Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04
For whoever signs off what the company's connected products still owe

Paste your product list. See which Cyber Resilience Act class each product falls in and what is missing.

Cyber Resilience Act Gap Finder reads your product list line by line: the class each product's function points to, the duties where you sell it, and the gaps, from the vulnerability reporting duty that already applies to the support period. Paste your product list, one line per product. Every connected product is read against the EU Cyber Resilience Act, the UK PSTI rules and California's connected-device law: which CRA class its declared function points to, which duties attach where you sell it, and what is missing, from the vulnerability reporting duty that already applies to the support period, default passwords and the conformity route, each with the clause behind it.

Paste your product list, one line per product: what it does, where you sell it, how passwords and updates work, the support period. Not documents, not firmware. The list is read in your browser and nothing is stored until you save.

It reads what your list says about each product. It does not test devices, read your technical file or give a compliance score.

Every finding names the column that raised it, the Article or Annex point behind it, and what it could not determine. It cites the Annex numbering and the Act's own dates; where the Commission's technical descriptions or harmonised standards are not held, it names them and does not state them.

It never says a product is compliant, conformant, CE-ready or certified, and the class is always the class the function you declared points to.

Check your own listTen products free, no account. A published dictionary of 72 product functions keyed to Annex III and IV and the clause text load with the page; every check runs in your browser.
Specimen, 5 of 30 productsan invented device maker
ProductFunction, and the class it points toRoute plannedNotes
GW-2smart meter gateway
critical
self-assessment1
IG-200industrial IoT gateway with firewall and VPN
default, or important class II?
self-assessment2
R-54G router for depots
important class I
self-assessment369
Cam-1indoor IP camera
important class I
harmonised standard5
TR-11GPS tracker for trailers
default
self-assessment4

30 products, 4 whose declared function points to a stricter class than the route planned, 2 on the EU market with no vulnerability reporting process.

13 of 14 note types raised, 28 of 30 functions matched, 1 borderline.

An engineer at a bench taking apart a device under a stereo microscope, a multimeter in the foreground
Go into the next distributor audit or notified body call knowing, product by product, which duty is still open and which Article asks for it. It works from the product list you already keep, without sending firmware, test reports or a technical file anywhere.
01

Paste the list as it leaves the spreadsheet or the PLM export

One product per row: product | function | markets at least, or with any of sold to, role, default password, updates, support period, vulnerability contact, reporting process, SBOM, conformity route, authorised representative, PSTI statement, placed on market and still on sale. Each function is matched to one of 72 published functions; a line that fits none is marked unmatched and never guessed.

02

Read the class and the route it asks for

Each product shows the class its declared function points to (default, important class I or II, critical, or out of scope under Article 2), the Annex point, the route Article 32 sets for that class against the route you planned, and the duties per market and role. A borderline function is worded as a question.

03

Take the notes to the product owners

Fourteen notes in a fixed order, from the reporting duty that applies from 11 September 2026 to the support period and default passwords, each with the products it names, the clause from the CRA, UK PSTI, ETSI EN 303 645 or California's law, and the question to put to the product owner, your notified body or legal.

One product per row: Product | Function | Markets, or a header row with any of Sold to, Role, Default password, Updates, Support period, Vulnerability contact, Reporting process, SBOM, Conformity route, EU authorised representative, PSTI statement, Placed on market, Still on sale. Tabs, pipes, commas or double spaces. A first line such as role: manufacturer | markets: EU, UK, US-California | manufacturer outside EU: yes | vulnerability reporting process: no | as at: 2026-09-26 sets the company defaults and the date.
Nothing is sent anywhere until you choose to save.
Company defaults (a line's own column overrides)

Why a list, and not a test lab

A test lab reads one device at a time and a technical file reads one product in depth. The head of product compliance at a 1,400-person maker is asked a simpler question first, by the board, a distributor or a market surveillance authority: across everything we sell, which products fall in a stricter class than we planned for, which have no reporting process now that Article 14 applies, and which are missing a support period, a vulnerability contact or a statement of compliance. The answer sits in the product list you already keep. That is what this reads, in your browser, from the list as it stands.

The dictionary is ours and published in full: every product function and the class it points to, the four classes with the Annex wording, the clauses each regime attaches, the dates of application, how a declared function is matched and the columns a product list needs. It reads labels only, and a note is a gap for the product owner or a question for your notified body or legal, never a ruling.