A Cyber Resilience Act gap analysis compares one product against the Annex I essential requirements of Regulation (EU) 2024/2847 and lists each requirement that still needs evidence in the technical documentation.
Key takeaways
- A CRA gap analysis covers one product, because Annex I, Annex VII and the EU Declaration of Conformity each apply to a specific product.
- Scope and classification come first, because the product class decides the conformity assessment route under Article 32.
- Part I(1) and all of Part II of Annex I apply to every product, and each Part I(2) requirement needs an implementation reference or a written justification.
- A gap list computed before existing evidence is mapped counts documents that the company already holds.
- A maturity score measures the organisation and a gap analysis measures one product, so each one answers a different question.
When should a manufacturer run a CRA gap analysis?
Run the gap analysis after scope and classification. Scope decides which products the regulation covers. Classification decides the conformity assessment route under Article 32, and that route decides who assesses the evidence.
Starting with Annex I puts effort into products whose route is still unknown. The CRA for manufacturers guide sets out eight stages in dependency order. The gap analysis is stage four, after scope, classification and the risk assessment.
Check scope on the CRA scope page. Classify each product with the free classification tool. The four product classes page explains each result.
What does a CRA gap analysis check?
A CRA gap analysis checks each Annex I requirement against the evidence for one product. Annex I has two parts. Part I covers the properties of the product. Part II covers vulnerability handling.
| Group | Annex I reference | Entries | How it applies |
|---|---|---|---|
| Security level based on risk | Part I(1) | 1 | Always applies |
| Product properties | Part I(2), points (a) to (m) | 13 | Applies where the risk assessment finds it applicable |
| Vulnerability handling | Part II, points (1) to (8) | 8 | Always applies |
That gives 22 entries per product. Part I(1) reads "Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks."
The Part I(2) requirements apply on the basis of the cybersecurity risk assessment in Article 13(2). Under Article 13(3), the manufacturer states which of them apply. An applicable requirement needs an implementation reference. A requirement that the risk assessment excludes needs a written justification. The page on Article 13 covers both steps.
Each entry ends in one of three states.
- Met. Evidence in the technical documentation demonstrates the requirement.
- Not applicable. A justification that refers to the risk assessment explains the decision. Only Part I(2) entries can take this state.
- Open. The entry has no evidence, or no justification. Each open entry is a gap.
Why map existing evidence before listing gaps?
Map existing evidence first. Much of the evidence usually exists already. Architecture diagrams, test reports, release notes, user manuals and threat models sit in the engineering organisation before CRA work starts.
A gap list computed before the mapping step shows almost every entry as open. The team then writes new documents to replace documents it already owns. Your CRA technical file is mostly written already explains the mapping step in detail.
Record partial coverage as partial. A penetration test of the network interfaces covers part of a security testing requirement and leaves the physical interfaces open. An entry marked as met on partial evidence is a false statement in the technical file.
How is a gap analysis different from a maturity assessment?
A maturity assessment scores how the organisation works. A gap analysis checks whether one product has evidence behind each Annex I requirement.
| Question | Maturity assessment | CRA gap analysis |
|---|---|---|
| Unit of assessment | The organisation | One product |
| Reference | ENISA SME Cyber Resilience Maturity Assessment Model | Annex I of Regulation (EU) 2024/2847 |
| Output | A score per domain and an improvement checklist | A list of open entries with the evidence each one needs |
| Best use | Sequence the work and estimate the effort per product | Build the technical file before the EU Declaration of Conformity |
ENISA states that an advanced maturity level "does not replace legal obligations and should not be considered evidence of compliance". An organisation with a high score can still ship a product with open entries. A small team with a low score can still ship a conforming product.
The free CRA maturity assessment rates 25 practices across five domains on a five-level scale from Initial to Optimised. The tool runs in the browser and stores nothing on our servers. What a CRA maturity score actually predicts explains how to read the result.
What does a finished gap analysis produce?
A finished gap analysis produces a status for each of the 22 entries of one product. Each met entry carries its evidence. Each not-applicable entry carries its justification.
That record feeds two documents. The Annex VII technical documentation carries the risk assessment and the Annex I positions. The EU Declaration of Conformity states that the product meets the essential requirements. The post on CRA technical documentation evidence requirements lists what the file must contain.
Keep the record current. A product change can reopen an entry that was met, so run the gap analysis again for each release.
How does CVD Portal report the gaps?
The CVD Portal conformity gap engine reads the recorded state of each active product and reports each open item. It checks four areas.
- Classification. A product with no recorded classification returns a gap that points to the Article 32 conformity assessment route.
- Technical file readiness. A missing SBOM, missing product context, an empty risk register, or a missing notified body record where the route needs one, each return a gap.
- Annex I. Each applicable entry with no evidence or no sign-off returns a gap. The acceptance rules of the active clause mapping decide the result.
- Company obligations. When the request names no product, the engine also reports obligations that some active products do not yet cover.
Each gap carries the reference, the status and the action that closes it. The engine is available through the REST API at /api/v1/compliance/gaps and through the MCP tool get_conformity_gaps. The engine proposes. A person at the manufacturer confirms each evidence mapping and signs off each entry.
Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.
What is the next step?
Start with the product that has the earliest obligation. Article 14 reporting has applied since 11 September 2026. The CRA applies in full from 11 December 2027.
- Classify the product with the free classification tool.
- Score the organisation with the free CRA maturity assessment.
- Work through the CRA readiness checklist for one product.
- Start a Compliance trial from the pricing page to run the gap engine on your own products.
Sources
Regulation (EU) 2024/2847 has the CELEX identifier 32024R2847.
Frequently asked questions
What is a CRA gap analysis?
A CRA gap analysis compares one product with digital elements against the Annex I essential requirements of Regulation (EU) 2024/2847. It lists each requirement that still needs evidence or a written justification in the technical documentation.
When should a manufacturer run a CRA gap analysis?
After scope and classification. Classification decides the conformity assessment route under Article 32, and that route decides who assesses the evidence. Existing engineering evidence is mapped to each requirement before the gap list is computed.
Is a CRA maturity score the same as a gap analysis?
No. A maturity score measures how consistently the organisation works across 25 practices in five domains. A gap analysis checks whether one product has evidence behind each Annex I requirement. ENISA states that an advanced maturity level does not replace legal obligations.