CRA Compliance Tools

Interactive resources aligned with ENISA Guidelines and ISO/IEC standards

From initial assessments to ongoing monitoring, these tools leverage EU-driven ENISA Guidelines, IEC 62443 for secure development, and ISO/IEC 27001 frameworks to guide you through every aspect of CRA compliance.

Standards-Based Compliance Assessment

Start with our ENISA-aligned gap analysis that maps your existing ISO/IEC 27001 and IEC 62443 certifications to CRA requirements, saving you time and effort.

  • ENISA Guidelines framework
  • ISO/IEC certification mapping
  • IEC 62443 compliance credit
  • Personalized action plan
Start Assessment →

All CRA Tools

Comprehensive toolkit for every stage of CRA compliance

Assessment & Planning

Start here to understand your CRA obligations and plan your compliance journey

ENISA-Aligned Gap Analysis Wizard

Interactive assessment using ENISA Guidelines to identify compliance gaps and map existing ISO/IEC certifications

Beginner ⏱️ 15-20 minutes
  • ENISA framework mapping
  • ISO 27001/IEC 62443 credit
  • Downloadable report
Use Tool →

Product Risk Calculator

Determine your product's risk classification (default, important, critical) based on CRA criteria

Beginner ⏱️ 10 minutes
  • Risk classification
  • Requirements mapping
  • Certification guidance
Use Tool →

Implementation Timeline

Create a customized implementation roadmap based on your product type and timeline constraints

Intermediate ⏱️ 20 minutes
  • Custom timelines
  • Milestone tracking
  • Resource planning
Use Tool →

Implementation & Documentation

Tools to build security measures and create required documentation

IEC 62443 Security Requirements Builder

Generate comprehensive security requirements following IEC 62443-4-1 and 4-2 standards for secure product development

Intermediate ⏱️ 45-60 minutes
  • IEC 62443-4-1 SDL templates
  • IEC 62443-4-2 technical specs
  • ISO 27034 integration
Use Tool →

CE Marking Generator

Create compliant CE marking documentation and declarations of conformity for CRA

Intermediate ⏱️ 30 minutes
  • Declaration templates
  • CE marking guidance
  • Compliance checklists
Use Tool →

SBOM Generator

Create Software Bill of Materials (SBOM) documents required for CRA compliance

Advanced ⏱️ 60+ minutes
  • Component scanning
  • Vulnerability mapping
  • Export formats
Use Tool →

ISO 29147/30111 Disclosure Policy Builder

Create coordinated vulnerability disclosure policies following ISO/IEC 29147 and 30111 standards

Beginner ⏱️ 20 minutes
  • ISO 29147 disclosure templates
  • ISO 30111 handling process
  • ENISA workflows
Use Tool →

Testing & Validation

Verify your implementation meets CRA security and compliance requirements

Security Testing Suite

Comprehensive security testing toolkit for CRA compliance verification

Advanced ⏱️ 2-4 hours
  • Automated scanning
  • Penetration testing
  • Vulnerability assessment
Use Tool →

Compliance Checker

Verify your current implementation against all CRA requirements with detailed reporting

Intermediate ⏱️ 30 minutes
  • Requirement verification
  • Compliance scoring
  • Action planning
Use Tool →

Conformity Assessment Planner

Plan your conformity assessment process based on product risk classification

Advanced ⏱️ 60 minutes
  • Assessment modules
  • Notified body finder
  • Cost estimation
Use Tool →

Monitoring & Maintenance

Ongoing tools for post-market surveillance and security maintenance

Threat Intelligence Monitor

Monitor emerging threats and vulnerabilities affecting your product category

Intermediate ⏱️ Setup: 30 min, Ongoing
  • CVE monitoring
  • Threat feeds
  • Alert system
Use Tool →

Update Tracker

Track security updates and patch deployment across your product lifecycle

Intermediate ⏱️ Setup: 45 min, Ongoing
  • Patch tracking
  • Deployment monitoring
  • Lifecycle management
Use Tool →

Incident Response Planner

Create and manage security incident response procedures for CRA compliance

Advanced ⏱️ 2-3 hours
  • Response workflows
  • Communication templates
  • Timeline tracking
Use Tool →

Tools by Product Type

Find tools specific to your type of digital product

💻

Software Products

Desktop apps, mobile apps, embedded software

  • SBOM Generator
  • Security Testing Suite
  • Update Mechanism Planner
  • Vulnerability Disclosure Builder
📱

IoT & Embedded

Connected devices, smart home, industrial IoT

  • Device Security Checker
  • Network Security Validator
  • Hardware Security Planner
  • Lifecycle Management Tools
☁️

Cloud Services

SaaS platforms, cloud infrastructure, APIs

  • Service Security Assessment
  • API Security Checker
  • Cloud Compliance Validator
  • Data Protection Planner
🏭

Industrial Systems

SCADA, industrial control, critical infrastructure

  • Critical System Assessor
  • Safety-Security Integration
  • Standards Compliance Checker
  • Risk Assessment Framework

Need Additional Support?

Our tools provide comprehensive guidance, but complex implementations may benefit from expert consultation.

Expert Consultation

Get personalized guidance from CRA compliance experts

Contact Experts

Implementation Services

Full-service CRA compliance implementation and certification support

Learn More

Tool Updates

Our tools are regularly updated to reflect the latest CRA guidance and implementation standards.

Last updated: August 2024
  • • Added SBOM generator with CVE integration
  • • Enhanced gap analysis with new product categories
  • • Updated CE marking templates for 2024 requirements

🤝 Still Feeling Overwhelmed by CRA?

The Cyber Resilience Act has a lot of moving parts. Our free tools work great for most people, but if you're dealing with something really complex or have a tight deadline, we can help you figure it out faster.