CRA Compliance

How do you run a Cyber Resilience Act gap analysis?

By CVD Portal
Last updated 2026-09-246 min read

A Cyber Resilience Act gap analysis compares one product against the Annex I essential requirements of Regulation (EU) 2024/2847 and lists each requirement that still needs evidence in the technical documentation.

Key takeaways

  • A CRA gap analysis covers one product, because Annex I, Annex VII and the EU Declaration of Conformity each apply to a specific product.
  • Scope and classification come first, because the product class decides the conformity assessment route under Article 32.
  • Part I(1) and all of Part II of Annex I apply to every product, and each Part I(2) requirement needs an implementation reference or a written justification.
  • A gap list computed before existing evidence is mapped counts documents that the company already holds.
  • A maturity score measures the organisation and a gap analysis measures one product, so each one answers a different question.

When should a manufacturer run a CRA gap analysis?

Run the gap analysis after scope and classification. Scope decides which products the regulation covers. Classification decides the conformity assessment route under Article 32, and that route decides who assesses the evidence.

Starting with Annex I puts effort into products whose route is still unknown. The CRA for manufacturers guide sets out eight stages in dependency order. The gap analysis is stage four, after scope, classification and the risk assessment.

Check scope on the CRA scope page. Classify each product with the free classification tool. The four product classes page explains each result.

What does a CRA gap analysis check?

A CRA gap analysis checks each Annex I requirement against the evidence for one product. Annex I has two parts. Part I covers the properties of the product. Part II covers vulnerability handling.

GroupAnnex I referenceEntriesHow it applies
Security level based on riskPart I(1)1Always applies
Product propertiesPart I(2), points (a) to (m)13Applies where the risk assessment finds it applicable
Vulnerability handlingPart II, points (1) to (8)8Always applies

That gives 22 entries per product. Part I(1) reads "Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks."

The Part I(2) requirements apply on the basis of the cybersecurity risk assessment in Article 13(2). Under Article 13(3), the manufacturer states which of them apply. An applicable requirement needs an implementation reference. A requirement that the risk assessment excludes needs a written justification. The page on Article 13 covers both steps.

Each entry ends in one of three states.

  • Met. Evidence in the technical documentation demonstrates the requirement.
  • Not applicable. A justification that refers to the risk assessment explains the decision. Only Part I(2) entries can take this state.
  • Open. The entry has no evidence, or no justification. Each open entry is a gap.

Why map existing evidence before listing gaps?

Map existing evidence first. Much of the evidence usually exists already. Architecture diagrams, test reports, release notes, user manuals and threat models sit in the engineering organisation before CRA work starts.

A gap list computed before the mapping step shows almost every entry as open. The team then writes new documents to replace documents it already owns. Your CRA technical file is mostly written already explains the mapping step in detail.

Record partial coverage as partial. A penetration test of the network interfaces covers part of a security testing requirement and leaves the physical interfaces open. An entry marked as met on partial evidence is a false statement in the technical file.

How is a gap analysis different from a maturity assessment?

A maturity assessment scores how the organisation works. A gap analysis checks whether one product has evidence behind each Annex I requirement.

QuestionMaturity assessmentCRA gap analysis
Unit of assessmentThe organisationOne product
ReferenceENISA SME Cyber Resilience Maturity Assessment ModelAnnex I of Regulation (EU) 2024/2847
OutputA score per domain and an improvement checklistA list of open entries with the evidence each one needs
Best useSequence the work and estimate the effort per productBuild the technical file before the EU Declaration of Conformity

ENISA states that an advanced maturity level "does not replace legal obligations and should not be considered evidence of compliance". An organisation with a high score can still ship a product with open entries. A small team with a low score can still ship a conforming product.

The free CRA maturity assessment rates 25 practices across five domains on a five-level scale from Initial to Optimised. The tool runs in the browser and stores nothing on our servers. What a CRA maturity score actually predicts explains how to read the result.

What does a finished gap analysis produce?

A finished gap analysis produces a status for each of the 22 entries of one product. Each met entry carries its evidence. Each not-applicable entry carries its justification.

That record feeds two documents. The Annex VII technical documentation carries the risk assessment and the Annex I positions. The EU Declaration of Conformity states that the product meets the essential requirements. The post on CRA technical documentation evidence requirements lists what the file must contain.

Keep the record current. A product change can reopen an entry that was met, so run the gap analysis again for each release.

How does CVD Portal report the gaps?

The CVD Portal conformity gap engine reads the recorded state of each active product and reports each open item. It checks four areas.

  1. Classification. A product with no recorded classification returns a gap that points to the Article 32 conformity assessment route.
  2. Technical file readiness. A missing SBOM, missing product context, an empty risk register, or a missing notified body record where the route needs one, each return a gap.
  3. Annex I. Each applicable entry with no evidence or no sign-off returns a gap. The acceptance rules of the active clause mapping decide the result.
  4. Company obligations. When the request names no product, the engine also reports obligations that some active products do not yet cover.

Each gap carries the reference, the status and the action that closes it. The engine is available through the REST API at /api/v1/compliance/gaps and through the MCP tool get_conformity_gaps. The engine proposes. A person at the manufacturer confirms each evidence mapping and signs off each entry.

Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.

What is the next step?

Start with the product that has the earliest obligation. Article 14 reporting has applied since 11 September 2026. The CRA applies in full from 11 December 2027.

Sources

Regulation (EU) 2024/2847 has the CELEX identifier 32024R2847.

Frequently asked questions

What is a CRA gap analysis?

A CRA gap analysis compares one product with digital elements against the Annex I essential requirements of Regulation (EU) 2024/2847. It lists each requirement that still needs evidence or a written justification in the technical documentation.

When should a manufacturer run a CRA gap analysis?

After scope and classification. Classification decides the conformity assessment route under Article 32, and that route decides who assesses the evidence. Existing engineering evidence is mapped to each requirement before the gap list is computed.

Is a CRA maturity score the same as a gap analysis?

No. A maturity score measures how consistently the organisation works across 25 practices in five domains. A gap analysis checks whether one product has evidence behind each Annex I requirement. ENISA states that an advanced maturity level does not replace legal obligations.

Stay compliant with the Cyber Resilience Act

Check your readiness with the CRA Readiness Checklist, or compare plans on pricing.

Create my free CVD portalCreate your free CVD portal

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.