Email me this assessment
Prefer to do it later, or share it with your engineering lead? We will send you the link plus a short CRA reporting brief.
CRA Reporting Readiness Gap Assessment
From 11 September 2026, manufacturers of products with digital elements sold into the EU must report incidents and actively exploited vulnerabilities under Article 14 of the EU Cyber Resilience Act on a 24-hour / 72-hour / final-report clock. Score yourself in 10 minutes and see exactly which gaps to close first.
How to use it. Answer all 22 questions for your in-scope products. Score Yes = 2, Partial = 1, No = 0. Your total (out of 44) gives your readiness band below. Be honest — a generous score helps no one once the 24-hour clock starts.
Educational self-check only — not legal advice and not a guarantee of compliance. The 11 September 2026 deadline is real. Non-compliance can attract fines up to €15,000,000 or 2.5% of worldwide annual turnover (Art. 64).
Score yourself above to see your readiness band
Add up your answers (Yes = 2, Partial = 1, No = 0) out of 44, then match your total: 0–16 High risk · 17–27 Partial readiness · 28–37 Mostly ready · 38–44 Reporting-ready. Whatever the score, every “Partial” is a half-built control — and under the 24-hour clock a half-built control behaves like a missing one.
What your band means
| Total | Band | What it means |
|---|---|---|
| 0–16 | High risk | Not reporting-ready. With under 90 days to 11 Sep 2026, a confirmed serious vulnerability today would almost certainly blow the 24-hour clock — the band where one incident becomes penalty exposure up to €15M / 2.5% of turnover. Start with scope, an owner, and the two reporting procedures now. |
| 17–27 | Partial readiness | Foundations exist, but the gaps are operational and dangerous: no decision tree, no pre-built report templates, no rehearsal, or no evidence log. Convert “we know about it” into “documented, owned, and rehearsed.” |
| 28–37 | Mostly ready | Strong position. Remaining gaps are the proof-and-practice layer: a tabletop drill, a complete evidence log, the legacy-product list, a tested out-of-hours path. Close these to go from “ready on paper” to “ready at 2am on a Sunday.” |
| 38–44 | Reporting-ready | Excellent. Scope, owners, vulnerability handling, SBOM, intake, both reporting procedures, templates, the submission route, and evidence are all present. Focus on maintenance: keep the SBOM and register current, re-run the drill annually, keep the policy approved. |
Start from documents that already implement Article 14
The CRA Incident & Vulnerability Reporting Readiness Pack is 18 ready-to-adapt templates that map one-to-one to the questions you just answered — applicability assessment, vulnerability handling, SBOM, CVD policy and intake, both reporting procedures, the reportability decision tree, pre-filled report templates, the ENISA submission guide, a 24-hour tabletop drill, registers, and a 90-day checklist. Editable DOCX + XLSX, instant download.
Far less than one hour of the legal and engineering scramble a missed 24-hour deadline triggers. Buying for multiple business units, or as a consultant deploying to several clients? An Enterprise licence (€997) covers group-wide and multi-client use.
Educational self-assessment only — not legal advice and not a guarantee of compliance with Regulation (EU) 2024/2847. Verify your obligations against the regulation text and qualified counsel.
Know your score. Now get the reporting brief.
We will email you this assessment to keep, plus a plain-English brief on what the 11 September 2026 reporting obligations ask of you.
