The model provides a structured approach for micro, small, and medium-sized enterprises to evaluate and strengthen their cyber resilience, framed around the requirements of the Cyber Resilience Act. It is aimed primarily at organisations manufacturing products with digital elements that fall directly under CRA obligations, but is also usable by integrators or service providers elsewhere in the product life cycle. It is accompanied by a downloadable CRA Maturity Model spreadsheet tool for conducting the self-assessment.
Author: ENISA
Status: Adopted / Published
Adoption date: 2026-07-13
Last updated: 19 Aug 2026
Category: Guidance
Subcategory: Tool