What problem does it solve?
Manufacturers, importers, and distributors selling connected products in the EU must comply with Regulation (EU) 2024/2847 (Cyber Resilience Act), but determining product classification, conformity assessment routes, and vulnerability reporting obligations is complex and error-prone.
Core Features & Use Cases
- Product Classification: Determine whether a product is a Product with Digital Elements (PDE) and classify it as Default, Class I (Annex III), or Class II (Annex IV) to select the correct conformity assessment route.
- Gap Analysis: Map product security controls against Annex I Part I security properties and Part II vulnerability handling obligations, including SBOM, VDP, and ENISA/CSIRT 24/72-hour reporting.
- CE Marking & Documentation: Guide preparation of Annex VII technical documentation, EU Declaration of Conformity, and CE marking with Notified Body requirements.
- Use Case: A router manufacturer uses this Skill to classify its home router as Class I, choose between self-assessment and Notified Body assessment, and build a vulnerability handling programme meeting the 5-year support period obligation.
Quick Start
Use the eu-cra skill to classify my connected IoT sensor product and outline its conformity assessment and vulnerability reporting obligations.