CRA Reporting Readiness Gap Assessment

Free — no payment

Email me this assessment

Prefer to do it later, or share it with your engineering lead? We will send you the link plus a short CRA reporting brief.

✓ Check your inbox — the assessment is on its way.

Something went wrong. Please try again, or email info@nis-2-templates.com.

Free 10-minute self-assessment

CRA Reporting Readiness Gap Assessment

From 11 September 2026, manufacturers of products with digital elements sold into the EU must report incidents and actively exploited vulnerabilities under Article 14 of the EU Cyber Resilience Act on a 24-hour / 72-hour / final-report clock. Score yourself in 10 minutes and see exactly which gaps to close first.

✓ 22 questions ✓ Instant score & band ✓ Maps to Article 14 & Annex I Part II

How to use it. Answer all 22 questions for your in-scope products. Score Yes = 2, Partial = 1, No = 0. Your total (out of 44) gives your readiness band below. Be honest — a generous score helps no one once the 24-hour clock starts.

Educational self-check only — not legal advice and not a guarantee of compliance. The 11 September 2026 deadline is real. Non-compliance can attract fines up to €15,000,000 or 2.5% of worldwide annual turnover (Art. 64).

A. Applicability & Scope

Most reporting failures start here — a product nobody flagged as in-scope.

A1. Have you confirmed in writing whether each product is a “product with digital elements” placed on the EU market, and therefore in CRA scope?

Covered by the Applicability Assessment.

A2. Have you classified your in-scope products (default, “important” Class I/II under Annex III, or “critical” under Annex IV)?

A3. If you are a non-EU manufacturer, have you confirmed the obligations still apply because your product reaches the EU market?

A4. Have you identified products already on the market before 11 December 2027 that still fall under the Art. 14 reporting obligations?

Covered by the Legacy Product Register.

B. Vulnerability Handling & SBOM (Annex I Part II)

You cannot report what you cannot see.

B1. Do you have a documented vulnerability-handling procedure that remediates product vulnerabilities without undue delay?

Covered by the Vulnerability Handling Procedure.

B2. Do you maintain an up-to-date software bill of materials (SBOM) for each in-scope product?

Covered by the SBOM Policy & Procedure.

B3. Do you keep a central register of every reported and discovered vulnerability, with status, severity, and remediation evidence?

Covered by the Vulnerability Register.

B4. Do you publicly disclose fixed vulnerabilities and ship security updates to users in a timely, documented way?

C. Coordinated Disclosure & Intake

If a researcher cannot easily reach you, you lose the head start the 24-hour clock demands.

C1. Do you publish a coordinated vulnerability disclosure (CVD) policy telling researchers how to report issues?

Covered by the Coordinated Vulnerability Disclosure Policy.

C2. Do you provide a single, monitored contact address (security.txt / security@) dedicated to vulnerability reports?

Covered by the Security Contact & Vulnerability Intake document.

C3. Do you have a defined intake/triage workflow that acknowledges, validates, and prioritises an incoming report within a set time?

C4. Have you tested that a report arriving out of hours (evening, weekend, holiday) actually reaches a human who can act?

D. The 24h / 72h / Final-Report Workflow

The clock starts when you become aware — and it does not pause for weekends or time zones.

D1. Do you have a written procedure for reporting an actively exploited vulnerability on the 24h / 72h / 14-day timeline?

Covered by the Actively Exploited Vulnerability Reporting Procedure.

D2. Do you have a written procedure for reporting a severe incident on the 24h / 72h / 1-month timeline?

Covered by the Severe Incident Reporting Procedure.

D3. Does a duty officer have a clear decision aid to determine fast whether an event is reportable (actively exploited? severe?) and start the clock?

Covered by the Reportability Decision Tree.

D4. Do you have pre-built report templates matching the Art. 14 content for the early warning, notification, and final report?

Covered by the Report Templates (Early Warning / Notification / Final).

D5. Do you know how to submit via the ENISA single reporting platform (Art. 16) and to which coordinating CSIRT?

Covered by the Single Reporting Platform Submission Guide.

E. Roles, Operational Readiness & Evidence

A procedure on a shelf does not file a report. People, governance, and proof do.

E1. Have you appointed a named CRA Compliance Officer and a PSIRT lead, with deputies?

Covered by the Roles, Responsibilities & RACI document.

E2. Has top management formally approved a CRA reporting policy committing the organisation to the Art. 14 obligations?

Covered by the CRA Reporting Policy.

E3. Have you rehearsed the 24-hour reporting workflow under realistic time pressure (tabletop or live drill) in the last 12 months?

Covered by the Tabletop Exercise — 24-Hour Reporting Drill.

E4. Do you keep an evidence log of every reporting decision, submission, and timestamp — so you can prove what you did and when?

Covered by the Incident & Reporting Log.

E5. Could your team produce a defensible early warning within 24 hours today, if a serious vulnerability were confirmed this afternoon?

Your result

Score yourself above to see your readiness band

Add up your answers (Yes = 2, Partial = 1, No = 0) out of 44, then match your total: 0–16 High risk · 17–27 Partial readiness · 28–37 Mostly ready · 38–44 Reporting-ready. Whatever the score, every “Partial” is a half-built control — and under the 24-hour clock a half-built control behaves like a missing one.

What your band means

Total Band What it means
0–16 High risk Not reporting-ready. With under 90 days to 11 Sep 2026, a confirmed serious vulnerability today would almost certainly blow the 24-hour clock — the band where one incident becomes penalty exposure up to €15M / 2.5% of turnover. Start with scope, an owner, and the two reporting procedures now.
17–27 Partial readiness Foundations exist, but the gaps are operational and dangerous: no decision tree, no pre-built report templates, no rehearsal, or no evidence log. Convert “we know about it” into “documented, owned, and rehearsed.”
28–37 Mostly ready Strong position. Remaining gaps are the proof-and-practice layer: a tabletop drill, a complete evidence log, the legacy-product list, a tested out-of-hours path. Close these to go from “ready on paper” to “ready at 2am on a Sunday.”
38–44 Reporting-ready Excellent. Scope, owners, vulnerability handling, SBOM, intake, both reporting procedures, templates, the submission route, and evidence are all present. Focus on maintenance: keep the SBOM and register current, re-run the drill annually, keep the policy approved.
Close your gaps before 11 September 2026

Start from documents that already implement Article 14

The CRA Incident & Vulnerability Reporting Readiness Pack is 18 ready-to-adapt templates that map one-to-one to the questions you just answered — applicability assessment, vulnerability handling, SBOM, CVD policy and intake, both reporting procedures, the reportability decision tree, pre-filled report templates, the ENISA submission guide, a 24-hour tabletop drill, registers, and a 90-day checklist. Editable DOCX + XLSX, instant download.

Far less than one hour of the legal and engineering scramble a missed 24-hour deadline triggers. Buying for multiple business units, or as a consultant deploying to several clients? An Enterprise licence (€997) covers group-wide and multi-client use.

Educational self-assessment only — not legal advice and not a guarantee of compliance with Regulation (EU) 2024/2847. Verify your obligations against the regulation text and qualified counsel.

Free — no payment

Know your score. Now get the reporting brief.

We will email you this assessment to keep, plus a plain-English brief on what the 11 September 2026 reporting obligations ask of you.

✓ Check your inbox — the assessment is on its way.

Something went wrong. Please try again, or email info@nis-2-templates.com.