The EU Agency for Cybersecurity (ENISA) publishes the Micro, Small and Medium-sized enterprises (SME) Cyber Resilience Maturity Assessment Model, a simple and practical guidance for SMEs to support them assess their current status, identify improvements and strengthen their cyber resilience practices. As SMEs make up a large part of EU´s digital ecosystem, their ability to understand and implement the Cyber Resilience Act (CRA)is significant for the regulation’s success. Particularly, as smaller organisations face practical challenges related to resources, expertise, time and implementation capacity. To help address this, as part of the European Commission’s SME cybersecurity strategy, ENISA is working on practical guidance, tools and support activities tailored to the realities and needs of smaller organisations. The SME Cyber Resilience Maturity Assessment Model provides a structured approach for SMEs to evaluate and strengthen their overall cyber resilience, while taking into account the requirements of the CRA. The model is primarily intended for organisations that manufacture and place products with digital elements on the market, as these are directly subject to CRA requirements. However, it can also be used by other organisations involved in the product life cycle, such as integrators or service providers, to assess and improve their product security practices. It focuses on the following five domains, with each domain divided into five maturity criteria that reflect expected practices under the CRA and product security approaches: - governance and documentation, - risk management and security by design and by default, - vulnerability and patch management, - product life cycle management, - awareness, competence and skills. The model suggests three maturity profiles: basic, intermediate and advanced, intended to show how consistently product-related risks are managed in the organisation. Overall, this model reflects practices supporting the implementation of the CRA and supports organisations in strengthening their product security and cyber resilience over