CRA Art. 13 — Risk Assessment

Cybersecurity Risk Assessment

Assess the cybersecurity risk profile of your product as required by CRA Art. 13 and Annex I. Identify your threat exposure, find gaps in your security posture, and prioritise the Annex I requirements that matter most for your product.

Risk profile per area
Prioritised Annex I gaps
Private & confidential

100% Private Assessment

All calculations happen in your browser. No data is transmitted or stored on our servers. Your product information remains completely confidential.

This is not a CRA product classification

This tool assesses your product's cybersecurity risk profile — not its CRA category. CRA product classification (Default, Important Class I/II, Critical) is determined by product type, not by a risk score. Use the Product Checker to determine your CRA classification.

Cybersecurity Risk Assessment

1. Product Context

Describe your product to establish the baseline context for the risk assessment.

2. Threat & Exposure Profile

These factors determine the cybersecurity threats your product faces and its exposure to attack.

3. Current Security Posture

Check what you have already implemented. Unchecked items will be flagged as compliance gaps, prioritised by your risk profile.

Annex I Part I — Essential Cybersecurity Requirements

Annex I Part II — Vulnerability Handling Requirements

🤝 Still Feeling Overwhelmed by CRA?

The Cyber Resilience Act has a lot of moving parts. Our free tools work great for most people, but if you're dealing with something really complex or have a tight deadline, we can help you figure it out faster.