Editorial explainer · official ENISA sources and Regulation (EU) 2024/2847medium
A maturity model for companies with no security department: ENISA tries to make the CRA workable
On 13 July 2026 ENISA published the SME Cyber Resilience Maturity Assessment Model: a structured approach for micro, small and medium-sized enterprises to evaluate and strengthen their cyber resilience while taking the Cyber Resilience Act's requirements into account. A spreadsheet tool ships alongside the document. It is the natural sequel to June's SME CRA Survey Report, and it lands a few weeks before the regulation's first real deadline: 11 September 2026, when the reporting obligations start to apply. The model certifies nothing and makes nobody compliant. It answers a more modest and more urgent question: where are we, and where do we start?
The problem the regulation does not solve on its own
The Cyber Resilience Act — Regulation (EU) 2024/2847 — is written for products, not for company size. A maker of connected devices with twelve employees carries obligations of the same nature, on the products it places on the European market, as a multinational. The difference is not in the rule: it is in who reads it.
In large organisations someone's job is to translate a regulation into a plan. In SMEs, which make up most of Europe's productive fabric, that function does not exist as a role: it is absorbed by whoever is already doing something else, usually the technical lead or the owner. The typical outcome is not deliberate non-compliance. It is paralysis: a long text, no obvious entry point, and a deadline that feels distant until it is not.
The document ENISA published on 13 July 2026 tries to provide that entry point.
What it actually is
The SME Cyber Resilience Maturity Assessment Model is, as the agency describes it, a structured approach for micro, small and medium-sized enterprises to evaluate and strengthen their overall cyber resilience, while taking into account the requirements of the Cyber Resilience Act.
The primary audience is stated: organisations that manufacture and place products with digital elements on the market, because they are directly subject to CRA requirements. But ENISA notes the model can also be used by other organisations involved in the product life cycle — integrators, service providers — to assess and improve their product security practices.
A CRA Maturity Model Tool in .xlsx format is published alongside the document. That is not a minor detail: it means the self-assessment happens inside a tool the SME already knows how to use, with no platform purchase and no mandatory consultancy for the first step.
- 01Assesswhere you actually are, not where you think you are
- 02Identifyimprovement areas, in order
- 03Strengthenwith the CRA requirements as the reference
The context: what June showed
The model did not arrive in isolation. On 24 June 2026 ENISA published the SME CRA Survey Report, the result of a survey run specifically to understand where smaller firms stood in relation to the regulation. The agency states explicitly that it is working on practical guidance, tools and support activities tailored to the realities and needs of smaller organisations, to help them understand and implement the CRA.
The sequence is worth reading for what it is: first measure the distance between the rule and the people who must apply it, then build the tool. In regulatory practice that order is far from a given.
The deadline that makes this urgent
- 10 December 2024In force
The Cyber Resilience Act enters into force.
- 24 June 2026Survey
ENISA publishes the SME CRA Survey Report.
- 13 July 2026Tool
The SME maturity model ships, with a spreadsheet tool.
- 11 September 2026First deadline
Reporting obligations for manufacturers begin to apply.
- 11 December 2027Main block
Essential requirements, conformity assessment, CE marking.
11 September 2026 is the first moment the CRA stops being a planning matter and becomes an operational duty: from that day manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours and a notification within 72.
That deadline hits SMEs asymmetrically compared with large firms, and not for reasons of resourcing. Reporting within 24 hours requires noticing: that is, a channel through which reports about your products actually arrive, someone who reads it, and a procedure decided in advance. A company without a public vulnerability disclosure address does not have a paperwork problem: it has a detection problem.
How to use it, without illusions about what it does
What it does: it gives structure to a vague question. It turns "we should deal with the CRA" into a list of areas with a current level and a next level. It is the cheapest way to find out which two or three areas leave you most exposed — and in most cases they are not the ones you expect.
What it does not do: it is not a certification, it does not produce compliance, it does not replace the conformity assessment the regulation requires and it binds no authority. A high self-assessment score is not a defence if a product placed on the market does not meet the essential requirements.
How not to waste it: filling it in once and filing it away is the most likely and least useful ending. The value of a maturity model is in the second measurement, not the first: it exists to show whether anything moved. Setting the date for round two now — six months, not "when we have time" — is the difference between a tool and a file.
The most concrete piece of advice: start from the part of the model covering vulnerability handling and external communication. Not because it is the most important in the abstract, but because it carries the nearest deadline, and it is where being late becomes visible from the outside.
A note on what this article is: an explainer on official tools just published, with the facts taken from ENISA's pages and from the regulation. It contains no assessment of the model's effectiveness, which is not yet measurable: it came out a few weeks ago.