Paste your product list. See which Cyber Resilience Act class each product falls in and what is missing.
Cyber Resilience Act Gap Finder reads your product list line by line: the class each product's function points to, the duties where you sell it, and the gaps, from the vulnerability reporting duty that already applies to the support period. Paste your product list, one line per product. Every connected product is read against the EU Cyber Resilience Act, the UK PSTI rules and California's connected-device law: which CRA class its declared function points to, which duties attach where you sell it, and what is missing, from the vulnerability reporting duty that already applies to the support period, default passwords and the conformity route, each with the clause behind it.
Paste your product list, one line per product: what it does, where you sell it, how passwords and updates work, the support period. Not documents, not firmware. The list is read in your browser and nothing is stored until you save.
It reads what your list says about each product. It does not test devices, read your technical file or give a compliance score.
Every finding names the column that raised it, the Article or Annex point behind it, and what it could not determine. It cites the Annex numbering and the Act's own dates; where the Commission's technical descriptions or harmonised standards are not held, it names them and does not state them.
It never says a product is compliant, conformant, CE-ready or certified, and the class is always the class the function you declared points to.
| Product | Function, and the class it points to | Route planned | Notes |
|---|---|---|---|
| GW-2 | smart meter gateway critical | self-assessment | 1 |
| IG-200 | industrial IoT gateway with firewall and VPN default, or important class II? | self-assessment | 2 |
| R-5 | 4G router for depots important class I | self-assessment | 369 |
| Cam-1 | indoor IP camera important class I | harmonised standard | 5 |
| TR-11 | GPS tracker for trailers default | self-assessment | 4 |
30 products, 4 whose declared function points to a stricter class than the route planned, 2 on the EU market with no vulnerability reporting process.
13 of 14 note types raised, 28 of 30 functions matched, 1 borderline.

Paste the list as it leaves the spreadsheet or the PLM export
One product per row: product | function | markets at least, or with any of sold to, role, default password, updates, support period, vulnerability contact, reporting process, SBOM, conformity route, authorised representative, PSTI statement, placed on market and still on sale. Each function is matched to one of 72 published functions; a line that fits none is marked unmatched and never guessed.
Read the class and the route it asks for
Each product shows the class its declared function points to (default, important class I or II, critical, or out of scope under Article 2), the Annex point, the route Article 32 sets for that class against the route you planned, and the duties per market and role. A borderline function is worded as a question.
Take the notes to the product owners
Fourteen notes in a fixed order, from the reporting duty that applies from 11 September 2026 to the support period and default passwords, each with the products it names, the clause from the CRA, UK PSTI, ETSI EN 303 645 or California's law, and the question to put to the product owner, your notified body or legal.
Why a list, and not a test lab
A test lab reads one device at a time and a technical file reads one product in depth. The head of product compliance at a 1,400-person maker is asked a simpler question first, by the board, a distributor or a market surveillance authority: across everything we sell, which products fall in a stricter class than we planned for, which have no reporting process now that Article 14 applies, and which are missing a support period, a vulnerability contact or a statement of compliance. The answer sits in the product list you already keep. That is what this reads, in your browser, from the list as it stands.