The Cyber Resilience Act (CRA) is the European Union regulation that introduces cybersecurity requirements for products with digital elements, both hardware and software. On 13 July 2026 the European Union Agency for Cybersecurity (ENISA) published a maturity self-assessment model designed for small and medium-sized enterprises (SMEs). This briefing gathers the content of the model, the data from the accompanying survey and the regulation’s application timeline.
What the Cyber Resilience Act requires
The Cyber Resilience Act, adopted as Regulation (EU) 2024/2847, applies to products with digital elements placed on the Union market, from connected devices to software programs. According to the European Commission, the regulation introduces mandatory cybersecurity requirements for manufacturers, covering the planning, design, development and maintenance of products across the entire value chain, and requires them to handle vulnerabilities throughout the product lifecycle. Some products considered of particular relevance for cybersecurity will have to undergo a conformity assessment by a notified body before being sold. Compliant products will bear the CE marking, and national market surveillance authorities will ensure enforcement. The regulation entered into force on 10 December 2024; its main obligations will apply from 11 December 2027, while the reporting obligations will apply from 11 September 2026. The CRA sits within the framework of the Union’s cybersecurity strategy and complements the NIS2 Directive.
The ENISA self-assessment model for SMEs
The model published by ENISA, the SME Cyber Resilience Maturity Assessment Model, is part of the European Commission’s SME cybersecurity strategy. It is practical guidance that allows small and medium-sized enterprises to assess their current status, identify areas for improvement and strengthen their cyber resilience practices while taking into account the requirements of the CRA. It is intended primarily for organisations that manufacture and place products with digital elements on the market, which are directly subject to the regulation, but it can also be used by integrators and service providers involved in the product lifecycle.
The model is organised into five domains, each divided into five maturity criteria: governance and documentation; risk management and security by design and by default; vulnerability and patch management; product lifecycle management; awareness, competence and skills. It assigns each organisation one of three maturity profiles (basic, intermediate, advanced), which indicate how consistently product-security practices are applied. ENISA notes that an advanced maturity level does not replace legal obligations and does not constitute evidence of compliance. The model is accompanied by a downloadable Excel tool that guides the user through the process, automatically calculates maturity scores and helps track progress from one self-assessment to the next.
The findings of the survey on smaller enterprises
The model is based on a survey conducted by ENISA in February and March 2026, whose results were published on 24 June 2026. A total of 194 organisations from 31 countries, including 25 EU Member States, responded, covering microenterprises, small and medium-sized enterprises according to the European Commission definition. The questionnaire assessed awareness of the CRA, understanding of its requirements, existing cybersecurity practices, organisational responsibilities and anticipated challenges ahead of compliance.
The results reveal a gap between awareness and practical readiness: 66 per cent of respondents had already heard of the CRA, but the understanding of its practical requirements remains to be improved. The size of the enterprise is the factor that most affects maturity: across all five domains, medium-sized companies scored on average about one point higher than microenterprises. The weakest area overall, particularly for microenterprises, is incident response and product lifecycle management.
The forms of support requested by enterprises
The survey also gathered support needs. Practical templates are the most requested form of help: technical documentation templates and secure development templates were each cited by more than 70 per cent of respondents. The question of resources, cost and time remains central: 142 respondents underlined the need for financial support. Enterprises, moreover, do not rely on a single source of information about the CRA, so effective communication requires a combination of formats and channels. On this basis, the ENISA report sets out recommendations on the critical points identified, from documentation and conformity assessment to technical documentation templates, from incident response and product lifecycle management to financial support, with specific recommendations for microenterprises.
Outlook
The Cyber Resilience Act timeline sets out two dates already defined: the obligations to report actively exploited vulnerabilities and severe incidents will apply from 11 September 2026, while the regulation’s main obligations will apply from 11 December 2027. In the intervening period, the European Commission and ENISA have announced the continuation of guidance, tools and support activities aimed at SMEs. What remains to be defined, at the level of the individual enterprise, is the adoption of the practices described in the model and the closing of the gaps identified by the survey, in particular in incident response and product lifecycle management and in the availability of resources for the smallest organisations.
In dialogue with the 2030 Agenda
- Goal 9 (Industry, Innovation and Infrastructure). The security of products with digital elements concerns the resilience of the infrastructure and technological goods circulating in the single market.
- Goal 8 (Decent Work and Economic Growth). Small and medium-sized enterprises make up a large part of the Union’s economic fabric; supporting their readiness aims to prevent adjustment costs from weighing disproportionately on the smallest organisations.
- Goal 4 (Quality Education). One of the model’s five domains concerns awareness, competence and skills; the survey highlights the need for training and practical templates.
- Goal 17 (Partnerships for the Goals). The work involves the European Commission, ENISA, the Member States and enterprises, with a survey extended to 31 countries.
Sources
- ENISA, news item “Where do SMEs stand in preparing for the Cyber Resilience Act?”, 13 July 2026
- ENISA, “SME Cyber Resilience Maturity Assessment Model”, 13 July 2026
- ENISA, “SME CRA Survey Report”, 24 June 2026
- European Commission, “Cyber Resilience Act” page (Shaping Europe’s digital future)
- European Commission, “Cyber Resilience Act: Reporting obligations” page
- Regulation (EU) 2024/2847 (Cyber Resilience Act), text on EUR-Lex




