eu-cra

Assess products against EU Cyber Resilience Act requirements and conformity routes.

869|179|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: eu-cra
Source: https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/eu-cra/skills/eu-cra
Command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Manufacturers, importers, and distributors selling connected products in the EU must comply with Regulation (EU) 2024/2847 (Cyber Resilience Act), but determining product classification, conformity assessment routes, and vulnerability reporting obligations is complex and error-prone.

Core Features & Use Cases

  • Product Classification: Determine whether a product is a Product with Digital Elements (PDE) and classify it as Default, Class I (Annex III), or Class II (Annex IV) to select the correct conformity assessment route.
  • Gap Analysis: Map product security controls against Annex I Part I security properties and Part II vulnerability handling obligations, including SBOM, VDP, and ENISA/CSIRT 24/72-hour reporting.
  • CE Marking & Documentation: Guide preparation of Annex VII technical documentation, EU Declaration of Conformity, and CE marking with Notified Body requirements.
  • Use Case: A router manufacturer uses this Skill to classify its home router as Class I, choose between self-assessment and Notified Body assessment, and build a vulnerability handling programme meeting the 5-year support period obligation.

Quick Start

Use the eu-cra skill to classify my connected IoT sensor product and outline its conformity assessment and vulnerability reporting obligations.

Frequently Asked Questions about eu-cra

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I classify a product under the EU Cyber Resilience Act?

Check whether the product has a network interface, then compare it against the 35 Annex III (Class I) and 12 Annex IV (Class II) categories. Products matching neither annex are Default class and use Module A self-assessment.

What are the EU CRA vulnerability reporting deadlines?

Manufacturers must send an early warning to ENISA and national CSIRTs within 24 hours of becoming aware of an actively exploited vulnerability, a full notification within 72 hours, and a final report within 14 days after a fix is available.

Does the EU CRA require a Software Bill of Materials?

Yes, manufacturers must provide a machine-readable SBOM on request to market surveillance authorities, covering at minimum top-level dependencies with name, version, supplier, and licence. SPDX and CycloneDX are the recommended formats.

When do EU CRA obligations become mandatory?

The CRA entered into force on 10 December 2024. Vulnerability and incident reporting obligations apply from 11 September 2026, and all remaining manufacturer, importer, and distributor obligations apply from 11 December 2027.

Which products are excluded from the EU Cyber Resilience Act?

Medical devices under MDR/IVDR, aviation products under EASA, automotive type-approved products, marine equipment, and military or national security products are excluded. Non-commercial open-source software is also generally out of scope.

What are the penalties for EU CRA non-compliance?

Violating Annex I essential requirements carries fines up to €15 million or 2.5% of global annual turnover. Other obligation breaches reach €10 million or 2%, and providing misleading information to authorities reaches €5 million or 1%.