EU CRA ComplianceCRA compliance software See the CRA Workbench →

Free toolsNo signupNothing uploaded

The free bench

Two instruments for the two CRA obligations with a clock on them — both run entirely in your browser.

ART·13
Free
Article 13 · risk assessment

The risk-assessment bench

Article 13(3) is a checklist disguised as a sentence. ART·13 walks it: the five elements the assessment must comprise, a method chosen against the CRACY criteria, assets and their containers, threats scored and treated, then the step almost everyone skips — each of the thirteen Annex I Part I(2) requirements decided, with a justification for every "not applicable". Out comes a printable draft assessment for Annex VII.

  1. 01 Product profile
  2. 02 Method choice
  3. 03 Assets & containers
  4. 04 Threats & treatment
  5. 05 Annex I applicability
  6. 06 Reassessment triggers
  7. 07 Draft assessment
  • Two methods offered — the Four-Question Framework for the lightest credible run, OCTAVE Allegro when the artefacts have to survive external review.
  • STRIDE prompts built in — CRACY requires any acceptable method to integrate with threat modelling.
  • OT shortcut — containers map onto the zone-and-conduit model, threats onto IEC 62443-4-1 practices, so existing work is re-cut rather than repeated.
  • Print or export — save as PDF, or take the JSON with you and re-import it later.

Your data stays with you. The assessment is autosaved to this browser's local storage and is never uploaded. Clearing it is one button. Method layer after CRACY (CRA Made Easy) deliverable D2.2, LSEC — co-funded by the EU Digital Europe Programme, grant No 101190492 · cra-cy.eu.

24·72
Free
Article 14 · reporting

The reporting clock

From 11 September 2026, an actively exploited vulnerability or a severe incident starts a fixed clock: early warning in 24 hours, notification in 72, a final report at the end. 24·72 makes the triage call that starts it, runs every deadline, and drafts what each stage has to contain.

  1. 01 Trigger triage
  2. 02 24h early warning
  3. 03 72h notification
  4. 04 Final report
  5. 05 Submission log
  • Both tracks — actively exploited vulnerability and severe incident, each with its own final-report deadline.
  • One filing path — the CRA Single Reporting Platform (Art 16), reaching the CSIRT-coordinator and ENISA simultaneously.
  • Drafts, not submissions — it shows what each report must say; it does not file anything.

Also browser-only. Events you log stay in the page. Facts verified against Regulation (EU) 2024/2847 Articles 14 and 16.

Read first

The tools cover two obligations. The file covers all six.

ART·13 and 24·72 are free because they are narrow. The CRA Workbench runs the whole chain — classify, risk, gap, route, vulnerability programme, Annex VII technical file — with the auditor-judgment layer and the CRA ↔ IEC 62443-4-1 bridge for OT teams.

See the CRA Workbench →

These tools produce draft documentation for expert review. They indicate what the regulation asks for; they do not engineer your product, file anything on your behalf, or by themselves establish compliance — reviewer sign-off is always required. Article and annex references are quoted from Regulation (EU) 2024/2847, but the CRA's harmonised-standards landscape is still settling: confirm against the current official text before relying on any point. Nothing here is legal advice.