CRA · NIS2 · GDPR · Machinery Regulation · RED

Your CRA file, audit-ready. In a workspace you own.

Crosswalk turns five EU cyber laws into one guided assessment: verbatim law texts, gap analysis, evidence and the documents your auditor asks for. It runs in your browser; nothing is uploaded.

No payment details · Runs offline · Built by a CRA trainer

The Crosswalk dashboard of our own compliance file: organisation coverage 90% in place, 6 open gaps, 7 risks not closed, one product, open work per person and recent activity
  • CRA
  • NIS2
  • GDPR
  • MR
  • RED
  • No account, no upload
  • Verbatim EU law texts
  • Export to Markdown & PDF

The clock is running

What applies when

Five laws, one calendar. Some dates have passed; the rest are close enough to plan for now.

  1. Cybersecurity requirements for radio equipment apply

    RED
  2. Rules for notified bodies apply

    CRA
  3. Reporting of actively exploited vulnerabilities and severe incidents

    CRA
  4. Today
  5. Machinery Regulation applies

    MR
  6. All CRA obligations apply

    CRA

One assessment, five laws

Answer a requirement once. See where else it counts.

Overlapping obligations are mapped to each other, and the standards you already use to every law they serve, so a requirement you answer under the CRA also counts under NIS2 and the GDPR where they overlap, and a standard assessed once counts for every law it supports.

How Crosswalk maps five EU cyber laws to the standards you assess againstCRANIS2GDPRMRREDCrosswalkone assessmentIEC 62443ISO/IEC 2700122301ETSI EN 303 645EN 18031ISO/IEC 2914730111ISO/TR 22100-4IEC TS 63074
  • CRA, Cyber Resilience Act: assessed against IEC 62443, ISO/IEC 27001 and ISO 22301, ETSI EN 303 645, EN 18031, ISO/IEC 29147 and 30111.
  • NIS2, NIS2 Directive: assessed against ISO/IEC 27001 and ISO 22301, IEC 62443, ISO/IEC 29147 and 30111.
  • GDPR, General Data Protection Regulation: assessed against ISO/IEC 27001 and ISO 22301, ISO/IEC 29147 and 30111.
  • MR, Machinery Regulation: assessed against ISO/TR 22100-4 and IEC TS 63074, IEC 62443, ISO/IEC 27001 and ISO 22301.
  • RED, Radio Equipment Directive: assessed against EN 18031, ETSI EN 303 645.

Hover or focus a law to see which standards Crosswalk assesses it against. Standards stay voluntary; the law is the binder.

The product

What you get

See where you stand

The dashboard shows coverage per law for the organisation, the open gaps and risks, who owns which piece of work and what changed last. One project, all five laws, in a workspace you own.

5 laws
1 workspace
0 uploads
The Crosswalk dashboard: organisation coverage 90% in place, open gaps, risks, open work per person and recent activity

Close the gaps with evidence

Every requirement has its place in the tree: the law text beside it, the control to assess, the evidence to attach and the to-do with an owner and a date. Gaps are listed, not hidden.

The navigation tree of a Crosswalk project: dashboard, organisation, organisation assessment, products, reports and tools

Hand your auditor the file

Generate the audit report set: a management review, one document per law for the organisation and per product, and the technical documentation in the order Annex VII prescribes. As Markdown or PDF, with the source snapshot on every document.

The audit report set with four generated documents, each with View, Markdown and PDF

This is our own CRA file. Crosswalk is itself a product with digital elements, and we keep its compliance file in Crosswalk.

Free tools

Start with the scan, then the hub for your law

Everything here is free and runs in your browser. The scan tells you which laws apply; the hubs and tools take you from there.

Compliance scan · 2 minutes

Which EU cyber laws apply to you?

A few questions about where you operate, what you make and whom you serve. You get a yes or no per law, the reasoning, and the tools that fit.

  1. 01Where does your organization operate?
  2. 02What type of organization are you?
  3. 03How large is your organization?
  4. and up to ten more, depending on your answers
CRA applies from 11 Dec 2027

CRA Compliance Hub

For anyone placing products with digital elements on the EU market: obligations, requirements, the timeline, penalties and the free CRA tools.

  • Gap analysis
  • Product checker
  • Risk classifier
  • Checklist
  • RACI
NIS2 measures apply since 18 Oct 2024

NIS2 Compliance Hub

For essential and important entities: risk-management measures, incident reporting, governance, and whether your sector is in scope.

  • Sector checker
  • Compliance steps
  • Incident reporting
CRA

CRA Gap Analysis

Where you stand against the essential requirements.

CRA

CRA Product Checker

Is your product in scope, and in which class?

CRA

CRA Risk Classifier

Default, important or critical.

CRA

CRA Checklist

The obligations as a printable list.

NIS2

NIS2 Sector Checker

Essential, important, or out of scope.

GDPR

GDPR Compliance Hub

Lawful processing, security of processing, breach notification.

MR

Machinery Regulation Hub

Regulation (EU) 2023/1230, applies from 20 January 2027: overview, articles, obligations, six steps to conformity, timeline.

CRA

CRA RACI

Who does what, as a printable matrix.

Built on proven standards

The frameworks behind the laws

Each law has its frameworks: ENISA guidance and IEC 62443 for the CRA, ISO 27001 for NIS2, ISO 27701 for the GDPR, ISO/TR 22100-4 and IEC TS 63074 for the Machinery Regulation. The site shows where they overlap, so one investment serves several laws.

  • ENISA ENISA Guidelines EU Cybersecurity Agency
  • ISO ISO 27001 Information Security Management
  • ISO ISO 27701 Privacy Management (PIMS)
  • IEC IEC 62443 Industrial Cybersecurity
  • ISO ISO 31000 Risk Management
  • NIST NIST CSF 2.0 Cybersecurity Framework
  • ISO ISO 27002 Security Controls
  • ISO ISO 29134 Privacy Impact Assessment
  • ISAE ISAE 3000 Assurance Engagements
  • CIS CIS Controls v8 Center for Internet Security
  • SOC SOC 2 Trust Services Criteria
  • ISO ISO 27035 Incident Management

Who this is for

Three kinds of reader, one file

Small and medium businesses

The problem. You have to comply, and professional advice costs thousands of euros you would rather spend on the product.

What you get. Plain-English guides and free tools that fit a small budget and a real timeline, and a workspace that starts at no cost.

Developers and tech teams

The problem. The regulations are written for lawyers, and you are the one who has to build what they ask.

What you get. Requirements as controls with the law text beside them, standards mapped to each, and guidance you can act on in a sprint.

Compliance and legal teams

The problem. You explain complex obligations to people who do not read regulations, and you owe the auditor a complete file.

What you get. Clear, structured resources for the board and the engineers, and an audit-ready file with evidence, gaps and sign-off.

Portrait of Marcel Depré

Who builds this

Marcel Depré

Software security and compliance specialist with more than thirty years in OT software development: factory automation, control algorithms, test frameworks and automated generation of compliance evidence, with secure product development under IEC 62443-4-1 and 4-2 in industrial control. He developed and teaches the four-day Cyber Resilience Act course at Mikrocentrum and speaks on security in OT. Before that: thirteen years of OPC and RFID courses for Mikrocentrum.

  • 30+ years in OT software
  • Automated compliance evidence
  • IEC 62443-4-1 / 4-2
  • CRA course, Mikrocentrum (4 days)
  • Speaker on security in OT

Start your CRA file today.

The Lite licence costs nothing to start: one project, all five laws, no payment details.