A maturity assessment produces a number, and a number invites a verdict. Teams that score 4.1 tend to read it as clearance. Teams that score 2.3 read it as a warning that they are behind on the Cyber Resilience Act. Both readings assume the score measures the same thing the CRA measures, and it does not.
The model behind the score comes from ENISA. On 13 July 2026 the European Union Agency for Cybersecurity published the SME Cyber Resilience Maturity Assessment Model, a free document with a downloadable Excel workbook, aimed at micro, small and medium-sized enterprises that make products with digital elements. It is the EU cybersecurity agency's own answer to the question SMEs kept asking after its earlier survey work on CRA readiness, which is where to start when the regulation is large and the team is four people. We rebuilt the questionnaire as a browser tool so you can work through it without a spreadsheet, and ENISA remains the author of the model itself.
That model asks 25 questions across five domains, each answered on a five-level ladder from Initial to Optimised. The questions are about how your organisation works. Do policies exist and are they applied. Are roles assigned. Are risk assessments used to make decisions rather than filed after them. Are updates tested before delivery. Every question is scoped to the organisation and its habits.
CRA conformity is scoped to a product. Article 13(2) requires a cybersecurity risk assessment of that product. Annex I requires the essential requirements to be met by that product or justified away for it. Annex VII requires technical documentation describing that product. The Declaration of Conformity names that product and carries a manufacturer's signature under it. None of those obligations reference organisational maturity, and no market surveillance authority will accept a maturity band in place of a technical file.
ENISA says this in the document itself. An advanced maturity level, in its words, "does not replace legal obligations and should not be considered evidence of compliance". The improvement actions in its Annex carry the same warning, that following them does not guarantee compliance. The agency built a diagnostic and labelled it as one.
So the score does not answer the conformity question. It answers a different one that is worth asking anyway.
The two failures that prove they are separate
Consider an organisation that scores Advanced. Policies are approved and reviewed. Security testing is automated and risk-based. The vulnerability handling process is documented and rehearsed. Then it ships a product built four years ago on a supplier stack nobody has touched since, with no per-product risk assessment on file, no SBOM, and a support period that was never declared. Every organisational answer was truthful. The product still fails Annex I and Annex VII, because conformity is per product and nobody did the per-product work.
Now consider the reverse. A three-person team scores 2.1. There is one product. The founder wrote the risk assessment personally, worked through the Annex I requirements one at a time, published a disclosure contact, and drafted the technical documentation. The maturity score is accurate, because nothing about that work is repeatable and none of it is written down as process. The product can still be conforming.
The second case is more common among SMEs than the industry admits, and it is why a low band should not read as a compliance emergency. It reads as a cost forecast.
The score is a per-product cost estimate
Here is the useful reading. Your maturity level predicts how much each additional product costs you in compliance effort, and how much the first one cost.
At Level 2, everything is done once, by hand, by whoever is available. The risk assessment for product two starts from nothing, because the assessment for product one lives in someone's drafts folder and its method was never described. Cost scales linearly with the portfolio, and it scales again every time the product changes enough to count as a substantial modification.
At Level 4, the method exists, the roles are assigned, and the documentation has a shape that the second product inherits. The first product was expensive. The eleventh is cheap.
That is the whole practical value of the ladder. It is not a grade. It tells you whether you are about to pay full price 12 times.
For a manufacturer with one product, low maturity is survivable and possibly rational. For a manufacturer with a catalogue, low maturity is the thing that makes CRA compliance feel impossible, and no amount of effort on any single product fixes it.
The wall between Level 3 and Level 4
Read the model's own wording carefully and a pattern shows up in almost every question. Level 3 says documented. Level 4 says consistently applied.
Question 1.1 puts it plainly. Level 3 is documented policies that are not formally approved or consistently used. Level 4 is policies formally approved, documented and generally applied. Question 2.1 does the same for risk assessments, where Level 3 is documented but not consistently used and Level 4 is systematically performed and guiding decisions.
Most SMEs that have done any CRA preparation land on this line and stop. They have written things. The writing has not changed what anyone does on a Tuesday. This is the single most common shape of a stalled compliance programme, and the assessment surfaces it as a cluster of 3s rather than a cluster of 2s, which is easy to mistake for progress.
Moving from 3 to 4 in any domain is an organisational change, not a documentation exercise. Someone has to own the process, and someone has to notice when it is skipped.
Vulnerability and patch management moves first
The five domains are not equally urgent, and ENISA agrees. Its improvement guidance ranks gaps by risk rather than by score, and the examples it gives of a high-risk gap are untracked vulnerabilities, a missing incident response process and unclear regulatory responsibilities. Two of those three sit in one domain, and that domain is the only one with a date attached to it.
Article 14 reporting applies from 11 September 2026. From that date, an actively exploited vulnerability in a product with digital elements triggers an early warning within 24 hours and a vulnerability notification within 72 hours, filed to ENISA and the relevant CSIRT. There is no clause that adjusts the clock for organisational maturity, no exemption for small manufacturers, and no grace period for a company that has not decided who is on call.
Domain 3 covers exactly the capabilities that clock depends on. A way to receive, acknowledge, record and track a report (3.1). A process for creating, testing and delivering updates (3.2). An SBOM you actually use for dependency triage (3.3). Risk-based prioritisation (3.4). Verification that the fix worked, with evidence retained (3.5).
If your Domain 3 average is below 3 and September 2026 is in front of you, that domain outranks everything else the assessment tells you, including domains where your score is worse. A Governance score of 1.8 costs you time. A Vulnerability Handling score of 1.8 costs you a missed statutory deadline the first time a researcher emails you about something already being exploited.
Why the tooling stops at Level 4
In our assessment, each question is tagged with whether the platform supports it and to what level. The support level is capped at 4 deliberately, and four questions in Domain 5 carry no platform tag at all.
Level 5 across this model is measurement and continuous improvement. Reviews that are measured, tracked and improved. Testing that is monitored. A culture of open reporting. Software can hold the process, hold the evidence, and show you the gaps. It cannot make anyone look at the result, and a product that claims otherwise is selling you a dashboard nobody opens.
The four unmapped questions are Domain 5's skills and culture items, 5.1, 5.2, 5.3 and 5.5. Whether your developers know how to build securely, whether they are trained, whether people feel able to report problems, and whether you validate competence, are things no vendor can supply. We would rather mark them uncovered than let a green tick imply otherwise. The one Domain 5 question tooling does help with is 5.4, following external advisories and alerts, which is a feed problem.
How to use the output
Take the three lowest-scoring questions, ignore the domain averages for a moment, and ask what specifically would move each one up a single level. Not to 5, one level. The model's level descriptions are written so that the next rung is a concrete change, usually the difference between a thing existing and a thing being used.
Then check Domain 3 against the September 2026 date regardless of where it ranks.
Then re-run the assessment in six months rather than six weeks. Nothing in this model moves fast, and a score that changes month to month is measuring your mood.
The free assessment runs entirely in your browser and stores nothing on our servers. It is ENISA's 25 questions, scored ENISA's way, with each question additionally tagged to show whether tooling can help and to what level. If you would rather work in the original, ENISA publishes the model and its Excel workbook for free.
If you want to know where a specific product stands rather than where your organisation does, that is a different exercise, and it starts with classification and a per-product risk assessment.
The SME Cyber Resilience Maturity Assessment Model was published by ENISA, the European Union Agency for Cybersecurity, on 13 July 2026. Our browser version is an independent implementation and is not affiliated with or endorsed by ENISA.