Cyber Resilience Act Maturity · Regulation (EU) 2024/2847 on cyber resilience for digital products
Your CRA requirements translated into maturity levels, documented gaps and a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
Cyber Resilience Act Maturity · Regulation (EU) 2024/2847 on cyber resilience for digital products
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One Regulation (EU) 2024/2847 (Cyber Resilience Act) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism (a level, the level above, and the action linking them) is what turns an observation into a trajectory.
Do you have an up to date software bill of materials (SBOM) for the products you place on the market?
- N1
No software bill of materials exists. A product’s third party components are known only to the developers who integrated them.
- N2
Component lists exist for some products, built manually, with no common format and no update at each release.
- N3
An SBOM is generated in a standard format for products in scope, updated with each published version and kept alongside the technical documentation.
- N4
The SBOM is produced automatically by the build chain, cross checked against vulnerability bulletins, and triggers a review when a component is affected.
- N5
The SBOM covers transitive dependencies and supplier components, with documented tracking of exceptions and periodic review of component acceptance rules.
Action to move from level 2 to level 3
Select a standard SBOM format, add it to the deliverable definition of each published version and check for its presence at release review, linking it to the product’s technical file.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Maja SucekChief Operating Officer, Interreg Danube

Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurement
What this framework covers
The Cyber Resilience Act, Regulation (EU) 2024/2847, applies to products with digital elements, hardware or software, made available on the Union market. It sets essential cybersecurity requirements for design, development and production, and vulnerability handling obligations throughout the support period. It requires a conformity assessment, technical documentation, an EU declaration of conformity and CE marking. It also creates notification obligations to ENISA for actively exploited vulnerabilities and severe incidents.
The difficulty is not reading the text, it is knowing who does what. The CRA engages R&D, product security, quality, legal and support, often in organisations where cybersecurity was designed around the information system rather than the product sold. Do you know the exact scope of your affected products and their classification? Can you produce an up to date software bill of materials for each of them? Who is committing today to the support period and to the distribution of security patches?
One confusion comes up regularly: the CRA is not a variant of NIS 2. NIS 2 covers the security of entities and their systems, the CRA covers the products a company places on the market. The same group can be subject to both, with different owners and different evidence. Another point of attention: the regulation applies on a staggered timetable, with notification obligations taking effect before the general obligations. Treating the subject as a simple CE marking file leads to discovering the deeper workstreams late, particularly coordinated vulnerability management.
A conformity audit concludes with a gap or a pass, product by product. The maturity assessment answers a different question: what level of control do your product security practices sit at, and what specific action moves you up to the next level. This is what allows a transformation programme to be steered across several product ranges and development teams, with a trajectory that reads clearly in a management committee rather than a checklist of requirements.
In Datamensio, the framework is ready to use and you can adapt it. The AI adjusts the themes, questions and levels to your product portfolio, or builds a version from your development procedures and existing technical files. It then reviews the answers, flags gaps that recur across ranges and drafts the reporting, while the decision stays yours: every proposed action can be kept, dismissed or rewritten before it enters the roadmap.
Reference standard: Regulation (EU) 2024/2847 (Cyber Resilience Act)
The themes assessed
Scope and product classification
Inventory of products with digital elements, role assumed (manufacturer, importer, distributor), classification against the regulation’s categories, identification of critical products.
Essential security by design requirements
Security considered from the design stage, secure default configuration, attack surface reduction, protection of data and communications, access control, logging.
Product risk analysis
Cybersecurity risk assessment per product, documentation of the analysis, updates as functionality evolves, consideration of intended use and reasonably foreseeable misuse.
Software bill of materials and supply chain
Production and updating of the SBOM, identification of third party and open source components, supplier assessment, traceability of dependencies and shipped versions.
Vulnerability management and coordinated disclosure
Reporting contact point, coordinated disclosure policy, handling timelines, security testing and reviews, tracking of unpatched vulnerabilities.
Security updates and support period
Determining and publishing the support period, patch distribution, separation of security patches from feature updates, end of support management.
Notification of exploited vulnerabilities and incidents
Detection and qualification, alerting procedures towards ENISA and national authorities, meeting deadlines, informing users, traceability of notifications.
Conformity assessment and technical documentation
Choice of assessment procedure, technical file, EU declaration of conformity, CE marking, involvement of a notified body where required, evidence retention.
User information
Security notice, installation and configuration instructions, communication of the support period, warnings and end of life information.
Governance and market surveillance
Split of responsibilities between R&D, security, quality and legal, product security skills, steering indicators, readiness for market surveillance authority requests.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Can the Cyber Resilience Act be certified?
Not in the sense of a voluntary ISO style certification. The regulation requires a conformity assessment, an EU declaration of conformity and CE marking, with a notified body involved for certain product categories. The Datamensio assessment measures the maturity of your practices and prepares this file, it does not issue any attestation.
What is the difference between this assessment and a CRA conformity audit?
The audit examines a product and concludes with a gap or a pass. The assessment places your practices on a maturity scale, theme by theme, and identifies the action that moves you to the next level. It is used to frame the programme ahead of the audit and to track its progress.
How long does the evaluation take?
The short version takes 20 to 30 minutes to complete for a product security manager. The full version, in collaborative mode, typically spans one to two weeks, most of the time spent gathering input from R&D, quality and support.
Can the framework be adapted to our product portfolio?
Yes. Questions, levels and themes can be modified, and you can add your own internal requirements. The AI produces a version per product family or business unit based on your development procedures.
How does this assessment relate to NIS 2 or ISO 27001?
NIS 2 and ISO 27001 cover the organisation and its systems, the CRA covers products placed on the market. Vulnerability management and risk analysis practices partly overlap. A cross cutting roadmap allows several assessments to be consolidated without duplicating actions.
Does answering require technical expertise?
The questions cover design, vulnerability management and documentation practices, not precise configurations. A product security manager or a quality manager can answer them, assigning engineering related questions to collaborative mode.
Can several product lines be compared with each other?
Yes. The same framework can be deployed across several business units or ranges, with benchmarking between entities and against previous evaluations. Gaps feed into a consolidated roadmap at group level.
Where is the data hosted?
In France, at OVH, with backup at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.





