eu-cra

Advises on EU Cyber Resilience Act compliance for products with digital elements.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill eu-cra-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: eu-cra
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/eu-cra
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill eu-cra-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Manufacturers, importers, and distributors selling connected hardware or software in the EU must comply with Regulation (EU) 2024/2847, but navigating product classification, conformity assessment routes, SBOM duties, and ENISA reporting deadlines is complex and error-prone. ## Core Features & Use Cases - Product Classification: Determines whether a product is in CRA scope and whether it falls into Default, Class I (Annex III), or Class II (Annex IV) categories. - Gap Analysis: Maps existing security controls against Annex I Part I security properties and Part II vulnerability handling obligations. - Conformity & CE Marking Guidance: Walks through Module A self-assessment or Notified Body routes, technical documentation (Annex VII), and the EU Declaration of Conformity. - Use Case: A router manufacturer asks whether their home router needs a Notified Body; the skill classifies it as Class I, explains the self-assessment option, and lists the technical documentation and 24/72-hour ENISA reporting duties. ## Quick Start Ask the skill to classify your connected product under the EU Cyber Resilience Act and list its conformity assessment obligations.

Frequently Asked Questions about eu-cra

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I classify my product under the EU Cyber Resilience Act?

Check whether the product has a network interface, then compare it against the 35 Annex III (Class I) and 12 Annex IV (Class II) categories. If it matches neither annex and is not excluded, it falls into the Default class with self-assessment.

What products are excluded from the EU Cyber Resilience Act?

Medical devices under MDR/IVDR, aviation products under EASA, automotive type-approved products, marine equipment, and military or national security products are excluded. Non-commercial open-source software is also generally out of scope.

When do EU CRA vulnerability reporting obligations start?

Vulnerability and incident reporting to ENISA and national CSIRTs applies from 11 September 2026. Full application of all manufacturer, importer, and distributor obligations begins on 11 December 2027.

Does the EU CRA require an SBOM for my product?

Yes, manufacturers must provide a machine-readable SBOM on request to authorities, covering at minimum top-level dependencies with name, version, supplier, and licence. SPDX and CycloneDX are the recommended formats.

What are the penalties for non-compliance with the EU CRA?

Violating Annex I essential requirements can cost up to €15 million or 2.5% of global annual turnover. Other obligation breaches reach €10 million or 2%, and misleading information to authorities up to €5 million or 1%.

Does the EU CRA apply to open-source software maintainers?

Individual open-source contributors who do not monetise their software are not covered. Open-source software stewards supporting commercially used components face light-touch duties like publishing a cybersecurity policy and cooperating with authorities.