The questions people actually ask.
Is SaaS affected by the CRA?+
Generally no: cloud-only SaaS falls under the NIS2 directive, not the CRA. The exception: if it ships a component installed on the customer side (agent, plugin, firmware) that's required to operate. The test settles your specific case.
What about open source?+
Open source developed outside of a commercial activity is exempt. As soon as a company commercializes it or integrates it into a product it sells, that company carries the CRA responsibility.
Is this legal advice?+
No. CRAcheck provides information based on the official text to guide and prepare you. For formal validation, consult a professional.
When do I need to be ready?+
Vulnerability reporting obligations apply from September 11, 2026. The main obligations (CE marking, EU declaration of conformity) from December 11, 2027.
What's the penalty for non-compliance?+
Up to €15M or 2.5% of worldwide annual turnover for a breach of the essential cybersecurity requirements.
Is the test really free?+
Yes: unlimited, no sign-up, and it runs in your browser. Only the document generator is paid (€25/month).