Skip to content

Latest commit

 

History

History
63 lines (36 loc) · 5.18 KB

File metadata and controls

63 lines (36 loc) · 5.18 KB

Cyber Resilience Maturity Assessment Model for SMEs (ENISA SME Cyber Resilience Maturity Assessment Model)

The CRA sets out mandatory requirements but gives manufacturers no simple way to gauge how close they are to meeting them. In July 2026, the European Union Agency for Cybersecurity (ENISA) published an official self-assessment methodology built exactly for this purpose — the SME Cyber Resilience Maturity Assessment Model. The document is distributed under the CC-BY 4.0 license (free use and reuse permitted, provided the source is credited).

An important caveat, straight from ENISA itself: a high maturity score under this model is not proof of CRA compliance and does not replace a manufacturer's legal obligations. It is a self-diagnostic and prioritisation tool, not a certification.

Who it's for

The model is aimed at micro, small, and medium enterprises acting as manufacturers, importers, or distributors of products with digital elements, but can be used by any organisation in such a product's supply chain.

Structure: 5 domains × 5 criteria

The methodology scores an organisation across five domains, each broken down into 5 specific criteria:

  1. Governance and documentation — assigned roles and responsibilities, management-approved security policies, product-level technical documentation, supplier requirements, regular management review.

  2. Risk management and Security by Design/Default — threat, abuse, and attack-surface analysis, supply-chain risk assessment, secure-by-default configuration, minimisation of active functions.

  3. Vulnerability and update management — vulnerability tracking, monitoring of external databases and advisories, risk-based prioritisation, update development/testing/distribution, communication with users, SBOM.

  4. Product lifecycle management — a declared support period, updates throughout the entire support period, end-of-life (EOL) notifications, secure decommissioning.

  5. Awareness, competence, and skills — baseline staff security awareness, role-based training, secure development and configuration practices, incident analysis and knowledge sharing.

Maturity scale (for each of the 25 criteria)

  • Level 1 — not implemented
  • Level 2 — implemented informally, on an ad hoc basis
  • Level 3 — documented, but applied inconsistently
  • Level 4 — applied consistently and reviewed regularly
  • Level 5 — measured, monitored, and continuously improved

A key nuance of the methodology: a process that is documented but not actually followed in practice is level 2, not level 3. Level 5 requires evidence of measurement (metrics/KPIs), not just "the process works well."

Scoring and profiles

A domain score is the average of its 5 criteria; the overall score is the average of the 5 domains. For compound questions (where one criterion covers several aspects), the weakest of them is counted.

  • Basic: 1.0–2.5 — informal, reactive approach, needs attention
  • Intermediate: 2.6–3.9 — documented but applied inconsistently
  • Advanced: 4.0–5.0 — formalised, consistent, continuously improved

How to go through it

The self-check takes roughly 2 hours: complete the questionnaire → get a score → determine your profile → prioritise the gaps (highest-risk first, then "quick wins," then long-term culture and training) → repeat annually or after significant changes to the product or processes.

Annexes to the methodology

The official document includes: Annex A — the self-check questionnaire (25 questions, 5 per domain), Annex B — a post-assessment action checklist, Annex C — a glossary, Annex D — a mapping table between the model's criteria and specific CRA requirements.

Companion ENISA tools

How to use this in practice

This model works well as a fast first step: in about 2 hours, a company gets a structured picture of its weak spots, framed in terms that line up with what the CRA actually asks for. But since the model deliberately does not distinguish between product categories (Default / Important / Critical) and does not tie its answers to specific articles or annexes of the regulation, the next step — understanding exactly which conformity assessment procedure applies to your product and exactly which Annex I requirements follow from that — calls for a more targeted tool that references CRA articles directly (for example, Platanor's CRA Readiness Check).


Source: ENISA, SME Cyber Resilience Maturity Assessment Model, July 2026 (CC-BY 4.0). Official publication page: https://www.enisa.europa.eu/publications/sme-cyber-resilience-maturity-assessment-model