The cybersecurity risk assessment under the CRA is a product-level assessment, not an organisational information security audit. Annex I, Part I covers 13 essential requirements — from protection against unauthorised access to data integrity to secure default settings. Part II adds 8 vulnerability handling requirements — from vulnerability identification to security updates to SBOM maintenance. CRACheck maps your product's characteristics against each requirement and generates a structured risk assessment document. €149 per product. 15–25 minutes. 100% browser-side.
€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side
ISO 27001 addresses organisational information security management — not product-level cybersecurity risk. Annex I of Regulation (EU) 2024/2847 requires assessing risks specific to the product's design, functionality, and intended use. An ISO 27001 certificate for your company does not satisfy the CRA's product-level risk assessment.
Part II is not operational — it defines essential requirements for how the product handles vulnerabilities throughout its lifecycle: from identification to remediation to update delivery. These requirements must be designed into the product, not bolted on after deployment.
Article 13(3) of Regulation (EU) 2024/2847 requires manufacturers to regularly review and update the cybersecurity risk assessment during the expected product lifetime or the support period (minimum 5 years per Art. 13(8)). The risk assessment is a living document.
8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.
Category under Annex III / IV.
Art. 31 + Annex VII. The risk assessment is a core component.
Primary deliverable. Structured assessment against each Annex I, Part I requirement and Part II requirement.
Annex II. Communicates residual risks to the user.
Art. 28 + Annex V.
Art. 13(6). Operationalises the vulnerability handling processes.
Art. 14. Art. 14(2): early warning within 24h, notification within 72h, final report within 14 days.
Includes risk assessment review milestones.
See before you buy — Download sample dossier (PDF, fictional company) — Real structure, real articles, real format. Fictional data.
Generated from your data, in your browser. No data leaves your device.