Platanor Technologies
Beta
Next deadline — vulnerability reporting (Art. 14) begins 11 Sep 2026 · 29 days

Is your IoT product ready for the EU Cyber Resilience Act?

Start with a 2-minute scope check to confirm the CRA applies to your products and see how they classify. Then continue to the full readiness check for a prioritised, personalised list of compliance actions — each mapped to the exact CRA article, annex or standard — before the deadlines hit.

01

Personalised actions

Every action mapped to a CRA article, annex, effort estimate and deadline.

02

Readiness score

Overall and per-domain scoring against the essential requirements.

03

Export & share

Download your full action plan as a PDF report to share with your team.

What this readiness check covers

The check opens with a short scope and classification screen: whether your product connects to a network or another device (directly or indirectly), whether you place it on the EU/EEA market, and whether it falls under Default, Important Class I, Important Class II or Critical — the four CRA product categories, which determine whether self-assessment is enough or a third-party conformity route is required. Most connected products (roughly 90%) fall into the Default category.

If your products are in scope, the full check then works through seven domains built directly from the CRA’s essential requirements:

  • Secure Development Lifecyclewhether security is integrated into your engineering process
  • Security by Default & Designproduct-level security properties at time of delivery
  • Vulnerability Managementyour ability to identify, handle and remediate vulnerabilities after release, including Article 14 reporting
  • Conformity Assessment & Documentationreadiness to demonstrate conformity — SBOM, risk assessment, technical documentation
  • Supply Chain Securityhow you manage cybersecurity risk from suppliers and third-party components
  • Post-Market Obligationsoperational security obligations once products are on the market
  • Awareness & Readinessoverall organisational readiness and quick-win areas

Who it’s for

Built for IoT and connected hardware manufacturers selling into the EU/EEA, or planning to — whether you’re a product manager tracking the September 2026 and December 2027 deadlines, a CTO who needs to know where the engineering gaps are, or a compliance officer scoping the work ahead. You don’t need to already know your CRA classification; the scope check works that out for you.

What is the CRA?

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for products with digital elements — including IoT and connected devices — placed on the EU market. Manufacturers must build in security by design, handle vulnerabilities across the whole product lifecycle, and keep technical documentation.

The rules phase in gradually: vulnerability reporting obligations apply from 11 September 2026, and the Act applies in full from 11 December 2027.

Official documents

Frequently asked questions

Is this the official CRA conformity self-assessment?

No. This is a readiness check, not the CRA conformity self-assessment required under Article 32. It identifies gaps to help you prepare and does not certify compliance or replace expert advice.

Do I need to give my email or create an account?

No. The check runs anonymously with no account and no email required to see your results. Progress is saved in your browser so you can leave and resume later.

How long does it take?

The scope and classification check takes about 2 minutes. If your products are in scope, the full readiness check across all domains takes roughly 20-40 minutes, depending on how many questions apply to your product category.

What happens to my answers?

Your answers stay in your browser to generate your report. Nothing is sent to Platanor unless you choose to share your results with us.

What do I get at the end?

An overall readiness score and tier, a per-domain breakdown, and a prioritised action list where each item is mapped to the specific CRA article, annex or standard it addresses, with an effort estimate and deadline. You can export the full report as a PDF.

My product doesn't connect to a network - do I still need this?

The CRA only applies to products with digital elements that have a direct or indirect connection to a device or network. The first question in the scope check confirms whether your product is in scope at all before asking anything else.

This is a readiness check — not the CRA conformity self-assessment required under Article 32. It identifies gaps to help you prepare, and does not certify compliance or replace expert advice.