Skip to main content

EU Cyber Resilience Act (Regulation 2024/2847) compliance for AI agents. Product classification, Annex I audit, SBOM generation, conformity assessment roadmap, vulnerability reporting readiness. For manufacturers of products with digital elements. By MEOK AI Labs.

Project description

CRA Compliance MCP

The only MCP server that automates EU Cyber Resilience Act (CRA, Regulation 2024/2847) compliance for manufacturers, importers, and distributors of products with digital elements.

Built by MEOK AI Labs. Pairs with our DORA, NIS2, EU AI Act, and ISO MCPs.

What it does

  • Classify any product into CRA class (default / Class I / Class II / Critical)
  • Audit Annex I essential requirements (both product-property Part 1 and vulnerability-handling Part 2)
  • Generate CycloneDX SBOM skeleton (Article 13 + Annex I 2.1 mandatory)
  • Assess vulnerability-reporting readiness for Sep 2026 mandatory reporting to ENISA
  • Produce conformity assessment roadmap with CE marking path + timeline + cost estimate
  • Track enforcement timeline — 3 critical dates between now and Dec 2027

Install

pip install cra-compliance-mcp

Use with Claude Desktop

{
  "mcpServers": {
    "cra": { "command": "cra-compliance-mcp" }
  }
}

Why it matters

  • Enforcement dates locked in: 11 Sep 2026 (reporting) → 11 Jun 2027 (vuln handling) → 11 Dec 2027 (full)
  • Penalties up to €15M or 2.5% of global turnover for Annex I violations
  • ALL products with digital elements sold on EU market in scope — IoT, software, SaaS, firmware, mobile apps
  • ENISA single reporting platform launching 2026 — requires 24h / 72h / 1-month timeline
  • CE marking mandatory from Dec 2027 — no CRA compliance = no EU market

Tiers

  • Free — 10 calls/day, classification, Annex I audit, SBOM skeleton
  • Pro (£199/mo) — unlimited, signed attestations, full SBOM scanner, notified-body handoff pack
  • Team (£499/mo) — multi-product, consolidated dashboard, cross-CRA/NIS2/DORA crosswalk
  • Enterprise (£1,499/mo) — SSO, SLA, co-branded Trust Center push, Annex II tech doc generator
  • 48h written assessment (£5,000) — vs £20–80k Big-4 gap assessments

Legal basis

Regulation (EU) 2024/2847 (Cyber Resilience Act). Commission Delegated and Implementing acts pending for Annex III/IV expansion and reporting technical formats. Automated self-assessment — not a substitute for a notified body conformity assessment.

License

MIT. MEOK AI Labs, 2026.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cra_compliance_mcp-1.2.0.tar.gz (10.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

cra_compliance_mcp-1.2.0-py3-none-any.whl (11.9 kB view details)

Uploaded Python 3

File details

Details for the file cra_compliance_mcp-1.2.0.tar.gz.

File metadata

  • Download URL: cra_compliance_mcp-1.2.0.tar.gz
  • Upload date:
  • Size: 10.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for cra_compliance_mcp-1.2.0.tar.gz
Algorithm Hash digest
SHA256 ba023756f3b379693c81cefeb2986a4a66d81e547d65c277797e63dad232b4b8
MD5 e4aafd1b2f1015f5ea4401897993b54d
BLAKE2b-256 07ed0d2734cba874a8a4d6b144d0850aa9b2d03ea061c2176e791246e339bb07

See more details on using hashes here.

File details

Details for the file cra_compliance_mcp-1.2.0-py3-none-any.whl.

File metadata

File hashes

Hashes for cra_compliance_mcp-1.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 d49e7aace5405da248a037cc46355be4b9098380c48b5355c4a518e1dd4f333c
MD5 286957c730903dc2c07698d11c05cd32
BLAKE2b-256 660793888f77371f8781a0f7513d65c7728b983da2b010bf78e1828a3f0dcc60

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page