Privacy Design®
Knowledge Base → Frameworks & law → 🧪 CRA SME Cyber-Resilience Self-Check (ENISA)

🧪 CRA SME Cyber-Resilience Self-Check (ENISA)

An interactive rendering of ENISA’s SME Cyber Resilience Maturity Assessment Model (July 2026) — a structured self-check for micro, small and medium enterprises placing products with digital elements on the EU market under the Cyber Resilience Act (EU) 2024/2847 (applies from December 2027). Score 25 questions across five domains and get a per-domain and overall maturity profile (Basic 1.0–2.5 · Intermediate 2.6–3.9 · Advanced 4.0–5.0), with ENISA’s suggested next steps.

It runs entirely in your browser — nothing is uploaded or stored on a server. Use it to spot gaps, prioritise improvements, and re-check over time.

Open the self-check full-screen (or to print / save as PDF).

The five domains

  1. Governance and documentation — policies, roles, product-level technical documentation, review, awareness of the CRA market-surveillance authority.
  2. Risk management and security by design and by default — risk assessments, secure design, secure defaults, pre-release testing, review on changing threats.
  3. Vulnerability and patch management — intake and tracking, security updates, SBOMs, risk-based prioritisation, fix verification.
  4. Product life cycle management — operational-phase security, support periods & end-of-life, improvement from operations, structured issue handling, monitoring.
  5. Awareness, competence and skills — sufficient skills, role-based training, responsible-development culture, following advisories, competence validation.

Source & licence

See also: Security & Resilience Regulation (NIS2 · CRA · DORA · ISO 27001) · Certification, Seals & Codes of Conduct · Data & Digital Sovereignty