Loading tools
Loading tools
Applies Regulation (EU) 2024/2847 — Recital (12) pure-SaaS scope test, Annex III/IV product classification, Annex I Part I essential requirements, Annex I Part II vulnerability handling & SBOM, Art. 13 support periods and Art. 14 incident reporting (enforcement 11 September 2026) — to produce a 0–100 conformity readiness score with a prioritized remediation roadmap.
Two gate questions decide whether Regulation (EU) 2024/2847 applies to your product — and which conformity route you face.
Do you place a product with digital elements (hardware, software product, SDK, mobile app, firmware, or the manufacturer-operated remote data processing backend it needs to function) on the EU market, for payment or free of charge?
Making available covers any supply for distribution, consumption or commercial use in the EU. Pure open-source software supplied outside commercial activity is excluded, but commercial FOSS or monetised products are covered.
Is your product excluded under Art. 2 (medical device under MDR/IVDR, vehicle type-approval, civil aviation safety, marine equipment, or national defence/security)? Select "No" if your product is NOT excluded.
Products regulated under Regulations (EU) 2017/745, 2017/746, 2019/2144, 2018/1139 or Directive 2014/90/EU are exempt from the CRA because sectoral laws govern their cybersecurity.
Answer Q01 and Q02 to determine scope.
A second pair of eyes before the expensive mistakes. Get in touch for a strategy call.