Regulation (EU) 2024/2847 · effective Dec 2027

Your All-in-One CRA Solution: Easy, Fast, Complete

ComplyPS guides manufacturers through the EU Cyber Resilience Act — from working out whether your product is in scope, to self-assessing the essential requirements, to staying audit-ready.

✓ Scope & risk classification ✓ Annex I self-assessment ✓ Readiness scoring

What is the EU Cyber Resilience Act?

The CRA (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for almost any product with digital elements placed on the EU market — hardware or software that connects to a device or network. Non-compliance can mean fines and market withdrawal.

10 Dec 2024

Entered into force

The regulation is law; the compliance clock starts ticking.

11 Sep 2026

Reporting obligations

Actively exploited vulnerabilities & severe incidents must be reported (24h / 72h).

11 Dec 2027

Main obligations apply

Full requirements, conformity assessment and CE marking become mandatory.

Why ComplyPS for CRA?

Compliance shouldn't need a team of consultants. We make it easy, fast and complete.

🧭

Easy

Plain-language questions replace dense legal text. Answer a short wizard and get a clear verdict.

Fast

Classify a product in minutes, not weeks. Instant risk-class and conformity-route guidance.

Complete

From scope to Annex I self-assessment to readiness scoring — the whole journey in one place.

Key features

Purpose-built for the Cyber Resilience Act.

🎯

Scope & risk classifier

Determine if your product is in scope and its class — default, important (Annex III, I & II) or critical (Annex IV).

📋

Annex I self-assessment

Rate every essential and vulnerability-handling requirement, capture evidence, and see your gaps.

📈

Readiness scoring

A live readiness percentage per product so you always know how close you are.

🛤️

Conformity routes

The right conformity-assessment path (Module A, B+C, H or certification) for your risk class.

🗂️

Multi-product workspace

Save assessments per product and revisit them as your portfolio grows.

🔒

Your data stays yours

Secure accounts and private assessments — built for confidentiality.

How it works

Four steps from uncertainty to audit-ready.

1

Classify

Answer a short wizard to find your scope and risk class.

2

Self-assess

Work through the Annex I requirements and record evidence.

3

Close gaps

See your readiness score and prioritise the gaps that matter.

4

Stay ready

Keep documentation current as products and the regulation evolve.

See where your product stands

Run a guided CRA scope & risk check, then go deeper with the Annex I self-assessment. Talk to us for a tailored walkthrough and access to the full platform.

Detailed pricing available on request.

Trusted by product teams

What early users say about getting CRA-ready with ComplyPS.

“We went from 'where do we even start' to a clear risk class and gap list in an afternoon.”
A
Product Security Lead
IoT manufacturer
“The Annex I self-assessment finally made the essential requirements concrete for our engineers.”
M
Compliance Manager
Industrial software vendor
“A readiness percentage we can show leadership — that alone was worth it.”
R
CTO
Connected-device startup

Illustrative testimonials shown as placeholders.

Get CRA-ready with ComplyPS

Start your assessment now, or book a demo to see the full platform.