment procedures by product class.

Who should take this assessment

Built for the teams who own CRA outcomes

Product security / PSIRT

Get a working CVE-to-decision workflow with classification and KEV logic already correct — before you need it under deadline pressure.

Compliance & regulatory affairs

Walk away with a scored Annex I register, drafted DoC, and technical documentation index per product line — ready for audit.

Engineering & manufacturing leadership

Understand whether the product you ship creates CRA obligations, what conformity route it needs, and what's missing from technical documentation.

Legal / outside counsel support

Use the structured output as the factual foundation for legal review, rather than starting from a blank page for each product.

How the assessment works

45–90 minutes for your first product

Every subsequent product is faster — manufacturer identification, standards references, and support-period defaults carry forward.

  1. 1

    Classify your product

    A few minutes that set up everything downstream.

  2. 2

    Run a CVE through the assessment

    Get an immediate, cited reporting answer.

  3. 3

    Complete the case file

    The structured form guides you through exactly what's required.

  4. 4

    Review deadlines and drafted reports

    Then work through Annex I and conformity.

  5. 5

    Export your results

    DoC, Annex II instructions, JSON export, and portfolio view.

FAQ

Straight answers before you start

Is this legal advice?

No. The assessment mirrors the structure of Regulation (EU) 2024/2847 to give you an accurate, evidence-based starting point — always verify specific obligations against the regulation itself or your counsel.

Does completing the assessment submit anything to a regulator?

No. It drafts submission-ready documents and a structured export built to match what a Single Reporting Portal or notified body would expect — sending it is a deliberate step you take afterward.

What happens to our assessment data?

It's written to local, private storage tied to your session. Nothing leaves your environment unless you export, copy, or submit it yourself.

Can we assess more than one product?

Yes — each product gets its own case, and the portfolio dashboard gives you a single view across all of them.

How current is the CVE/KEV data used in the assessment?

The assessment can run against a representative dataset for evaluation, or be connected to the live NVD API and CISA/ENISA KEV catalogs for production use.

Ready when you are

Don't wait for a CVE to find out where you stand

Run the assessment on one real product. In under an hour you'll know your classification, reporting obligations, Annex I completion score, and exactly what's missing from your technical documentation — in writing, exportable, and ready to act on.

Proud Members & Supported by

Industry Alliances & Strategic Partnerships

We collaborate with leading technology providers, research institutes, and mobility pioneers to advance the security of connected and autonomous vehicles.

Autocrypt
Leading automotive cybersecurity solutions provider focused on secure in-vehicle and V2X communication.
Beam Connectivity
Delivering robust and scalable connected vehicle platforms for mobility OEMs.
KATECH
Korea Automotive Technology Institute advancing vehicle R&D through global partnerships.
Cyber Autonomy
Shaping AI-driven cybersecurity and threat intelligence frameworks for next-gen mobility.
Zenzic
Orchestrating the UK’s connected and automated mobility ecosystem through strategic funding and collaboration.
Digital Catapult
Driving adoption of advanced digital technologies to boost innovation and secure infrastructure.
TechWorks & AESIN
Supporting the UK’s automotive electronics innovation ecosystem through industry collaboration.
ITS UK
The UK association for Intelligent Transport Systems, promoting innovation in mobility technology.
Betaden
West Midlands' commercial tech accelerator supporting high-growth companies like CRISKLE.
Never miss an update

Join Security Leaders. Stay Ahead.

Get insider updates and actionable insights from CRISKLE and our global partners—trusted by the world's mobility and security innovators.

Sign up for early access to feature rollouts, expert briefings, and key security alerts.

How can we help?

Ask us anything about CRISKLE

Hi! I'm here to help you learn more about CRISKLE and our services. Choose a question below or get in touch with our team.