The free bench
Two instruments for the two CRA obligations with a clock on them — both run entirely in your browser.
The risk-assessment bench
Article 13(3) is a checklist disguised as a sentence. ART·13 walks it: the five elements the assessment must comprise, a method chosen against the CRACY criteria, assets and their containers, threats scored and treated, then the step almost everyone skips — each of the thirteen Annex I Part I(2) requirements decided, with a justification for every "not applicable". Out comes a printable draft assessment for Annex VII.
- 01 Product profile
- 02 Method choice
- 03 Assets & containers
- 04 Threats & treatment
- 05 Annex I applicability
- 06 Reassessment triggers
- 07 Draft assessment
- Two methods offered — the Four-Question Framework for the lightest credible run, OCTAVE Allegro when the artefacts have to survive external review.
- STRIDE prompts built in — CRACY requires any acceptable method to integrate with threat modelling.
- OT shortcut — containers map onto the zone-and-conduit model, threats onto IEC 62443-4-1 practices, so existing work is re-cut rather than repeated.
- Print or export — save as PDF, or take the JSON with you and re-import it later.
Your data stays with you. The assessment is autosaved to this browser's local storage and is never uploaded. Clearing it is one button. Method layer after CRACY (CRA Made Easy) deliverable D2.2, LSEC — co-funded by the EU Digital Europe Programme, grant No 101190492 · cra-cy.eu.
The reporting clock
From 11 September 2026, an actively exploited vulnerability or a severe incident starts a fixed clock: early warning in 24 hours, notification in 72, a final report at the end. 24·72 makes the triage call that starts it, runs every deadline, and drafts what each stage has to contain.
- 01 Trigger triage
- 02 24h early warning
- 03 72h notification
- 04 Final report
- 05 Submission log
- Both tracks — actively exploited vulnerability and severe incident, each with its own final-report deadline.
- One filing path — the CRA Single Reporting Platform (Art 16), reaching the CSIRT-coordinator and ENISA simultaneously.
- Drafts, not submissions — it shows what each report must say; it does not file anything.
Also browser-only. Events you log stay in the page. Facts verified against Regulation (EU) 2024/2847 Articles 14 and 16.
Read first
- The Risk AssessmentArticle 13 read literally, and the methodologies that satisfy it — the reference behind ART·13.Read →
- The CRA BriefScope, the obligation chain, deadlines, classification, Article 14, and the IEC 62443 bridge.Read →
- CRA for OT & ICS ManufacturersThe complete guide: scope, classification, the six-step obligation chain, and the IEC 62443 bridge.Read →
- CRA Deadlines & TimelineEvery application date from 10 Dec 2024 to 11 Dec 2027, and what each one obliges.Read →
- Annex VII ChecklistThe eight evidence areas every manufacturer's technical file must contain.Read →
The tools cover two obligations. The file covers all six.
ART·13 and 24·72 are free because they are narrow. The CRA Workbench runs the whole chain — classify, risk, gap, route, vulnerability programme, Annex VII technical file — with the auditor-judgment layer and the CRA ↔ IEC 62443-4-1 bridge for OT teams.
See the CRA Workbench →These tools produce draft documentation for expert review. They indicate what the regulation asks for; they do not engineer your product, file anything on your behalf, or by themselves establish compliance — reviewer sign-off is always required. Article and annex references are quoted from Regulation (EU) 2024/2847, but the CRA's harmonised-standards landscape is still settling: confirm against the current official text before relying on any point. Nothing here is legal advice.