Self-check · CRA / 2024/2847
Work through the 22 requirements of Annex I to Regulation (EU) 2024/2847 — product properties and vulnerability handling. You get a score, gaps and a fix order.
The questionnaire goes requirement by requirement through Annex I to Regulation (EU) 2024/2847: first the product properties from Part I, then the vulnerability handling processes from Part II. Each question comes with a short explanation of what is actually expected from the manufacturer. Your answers stay in your browser, nothing is sent anywhere and nobody asks for your email.
We do not copy out the wording of the regulation — the questions paraphrase it and each one names the point it comes from. The official text is in Annex I on EUR-Lex.
Point 1 applies always and unconditionally. The requirements of point 2 apply, in the words of its opening sentence, “where applicable” on the basis of the cybersecurity risk assessment under Article 13(2) — which is why “not applicable” is an option for them. The justification then belongs in the technical documentation (Article 13(4)).
The remaining seven requirements of point 2: the data processed, availability, impact on surrounding networks, attack surfaces, mitigating the impact of an incident, security logging and data deletion.
Eight requirements on the manufacturer's processes. Unlike point 2 of Part I they are not tied to the risk assessment and there is no “not applicable” option: under Article 6(b), processes that comply with Part II are a condition for making the product available on the market.
The score is only a summary of the answers: “yes” counts in full, “partially” counts as half, “not applicable” is excluded from the calculation. It is not a measure of compliance with the regulation.
The output is based solely on your answers and is indicative — it is not evidence of conformity or a conformity assessment under Article 32. The score is useful for comparing yourself against yourself over time, not for comparison with other manufacturers.
CypherOn provides cybersecurity consulting services and is not a law firm. For legal opinions, turn to an attorney registered with the Czech Bar Association.
What SCA, SAST, DAST and image scanning actually find, how a software bill of materials and VEX are produced, what to block in CI/CD, and how KEV and EPSS feed the decision to report under Article 14.
Open DevSecOpsScope, your role in the supply chain and the product category under Annexes III and IV — and the conformity assessment route that follows from them under Article 32.
Open the calculatorWhen a vulnerability counts as actively exploited or an incident as severe, the 24 h / 72 h deadlines and the final report, the content of each report and preparing for the ENISA platform.
Open the procedureThe questions and their explanations are based on the sources below, as they stood on 9 August 2026. What binds is the wording of the legislation, not our reading of it.
When the questionnaire produces a longer list
Product threat modelling, secure development review, vulnerability management and the inputs for the technical documentation under Annex VII. Tell us which points came out as gaps and where you stand today.