Is your IoT product ready for the EU Cyber Resilience Act?
Start with a 2-minute scope check to confirm the CRA applies to your products and see how they classify. Then continue to the full readiness check for a prioritised, personalised list of compliance actions — each mapped to the exact CRA article, annex or standard — before the deadlines hit.
Personalised actions
Every action mapped to a CRA article, annex, effort estimate and deadline.
Readiness score
Overall and per-domain scoring against the essential requirements.
Export & share
Download your full action plan as a PDF report to share with your team.
What this readiness check covers
The check opens with a short scope and classification screen: whether your product connects to a network or another device (directly or indirectly), whether you place it on the EU/EEA market, and whether it falls under Default, Important Class I, Important Class II or Critical — the four CRA product categories, which determine whether self-assessment is enough or a third-party conformity route is required. Most connected products (roughly 90%) fall into the Default category.
If your products are in scope, the full check then works through seven domains built directly from the CRA’s essential requirements:
- Secure Development Lifecycle — whether security is integrated into your engineering process
- Security by Default & Design — product-level security properties at time of delivery
- Vulnerability Management — your ability to identify, handle and remediate vulnerabilities after release, including Article 14 reporting
- Conformity Assessment & Documentation — readiness to demonstrate conformity — SBOM, risk assessment, technical documentation
- Supply Chain Security — how you manage cybersecurity risk from suppliers and third-party components
- Post-Market Obligations — operational security obligations once products are on the market
- Awareness & Readiness — overall organisational readiness and quick-win areas
Who it’s for
Built for IoT and connected hardware manufacturers selling into the EU/EEA, or planning to — whether you’re a product manager tracking the September 2026 and December 2027 deadlines, a CTO who needs to know where the engineering gaps are, or a compliance officer scoping the work ahead. You don’t need to already know your CRA classification; the scope check works that out for you.
What is the CRA?
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for products with digital elements — including IoT and connected devices — placed on the EU market. Manufacturers must build in security by design, handle vulnerabilities across the whole product lifecycle, and keep technical documentation.
The rules phase in gradually: vulnerability reporting obligations apply from 11 September 2026, and the Act applies in full from 11 December 2027.
Official documents
Frequently asked questions
Is this the official CRA conformity self-assessment?
No. This is a readiness check, not the CRA conformity self-assessment required under Article 32. It identifies gaps to help you prepare and does not certify compliance or replace expert advice.
Do I need to give my email or create an account?
No. The check runs anonymously with no account and no email required to see your results. Progress is saved in your browser so you can leave and resume later.
How long does it take?
The scope and classification check takes about 2 minutes. If your products are in scope, the full readiness check across all domains takes roughly 20-40 minutes, depending on how many questions apply to your product category.
What happens to my answers?
Your answers stay in your browser to generate your report. Nothing is sent to Platanor unless you choose to share your results with us.
What do I get at the end?
An overall readiness score and tier, a per-domain breakdown, and a prioritised action list where each item is mapped to the specific CRA article, annex or standard it addresses, with an effort estimate and deadline. You can export the full report as a PDF.
My product doesn't connect to a network - do I still need this?
The CRA only applies to products with digital elements that have a direct or indirect connection to a device or network. The first question in the scope check confirms whether your product is in scope at all before asking anything else.
This is a readiness check — not the CRA conformity self-assessment required under Article 32. It identifies gaps to help you prepare, and does not certify compliance or replace expert advice.