CRA

CRA Advanced

Complex CRA scenarios: penalty tiers, the actively-exploited-vulnerability/incident reporting chain, and interaction with the EU AI Act.

10 questions · 80% to pass · free

eurocompliant.com is not an accredited certification body. This is a self-paced educational assessment; the certificate confirms completion only, not a professional, statutory, or accredited qualification.

Your details

We'll email your certificate here if you pass. We may occasionally follow up about eurocompliant.com - you can unsubscribe any time.

Question 1 of 10

Under Article 64(2), what is the maximum fine for non-compliance with the essential cybersecurity requirements in Annex I, or with Articles 13 and 14?

Question 2 of 10

Under Article 64(3), what is the maximum fine for non-compliance with the broader list of other CRA obligations not covered by paragraph 2?

Question 3 of 10

Under Article 64(4), what is the maximum fine for supplying incorrect, incomplete, or misleading information to a notified body or market surveillance authority?

Question 4 of 10

Under Article 3(42), what makes a vulnerability an 'actively exploited vulnerability' rather than simply a known vulnerability?

Question 5 of 10

Under Article 3(30), what is a 'substantial modification', and why does it matter?

Question 6 of 10

A manufacturer's SBOM (Article 13/Annex I Part II point 1) and its technical documentation (Article 31/Annex VII) retention obligation (Article 13(13)) both need to be current. How do their required durations compare?

Question 7 of 10

A company sells a connected consumer device with an embedded high-risk AI system under the EU AI Act. How do the CRA and the AI Act's Article 15 cybersecurity requirement interact?

Question 8 of 10

Under Article 13, which of the following are real, distinct manufacturer obligations (as opposed to being combined into a single duty)?

Select all that apply.

Question 9 of 10

Where does the requirement for a manufacturer's coordinated vulnerability disclosure policy come from?

Question 10 of 10

A manufacturer both designs the hardware for a connected device and separately develops its firmware. Under Article 3's definitions, how does the CRA treat this?

0 of 10 answered