The Cyber Resilience Act (CRA) is becoming increasingly relevant and concrete for many companies: Does the CRA apply to my product? Which requirements do I need to meet? Which processes are already covered – and where are gaps?
The OCCTET CRA Self-Assessment Platform is designed to help answer these questions. The updated version has been validated and is now live in production. OCCTET (Open Source Compliance: Comprehensive Techniques and Essential Tools) is an EU-funded project that supports small and medium-sized enterprises in implementing the requirements of the CRA.
The platform helps small and medium-sized enterprises prepare their products for the Cyber Resilience Act and identify concrete first steps towards compliance.
Why now?
Action is required: The CRA reporting obligations for actively exploited vulnerabilities and severe security incidents have been in effect since 11 September 2026. The CRA will become fully applicable on 11 December 2027.
From CRA Check to a Concrete Gap Analysis
A central component of the platform is the CRA Requirements Journey. It guides users through the key questions surrounding the applicability of the CRA and helps them systematically assess their current status.
This includes questions such as:
- Does the product fall within the scope of the CRA at all?
- Which existing security, development, and compliance processes are already relevant?
- What role does the company have in relation to the product?
- Which risk category is relevant for the product?
- Which conformity assessment procedure applies?
At the end, the result is more than just a list of answered questions. The findings are consolidated in a gap analysis.
The analysis covers various areas, including secure software development lifecycle, protection against unauthorized access, confidentiality, integrity, resilience, network security, logging and detection, vulnerability management, as well as risk management and governance.
The individual categories are assessed and brought together into a clear overall picture. A score of 4 indicates good coverage of the respective category with regard to the CRA requirements. This makes it easy to identify at a glance which areas are already well covered and where further action is still needed.

What Concrete Benefits Does the Platform Offer Companies?
The Self-Assessment Platform helps companies translate CRA requirements into concrete next steps.
The results include, among other things:
- a written assessment of the applicability of the CRA,
- a recommendation on the extent to which the CRA applies to the product,
- the identification of the relevant sets of requirements,
- an assessment of the appropriate conformity assessment procedure – for example, self-assessment or external certification,
- as well as a gap analysis report providing a structured overview of the current situation.
The platform does not cover the entire implementation of the Cyber Resilience Act. Instead, it provides initial guidance by helping companies answer key questions: Where do we stand? Which requirements apply to us? And where do we need to take action? The self-assessment provides a starting point for further analysis and highlights areas that require a closer look.
This is where the OCCTET toolchain comes in. Implementing the CRA requires more than simply checking off requirements in a questionnaire. In particular, companies need to examine the licenses, vulnerabilities, and dependencies of software with numerous open-source components in detail.
The ORT Server and the OCCTET Curator support this analysis and the subsequent manual review, while the federated VulnerableCode database provides additional information on known vulnerabilities. Companies can then further process the results in formats such as SPDX or CycloneDX SBOMs and VEX statements.
The added value of OCCTET lies in aligning regulatory requirements with the actual technical composition of a software product. The self-assessment shows where action is needed, while the toolchain identifies what lies behind those areas and which information companies need for further assessment and documentation.
This creates a direct link between CRA requirements and concrete open-source components, software dependencies, SBOMs, and vulnerability management.
More Content and Tools
With the latest release, the team has added the new CRA Requirements Journey and expanded the Cybersecurity Tools Catalogue.
The platform now also offers the option to use Oxy to search the catalogue for suitable tools with AI support. The AI-supported search makes it easier to find suitable tools for specific requirements or questions.
The team has also updated the platform’s content and made it available in English, German, and French.
Try It Yourself
The updated OCCTET CRA Self-Assessment Platform is now publicly available.
Anyone working with the Cyber Resilience Act and looking to gain an initial understanding of which requirements may be relevant to their product can try the platform directly:
OCCTET CRA Self-Assessment Platform:
cra.occtet.eu
The OCCTET project developed the platform to help small and medium-sized enterprises (SMEs) implement the requirements of the Cyber Resilience Act.
Next Post
