Start with Maditon

/ Free CRA readiness scan

Cyber Resilience Act

Reporting obligations start 11 September 2026

Twelve questions, five minutes, no signup. Find out whether the CRA applies to you, which obligations land first, and exactly where your gaps are.

31 days until reporting obligations apply
What the scan covers

Free · No account · Scored in your browser — nothing is sent to us until you ask for the report

What happens on 11 September 2026?

From 11 September 2026, a manufacturer that places a product with digital elements on the EU market must report actively exploited vulnerabilities in it, and severe incidents affecting its security, to its coordinator CSIRT and ENISA simultaneously through a single reporting platform. Three clocks run from becoming aware: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days of a fix being available. Check where you stand →

Who this is for

Software and hardware vendors that put products with digital elements on the EU market — and everyone downstream of them: importers, distributors, and open-source stewards.

Hardware with software in it

Anything connected — industrial kit, consumer IoT, medical-adjacent devices, network hardware.

Software you ship

On-premise applications, agents, SDKs, firmware, developer tooling — sold, licensed, or given away commercially.

Not sure whether your SaaS counts?

That is question 1. Pure SaaS is usually outside the CRA — but remote data processing that is integral to a product you ship is not. The scan draws that line for you.

Importers, distributors, OSS stewards

You carry your own obligations, lighter than a manufacturer’s but real. The scan tells you which set applies.

What you get

An applicability verdict

In scope, likely in scope, or likely out of scope — with the specific answers that drove the result.

Your obligation timeline

What lands on 11 September 2026 versus what waits until 11 December 2027.

A named gap list

Every unmet readiness check, what it means in plain English, and the article it maps to.

The full report by email

The complete gap list with explanations, sent once. No drip sequence, no newsletter unless you tick the box.

11 September 2026

Reporting obligations apply

Manufacturers must notify actively exploited vulnerabilities and severe incidents to their coordinator CSIRT and ENISA, starting with a 24-hour early warning.

11 December 2027

The Regulation applies in full

Essential cybersecurity requirements, vulnerability handling, conformity assessment, CE marking, and technical documentation all become enforceable.

How it works

  1. 01

    Answer 12 questions

    Three short phases: applicability, classification, September readiness. Around five minutes.

  2. 02

    See your result instantly

    Scored in your browser against fixed rules. No AI, no waiting, no data leaves the page.

  3. 03

    Get the full report

    Leave an email address and the complete gap list lands in your inbox.

No account. No credit card. No sales call unless you ask for one.

This scan uses no AI. Your answers are scored in your browser against a fixed set of rules, so the same answers always produce the same result.

Where your data goes

  • Your answers are scored in your browser. Nothing is sent to us until you ask for the report.
  • If you request the report, we store your email, the company name you gave us, and your answers on EU infrastructure (UpCloud, Finland).
  • The report email is sent by MailPace (UK company, EU-hosted). Analytics is Plausible — cookieless, EU-hosted, no personal data.
  • We never sell or share your data. Ask us to delete it and we will — no form to fill in, no reason required.

Read the privacy policy

The CRA Readiness Scan is built by Maditon — an EU-sovereign regulatory compliance platform for startups and SMEs, made by Abiton Ventures AB in Sweden. See what Maditon does

Questions people ask before starting

Is the CRA Readiness Scan legal advice?

No. The scan is informational. It applies a fixed set of rules to the answers you give and points you at the relevant parts of the Cyber Resilience Act. It is not a legal opinion, it does not create a lawyer-client relationship, and it cannot account for the specifics of your product or contracts. Treat the result as a starting point for a conversation with your own counsel.

Does the Cyber Resilience Act apply to pure SaaS?

Usually not. The CRA regulates products with digital elements placed on the EU market — hardware and software you ship. A web application you host and operate yourself is generally governed by NIS2 and the GDPR instead. The exception matters though: where remote data processing is integral to a product with digital elements, that processing is pulled into the product’s scope. If your SaaS is the cloud half of a device or an installed application, the CRA is likely in play. That is exactly what the first two questions of the scan test.

What actually happens on 11 September 2026?

The reporting obligations start. From that date a manufacturer that becomes aware of an actively exploited vulnerability in its product, or of a severe incident affecting the product’s security, must notify the coordinator CSIRT and ENISA simultaneously, through a single reporting platform. Three deadlines follow: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days of a fix being available — or within a month of the notification, for a severe incident. The rest of the Regulation, including the essential cybersecurity requirements and CE marking, applies from 11 December 2027.

What does the scan cost?

Nothing. There is no paid tier of the scan, no trial that expires, and no card required. It exists so that European software and hardware companies can find out where they stand before the first CRA deadline, and so that the ones who want help know we exist.

What do you do with my email address?

We send you the report you asked for. That is the only email you get unless you separately tick the marketing consent box, which is unticked by default. We store your address, the company name if you gave one, and your scan answers on EU infrastructure so we can answer follow-up questions. We never sell or share it. Email privacy@maditon.com and we delete everything we hold about you — usually within a few days, and in any case within the month the GDPR allows.

Do I have to be a manufacturer for this to matter?

No. Manufacturers carry the heaviest set of obligations, but importers and distributors have their own duties — broadly, checking that what they place on the market carries the right conformity marking and documentation, and acting when they learn a product is non-compliant. Open-source stewards have a lighter, separate regime again. The scan asks which role you play and tailors the result.