Diagnostic CRA
Cyber Resilience Act — Regulation (EU) 2024/2847
4 days before the exploited-vulnerability reporting obligation applies (Art. 14 — 11 September 2026)
  1. 1Your website
  2. 2security.txt check
  3. 3Product qualification
  4. 4Diagnostic
✦ 3 minutes to find your position

Assess your exposure to the Cyber Resilience Act

Enter your company’s domain: we check public security-maturity markers, then qualify your product against the CRA (scope, role, risk class). The result is displayed with no sign-up.

This public check does not establish CRA compliance: it checks, among other things, for a security.txt file (RFC 9116). Your domain is only used for this public technical check. Nothing is sent without your action.

Already know you're in scope? No need to qualify:

Book a free hour with an engineer →