Free Tool

CRA Applicability Assessment

Assessment adapted from CRA Article 2 and Article 3, to determine whether a specific product falls within EU Cyber Resilience Act scope, and if it does, which conformity tier applies. Screen one product at a time; run it again separately for every accessory or companion product. Export the result as a txt file.

Assessment logic last reviewed 13 September 2026. Key CRA dates: Article 14 vulnerability/incident reporting has applied since 11 September 2026; full application, including conformity assessment and CE marking, begins 11 December 2027.

This tool provides a preliminary screening result based on Aktriva's reading of CRA Article 2 and Article 3 (Regulation (EU) 2024/2847) and public European Commission guidance, current as of the "last reviewed" date above. CRA harmonised standards and further implementing or delegated acts refining classification under Annexes III and IV are still being finalized. This is decision support only — it does not replace a documented, product-specific regulatory determination, and it is not legal advice. Confirm your product's status with qualified regulatory counsel before relying on it for market-placement decisions.

Need this run as a documented program, not a one-off check?

Talk to Us About Regulatory Compliance