CRA Readiness Self-Assessment
Measure how ready your organisation is for the EU Cyber Resilience Act.
What this is
The Cyber Resilience Act (CRA) sets cybersecurity requirements for products with digital elements sold in the EU. This self-check walks you through the full questionnaire: 25 questions across five domains, from governance and documentation to awareness and skills. Your answers produce a maturity score from 1 to 5 and a maturity profile (basic, intermediate or advanced) with recommended actions for improvement.
How it works
- 1You answer one questionnaire at a time; the bar at the top shows your progress.
- 2Each question has five response options: pick the one that best matches your current practice (1 = lowest maturity, 5 = highest).
- 3Your score is calculated automatically: the average within each domain, then the average across the five domains.
- 4At the end you see the guidance for your score range, exactly as published in the model.
- It takes about 10 to 15 minutes.
- The questionnaire is shown in English, exactly as originally published.
- Your answers stay in your browser: nothing is sent to our servers and no account is needed.
- An advanced maturity level should not be read as proof of CRA compliance.
Before you answer: guidance from the model
Each question in Annex A has five response options, corresponding to increasing levels of maturity:
- 1 corresponds to Level 1 (score = 1);
- 2 corresponds to Level 2 (score = 2);
- 3 corresponds to Level 3 (score = 3);
- 4 corresponds to Level 4 (score = 4);
- 5 corresponds to Level 5 (score = 5).
Guidance on composite questions
Some questions in this assessment cover multiple related practices (e.g. risk assessment, secure design and component management). This is intended to keep the questionnaire concise.
Where an organisation performs well in some aspects but not in others, the score should reflect the lowest level that is consistently achieved. If needed, organisations may use internal notes to assess each aspect separately before selecting an overall score. Where significant differences exist between aspects, organisations are encouraged to internally assess them separately before selecting an overall score. The descriptions of maturity levels and domains in Section 2 can be used as a reference when selecting responses.
Source and attribution
The questionnaire (Annex A) and the guidance (Annex B) on this page are reproduced verbatim from the SME Cyber Resilience Maturity Assessment Model, ENISA, 2026, DOI 10.2824/1676704. Only the presentation, the guided flow and the automatic score calculation are provided by RedComply.
Official ENISA publication (PDF)Working towards EU product cybersecurity compliance? RedComply automates EN 18031 / RED Directive technical documentation for manufacturers.
Explore RedComply