Skip to main content

EU Cyber Resilience Act (Regulation 2024/2847) compliance for AI agents. Product classification, Annex I audit, SBOM generation, conformity assessment roadmap, vulnerability reporting readiness. For manufacturers of products with digital elements. By MEOK AI Labs.

Project description

CRA Compliance MCP

The only MCP server that automates EU Cyber Resilience Act (CRA, Regulation 2024/2847) compliance for manufacturers, importers, and distributors of products with digital elements.

Built by MEOK AI Labs. Pairs with our DORA, NIS2, EU AI Act, and ISO MCPs.

What it does

  • Classify any product into CRA class (default / Class I / Class II / Critical)
  • Audit Annex I essential requirements (both product-property Part 1 and vulnerability-handling Part 2)
  • Generate CycloneDX SBOM skeleton (Article 13 + Annex I 2.1 mandatory)
  • Assess vulnerability-reporting readiness for Sep 2026 mandatory reporting to ENISA
  • Produce conformity assessment roadmap with CE marking path + timeline + cost estimate
  • Track enforcement timeline — 3 critical dates between now and Dec 2027

Install

pip install cra-compliance-mcp

Use with Claude Desktop

{
  "mcpServers": {
    "cra": { "command": "cra-compliance-mcp" }
  }
}

Why it matters

  • Enforcement dates locked in: 11 Sep 2026 (reporting) → 11 Jun 2027 (vuln handling) → 11 Dec 2027 (full)
  • Penalties up to €15M or 2.5% of global turnover for Annex I violations
  • ALL products with digital elements sold on EU market in scope — IoT, software, SaaS, firmware, mobile apps
  • ENISA single reporting platform launching 2026 — requires 24h / 72h / 1-month timeline
  • CE marking mandatory from Dec 2027 — no CRA compliance = no EU market

Tiers

  • Free — 10 calls/day, classification, Annex I audit, SBOM skeleton
  • Pro (£199/mo) — unlimited, signed attestations, full SBOM scanner, notified-body handoff pack
  • Team (£499/mo) — multi-product, consolidated dashboard, cross-CRA/NIS2/DORA crosswalk
  • Enterprise (£1,499/mo) — SSO, SLA, co-branded Trust Center push, Annex II tech doc generator
  • 48h written assessment (£5,000) — vs £20–80k Big-4 gap assessments

Legal basis

Regulation (EU) 2024/2847 (Cyber Resilience Act). Commission Delegated and Implementing acts pending for Annex III/IV expansion and reporting technical formats. Automated self-assessment — not a substitute for a notified body conformity assessment.

License

MIT. MEOK AI Labs, 2026.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cra_compliance_mcp-1.1.0.tar.gz (9.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

cra_compliance_mcp-1.1.0-py3-none-any.whl (11.3 kB view details)

Uploaded Python 3

File details

Details for the file cra_compliance_mcp-1.1.0.tar.gz.

File metadata

  • Download URL: cra_compliance_mcp-1.1.0.tar.gz
  • Upload date:
  • Size: 9.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for cra_compliance_mcp-1.1.0.tar.gz
Algorithm Hash digest
SHA256 73739da2ed1af57fe61b1f55cc893eab0d0788e95ecf18f6168f93655e96fbd4
MD5 2b2ee5e767f9b32c7bc8ccc01d7df112
BLAKE2b-256 8a01505c65980a0ee7e26da06c089d19474b0e0a044e5cfdb5d2bb3c7f8584f0

See more details on using hashes here.

File details

Details for the file cra_compliance_mcp-1.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for cra_compliance_mcp-1.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 92bb6cced15e426d06816aa2ca4bf4590e3eb3ede8909486591c35107c2286df
MD5 f644b4d1059680ed01826957404145b2
BLAKE2b-256 df0c870eb3e31917926005c81a8a9a921c73f999f4b8fdd075d0ebb04aa89967

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page