EDIH, EEN, Interreg: the platform for European programmes.Find out more

Cyber Resilience Act Maturity · Regulation (EU) 2024/2847 on cyber resilience for digital products

Your CRA requirements translated into maturity levels, documented gaps and a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Cyber Resilience Act Maturity · Regulation (EU) 2024/2847 on cyber resilience for digital products

Scope and product classificationN1 → N5
Essential security by design requirementsN1 → N5
Product risk analysisN1 → N5
Software bill of materials and supply chainN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Scope and product classification6484
Essential security by design requirements5379
Product risk analysis6182
Software bill of materials and supply chain3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • Cetim
  • Aerospace Valley
  • Pôle SCS
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Regulation (EU) 2024/2847 (Cyber Resilience Act) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism (a level, the level above, and the action linking them) is what turns an observation into a trajectory.

Do you have an up to date software bill of materials (SBOM) for the products you place on the market?

  1. N1

    No software bill of materials exists. A product’s third party components are known only to the developers who integrated them.

  2. N2

    Component lists exist for some products, built manually, with no common format and no update at each release.

  3. N3

    An SBOM is generated in a standard format for products in scope, updated with each published version and kept alongside the technical documentation.

  4. N4

    The SBOM is produced automatically by the build chain, cross checked against vulnerability bulletins, and triggers a review when a component is affected.

  5. N5

    The SBOM covers transitive dependencies and supplier components, with documented tracking of exceptions and periodic review of component acceptance rules.

Action to move from level 2 to level 3

Select a standard SBOM format, add it to the deliverable definition of each published version and check for its presence at release review, linking it to the product’s technical file.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France

Chambre de commerce et d'industrie
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube

Interreg Danube Region

Take your first measurement

What this framework covers

The Cyber Resilience Act, Regulation (EU) 2024/2847, applies to products with digital elements, hardware or software, made available on the Union market. It sets essential cybersecurity requirements for design, development and production, and vulnerability handling obligations throughout the support period. It requires a conformity assessment, technical documentation, an EU declaration of conformity and CE marking. It also creates notification obligations to ENISA for actively exploited vulnerabilities and severe incidents.

The difficulty is not reading the text, it is knowing who does what. The CRA engages R&D, product security, quality, legal and support, often in organisations where cybersecurity was designed around the information system rather than the product sold. Do you know the exact scope of your affected products and their classification? Can you produce an up to date software bill of materials for each of them? Who is committing today to the support period and to the distribution of security patches?

One confusion comes up regularly: the CRA is not a variant of NIS 2. NIS 2 covers the security of entities and their systems, the CRA covers the products a company places on the market. The same group can be subject to both, with different owners and different evidence. Another point of attention: the regulation applies on a staggered timetable, with notification obligations taking effect before the general obligations. Treating the subject as a simple CE marking file leads to discovering the deeper workstreams late, particularly coordinated vulnerability management.

A conformity audit concludes with a gap or a pass, product by product. The maturity assessment answers a different question: what level of control do your product security practices sit at, and what specific action moves you up to the next level. This is what allows a transformation programme to be steered across several product ranges and development teams, with a trajectory that reads clearly in a management committee rather than a checklist of requirements.

In Datamensio, the framework is ready to use and you can adapt it. The AI adjusts the themes, questions and levels to your product portfolio, or builds a version from your development procedures and existing technical files. It then reviews the answers, flags gaps that recur across ranges and drafts the reporting, while the decision stays yours: every proposed action can be kept, dismissed or rewritten before it enters the roadmap.

Reference standard: Regulation (EU) 2024/2847 (Cyber Resilience Act)

The themes assessed

  • Scope and product classification

    Inventory of products with digital elements, role assumed (manufacturer, importer, distributor), classification against the regulation’s categories, identification of critical products.

  • Essential security by design requirements

    Security considered from the design stage, secure default configuration, attack surface reduction, protection of data and communications, access control, logging.

  • Product risk analysis

    Cybersecurity risk assessment per product, documentation of the analysis, updates as functionality evolves, consideration of intended use and reasonably foreseeable misuse.

  • Software bill of materials and supply chain

    Production and updating of the SBOM, identification of third party and open source components, supplier assessment, traceability of dependencies and shipped versions.

  • Vulnerability management and coordinated disclosure

    Reporting contact point, coordinated disclosure policy, handling timelines, security testing and reviews, tracking of unpatched vulnerabilities.

  • Security updates and support period

    Determining and publishing the support period, patch distribution, separation of security patches from feature updates, end of support management.

  • Notification of exploited vulnerabilities and incidents

    Detection and qualification, alerting procedures towards ENISA and national authorities, meeting deadlines, informing users, traceability of notifications.

  • Conformity assessment and technical documentation

    Choice of assessment procedure, technical file, EU declaration of conformity, CE marking, involvement of a notified body where required, evidence retention.

  • User information

    Security notice, installation and configuration instructions, communication of the support period, warnings and end of life information.

  • Governance and market surveillance

    Split of responsibilities between R&D, security, quality and legal, product security skills, steering indicators, readiness for market surveillance authority requests.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Can the Cyber Resilience Act be certified?

Not in the sense of a voluntary ISO style certification. The regulation requires a conformity assessment, an EU declaration of conformity and CE marking, with a notified body involved for certain product categories. The Datamensio assessment measures the maturity of your practices and prepares this file, it does not issue any attestation.

What is the difference between this assessment and a CRA conformity audit?

The audit examines a product and concludes with a gap or a pass. The assessment places your practices on a maturity scale, theme by theme, and identifies the action that moves you to the next level. It is used to frame the programme ahead of the audit and to track its progress.

How long does the evaluation take?

The short version takes 20 to 30 minutes to complete for a product security manager. The full version, in collaborative mode, typically spans one to two weeks, most of the time spent gathering input from R&D, quality and support.

Can the framework be adapted to our product portfolio?

Yes. Questions, levels and themes can be modified, and you can add your own internal requirements. The AI produces a version per product family or business unit based on your development procedures.

How does this assessment relate to NIS 2 or ISO 27001?

NIS 2 and ISO 27001 cover the organisation and its systems, the CRA covers products placed on the market. Vulnerability management and risk analysis practices partly overlap. A cross cutting roadmap allows several assessments to be consolidated without duplicating actions.

Does answering require technical expertise?

The questions cover design, vulnerability management and documentation practices, not precise configurations. A product security manager or a quality manager can answer them, assigning engineering related questions to collaborative mode.

Can several product lines be compared with each other?

Yes. The same framework can be deployed across several business units or ranges, with benchmarking between entities and against previous evaluations. Gaps feed into a consolidated roadmap at group level.

Where is the data hosted?

In France, at OVH, with backup at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurement