CRA Maturity Model
Self-assess your organisation's Cyber Resilience Act readiness across 5 domains and 25 controls.
Wähle für jede Frage den Reifegrad (1 = informell, 5 = kontinuierlich verbessert). Die Auswertung — Domain-Mittelwerte, Gesamt-Score und Basis/Mittel/Fortgeschritten-Einordnung — aktualisiert sich live.
1.Governance & Documentation
Do you have written and approved product security policies?
Are roles and responsibilities clearly defined for product security activities (development, vulnerability management, updates)?
Do you maintain product-level technical documentation (security features, risk assessments, design decisions, update procedures)?
Is there a process to regularly review product security and the quality of related documentation?
Are you aware of the Market Surveillance Authority, the applicable conformity assessment procedure and how to interact with authorities?
2.Risk Management & Security by Design/Default
Do you perform cybersecurity risk assessments and use the results to guide product design, development, configuration and component decisions?
Are products designed using security-by-design principles from the outset?
Are products delivered with secure-by-default configurations and settings?
Do you perform security testing before releasing or updating a product, and to what extent are automated tools used?
When risks change or new threats emerge, are risk assessments, configurations and third-party components reviewed and updated?
3.Vulnerability & Patch Management
Do you have a process to receive, acknowledge, record and track vulnerabilities reported by customers, researchers or internal staff?
Do you have a defined process for creating, testing, delivering and communicating security updates?
Do you maintain and use an SBOM to support vulnerability and dependency management?
Are vulnerabilities and updates prioritised based on risk and potential impact?
Do you verify that security updates effectively resolve reported vulnerabilities and maintain evidence of this verification?
4.Product Lifecycle Management
Is there a defined approach to managing product security during the operational phase?
Is product lifecycle actively managed (support periods, update responsibilities, end-of-life, customer communication)?
Is experience from product operation, post-incident reviews and customer input used to improve products over time?
Is there a structured and tested way to address identified product security issues?
Are products monitored during operation to identify security risks, vulnerabilities and emerging threats?
5.Awareness, Competence & Skills
Are sufficient skills available to design, develop and maintain products securely (including external expertise where needed)?
Do relevant staff receive appropriate cybersecurity training (product risk, vulnerability management, security-by-design)?
Does the organisation promote a culture of responsible product development, open reporting and product risk awareness?
Do you follow relevant external product security information (advisories, alerts)?
Do you assess and validate that your team has the required skills and competence to maintain secure products?