PortaRegulus
HOME
15 // INTEL · ANALYSIS

Not evidence of compliance.

ENISA published a free CRA maturity model for SMEs, and then wrote down what a good score does not buy you. That second part is the useful one.

PortaRegulus Intel CRA · ENISA · Maturity 08 Aug 2026

On 13 July 2026 ENISA published the SME Cyber Resilience Maturity Assessment Model, a free document with a downloadable Excel workbook. It lets a small manufacturer score its own product security practice across 25 questions and five domains, and lands on a profile of basic, intermediate or advanced. It is aimed squarely at the companies that make up most of the manufacturers the Cyber Resilience Act reaches and have nobody whose job this is.

The model is good. The sentence most readers will skip is better. An advanced maturity level, ENISA writes, "does not replace legal obligations and should not be considered evidence of compliance". The improvement actions in its annex carry the same warning, that following them does not guarantee compliance.

An agency built a diagnostic and then labelled it as a diagnostic. That is worth more than the questionnaire, because the failure mode it heads off is the common one.

Two different units of measurement

Maturity is scoped to your organisation. Are policies approved and actually used, are roles assigned, do risk assessments change decisions or just get filed after the fact. Every one of the 25 questions is about habits.

CRA conformity is scoped to a product. Article 13(2) wants a cybersecurity risk assessment of that product. Annex I wants the essential requirements met or justified away for it. Annex VII wants technical documentation describing it. The Declaration of Conformity names it and carries a signature underneath. No market surveillance authority will take a maturity band instead.

Because the two are scoped differently, they come apart in both directions.

CaseMaturityProduct conformity
Mature firm, legacy product with no per-product fileAdvancedFails Annex I and Annex VII
Three people, one product, all the work done by hand2.1Can be conforming

In the first case every organisational answer was true. Policies approved, testing automated, the disclosure process rehearsed. Then the company ships something built four years ago on a supplier stack nobody has touched since, with no risk assessment on file and a support period that was never declared. Conformity is per product, and nobody did the per-product work.

The second case is more common among small manufacturers than the industry admits. Nothing about that founder's work is repeatable and none of the method is written down, so the low score is accurate. The product can still be conforming.

What the score is actually good for

Sequencing, and a cost forecast.

Your maturity level predicts what each additional product costs you. At the bottom of the ladder everything is done once, by hand, by whoever is free. The risk assessment for product two starts from nothing, because the one for product one lives in somebody's drafts and its method was never described. Cost scales with the portfolio, and scales again every time a product changes enough to count as a substantial modification.

Higher up, the method exists, the roles are assigned, and the documentation has a shape the next product inherits. The first product was expensive. The eleventh is cheap.

For a manufacturer with one product, low maturity is survivable and possibly rational. For a manufacturer with a catalogue, low maturity is the thing that makes CRA compliance feel impossible, and no amount of effort on any single product fixes it.

The wall between level 3 and level 4

Read ENISA's level wording closely and the same step repeats through almost every question. Level 3 says documented. Level 4 says consistently applied.

Question 1.1 is the plainest. Level 3 is documented policies that are not formally approved or consistently used. Level 4 is policies formally approved, documented and generally applied. Question 2.1 does it again for risk assessments, where level 3 is documented but not consistently used and level 4 is systematically performed and guiding decisions.

Most SMEs that have done any CRA preparation land on that line and stop. They have written things. The writing has not changed what anybody does on a Tuesday. It shows up in the results as a cluster of 3s rather than a cluster of 2s, which is easy to read as progress. Getting past it is an organisational change, not another document. Somebody has to own the process and somebody has to notice when it is skipped.

One domain has a date on it

The five domains are not equally urgent, and ENISA does not treat them as if they were. Its improvement guidance ranks gaps by risk rather than by score, and the examples it gives of a high-risk gap are untracked vulnerabilities, a missing incident response process, and unclear regulatory responsibilities.

Two of those three sit in vulnerability and patch management, which is also the only domain with a deadline attached. Article 14 applies from 11 September 2026. From that date an actively exploited vulnerability in a product with digital elements triggers an early warning within 24 hours and a detailed notification within 72, filed to ENISA and the relevant CSIRT. There is no clause adjusting the clock for organisational maturity, no exemption for small manufacturers, and no grace period for a company that has not decided who is on call.

A governance score of 1.8 costs you time. A vulnerability handling score of 1.8 costs you a statutory deadline, the first time a researcher emails about something already being exploited.

The questionnaire without the spreadsheet

ENISA ships the model as a PDF with an Excel workbook. The workbook works. It is also a spreadsheet, which means it gets downloaded, opened once, and left in a folder.

We rebuilt the same 25 questions as a page you work through in a browser, with the scoring, the domain breakdown and the improvement checklist calculated as you go. It is free, there is no signup, and the answers are held in your own browser's local storage rather than on our servers.

We added one layer. Each question is tagged with whether our platform helps and to what level, capped at level 4. Level 5 across this model is measurement and continuous improvement, and software can hold a process, hold the evidence and show you the gaps without making anyone look at the result. Four of the five questions on skills and culture carry no tag at all. Whether your developers know how to build securely and whether people feel able to report a problem are not things a vendor supplies, and a green tick there would be a lie.

The short version

ENISA has given SMEs a free, structured way to find out which part of product security to fix first, and has been clear that finishing it proves nothing to a regulator. Use it to sequence the work and to forecast what the next product costs. Build conformity separately, per product, on evidence. If your vulnerability handling is the weak domain, start there, because that is the one the calendar is already deciding for you.

The model, the PDF and the Excel workbook are published free by ENISA. The browser version of the questionnaire is at cvdportal.com/cra-maturity-assessment. It is an independent implementation of ENISA's model and is not affiliated with or endorsed by ENISA.

Where do you actually stand?