🧪 CRA SME Cyber-Resilience Self-Check (ENISA)
An interactive rendering of ENISA’s SME Cyber Resilience Maturity Assessment Model (July 2026) — a structured self-check for micro, small and medium enterprises placing products with digital elements on the EU market under the Cyber Resilience Act (EU) 2024/2847 (applies from December 2027). Score 25 questions across five domains and get a per-domain and overall maturity profile (Basic 1.0–2.5 · Intermediate 2.6–3.9 · Advanced 4.0–5.0), with ENISA’s suggested next steps.
It runs entirely in your browser — nothing is uploaded or stored on a server. Use it to spot gaps, prioritise improvements, and re-check over time.
▶ Open the self-check full-screen (or to print / save as PDF).
The five domains
- Governance and documentation — policies, roles, product-level technical documentation, review, awareness of the CRA market-surveillance authority.
- Risk management and security by design and by default — risk assessments, secure design, secure defaults, pre-release testing, review on changing threats.
- Vulnerability and patch management — intake and tracking, security updates, SBOMs, risk-based prioritisation, fix verification.
- Product life cycle management — operational-phase security, support periods & end-of-life, improvement from operations, structured issue handling, monitoring.
- Awareness, competence and skills — sufficient skills, role-based training, responsible-development culture, following advisories, competence validation.
Source & licence
- Model: ENISA, SME Cyber Resilience Maturity Assessment Model, July 2026 — official PDF (ISBN 978-92-9204-799-3, DOI 10.2824/1676704).
- Questions and maturity descriptions are reproduced from the ENISA model, reused under CC BY 4.0. This is an unofficial interactive rendering, not an ENISA product.
- Disclaimer: an advanced maturity level supports structured improvement but does not replace legal obligations and is not evidence of CRA compliance.
See also: Security & Resilience Regulation (NIS2 · CRA · DORA · ISO 27001) · Certification, Seals & Codes of Conduct · Data & Digital Sovereignty