Regulation (EU) 2024/2847 · effective Dec 2027

ComplyCRA — your all-in-one CRA compliance solution

From working out whether your product is in scope, to self-assessing Annex I, to an AI gap assessment and audit-ready reports — with all of your data processed privately.

Request a live demo
✓ Scope & risk classification ✓ Annex I self-assessment ✓ AI gap assessment
complyps.com/complyps-cra/app Compliance overview Your CRA posture across all products, with open reporting deadlines. 78% Overall coverage Products 6 5 in scope Avg Annex I readiness 82% Reporting overdue 0 Products ACME Router X1 Default 92% SmartHub Gateway Important II 78% SecureCam Pro Critical 64% Edge Controller Important I 88% Key CRA dates Reporting obligations11 Sep 2026 Main obligations11 Dec 2027 Support periodsOK
Reg. (EU) 2024/2847
Built on the official CRA text
Offline & private
Your data never leaves your control
Ready before Dec 2027
Beat the compliance deadline
Classify in minutes
No account needed to start
WHAT'S INSIDE

Everything you need to get CRA-ready

Coverage across every product, open reporting deadlines, SBOM vulnerabilities and an AI gap assessment — one guided workflow, with your data kept private.

  • Overall coverage % rolled up across all products
  • Offline SBOM scanning against known CVEs & exploited-vuln status
  • Approval-gated reporting with 24h / 72h / final templates
  • Your data stays private — processed on your own infrastructure

What is the EU Cyber Resilience Act?

The CRA (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for almost any product with digital elements placed on the EU market — hardware or software that connects to a device or network. Non-compliance can mean fines and market withdrawal.

10 Dec 2024

Entered into force

The regulation is law; the compliance clock starts ticking.

11 Sep 2026

Reporting obligations

Actively exploited vulnerabilities & severe incidents must be reported (24h / 72h).

11 Dec 2027

Main obligations apply

Full requirements, conformity assessment and CE marking become mandatory.

Why ComplyPS for CRA?

Compliance shouldn't need a team of consultants. We make it easy, fast and complete.

🧭

Easy

Plain-language questions replace dense legal text. Answer a short wizard and get a clear verdict.

Fast

Classify a product in minutes, not weeks. Instant risk-class and conformity-route guidance.

Complete

From scope to Annex I self-assessment to readiness scoring — the whole journey in one place.

Key features

Purpose-built for the Cyber Resilience Act.

🎯

Scope & risk classifier

Determine if your product is in scope and its class — default, important (Annex III, I & II) or critical (Annex IV).

📋

Annex I self-assessment

Rate every essential and vulnerability-handling requirement, capture evidence, and see your gaps.

📈

Readiness scoring

A live readiness percentage per product so you always know how close you are.

🛤️

Conformity routes

The right conformity-assessment path (Module A, B+C, H or certification) for your risk class.

🗂️

Multi-product workspace

Save assessments per product and revisit them as your portfolio grows.

🔒

Your data stays yours

Secure accounts and private assessments — built for confidentiality.

How it works

Four steps from uncertainty to audit-ready.

1

Classify

Answer a short wizard to find your scope and risk class.

2

Self-assess

Work through the Annex I requirements and record evidence.

3

Close gaps

See your readiness score and prioritise the gaps that matter.

4

Stay ready

Keep documentation current as products and the regulation evolve.

See where your product stands

Run a guided CRA scope & risk check, then go deeper with the Annex I self-assessment. Talk to us for a tailored walkthrough and access to the full platform.

Detailed pricing available on request.

Trusted by product teams

What early users say about getting CRA-ready with ComplyPS.

“We went from 'where do we even start' to a clear risk class and gap list in an afternoon.”
A
Product Security Lead
IoT manufacturer
“The Annex I self-assessment finally made the essential requirements concrete for our engineers.”
M
Compliance Manager
Industrial software vendor
“A readiness percentage we can show leadership — that alone was worth it.”
R
CTO
Connected-device startup

Illustrative testimonials shown as placeholders.

CRA Insights

Guidance from people who know the CRA

Nine plain-English articles — scope, risk classes, Annex I, SBOMs, reporting, CVD and more — written from the regulation and security best practice.

Browse all 9 articles

Get CRA-ready with ComplyPS

Open ComplyCRA now, or book a demo and we'll walk you through the whole platform.

Book a demo

Tell us a bit about you and we'll be in touch to arrange a walkthrough.