The cybersecurity risk assessment under the CRA is a product-level assessment, not an organisational information security audit. Annex I, Part I covers 13 essential requirements — from protection against unauthorised access to data integrity to secure default settings. Part II adds 8 vulnerability handling requirements — from vulnerability identification to security updates to SBOM maintenance. CRACheck maps your product's characteristics against each requirement and generates a structured risk assessment document. €149 per product. 15–25 minutes. 100% browser-side.
€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side
ISO 27001 addresses organisational information security management — not product-level cybersecurity risk. Annex I of Regulation (EU) 2024/2847 requires assessing risks specific to the product's design, functionality, and intended use. An ISO 27001 certificate for your company does not satisfy the CRA's product-level risk assessment.
Part II is not operational — it defines essential requirements for how the product handles vulnerabilities throughout its lifecycle: from identification to remediation to update delivery. These requirements must be designed into the product, not bolted on after deployment.
Article 13(3) of Regulation (EU) 2024/2847 requires manufacturers to regularly review and update the cybersecurity risk assessment during the expected product lifetime or the support period (minimum 5 years per Art. 13(8)). The risk assessment is a living document.
8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.
Category under Annex III / IV.
Art. 31 + Annex VII. The risk assessment is a core component.
Primary deliverable. Structured assessment against each Annex I, Part I requirement and Part II requirement.
Annex II. Communicates residual risks to the user.
Art. 28 + Annex V.
Art. 13(6). Operationalises the vulnerability handling processes.
Art. 14. Art. 14(2): early warning within 24h, notification within 72h, final report within 14 days.
Includes risk assessment review milestones.
See before you buy — Download sample dossier (PDF, fictional company) — Real structure, real articles, real format. Fictional data.
Generated from your data, in your browser. No data leaves your device.
CRACheck generates a structured risk assessment mapping your product against every Annex I requirement. Integrated with the full 8-document CRA package.
CRACheck does not perform penetration testing, threat modelling workshops, architecture reviews, or code audits. It does not discover vulnerabilities in your product. The risk assessment documents what you declare about your product.
Documentation without testing is incomplete. Testing without documentation is undocumented. CRACheck handles the documentation layer.
For non-compliance with essential cybersecurity requirements under Art. 6 + Annex I.
For failing to document the risk assessment as part of the technical file under Art. 31.
For providing incomplete or misleading risk assessment information to authorities.
| Criterion | ISO 27001 risk register | Generic risk template | Security consultancy | CRACheck |
|---|---|---|---|---|
| CRA Annex I coverage | Organisational, not product | Partial | Full, but slow | Full (Part I + II) |
| CRA documentation integration | None | None | Separate deliverable | Integrated (8 docs) |
| Cost | Included in ISO audit (€10K+) | Free (template) | €5K–€20K | €149 |
| Time | Part of ISO cycle | 2–4 weeks | 4–10 weeks | 15–25 min |
| CRACheck | Full | Integrated | €149 | 15-25 min |
Each product needs its own Annex I risk assessment. Pack pricing: €99/product (10), €79/product (30).
Request volume pricingCRACheck generates a structured risk assessment document according to Annex I of Regulation (EU) 2024/2847 based on the information you enter. The accuracy of your threat declarations, mitigation measures, and residual risk statements is your responsibility as the manufacturer.
We guarantee that the document structure follows Annex I (Part I + Part II) and that the legal references cited are correct. We do not guarantee that the risk assessment will be accepted by a market surveillance authority in a specific inspection.
CRACheck is not legal advice. For complex risk scenarios, consult a specialised product security or regulatory consultancy.
CRACheck maps every Annex I requirement to your product and generates the full documentation set. €149 per product.