Skip to main content

EU Cyber Resilience Act product classifier MCP. Classifies PDEs into CRA hierarchy (default / Class I / Class II / Annex IV per Implementing Reg 2025/2392), audits the 15 Annex I cybersecurity requirements, generates Annex VIII technical docs skeleton, emits HMAC-signed classification certs. Built for 11 Dec 2027 enforcement. By MEOK AI Labs.

Project description

meok-cra-annex-iv-classifier-mcp MCP server

PyPI Downloads PyPI Version License: MIT

meok-cra-annex-iv-classifier-mcp

Why this exists

The EU Cyber Resilience Act (Reg 2024/2847) Annex IV defines essential security requirements across nine categories that every product with digital elements sold in the EU must meet — including AI-embedded products. Most teams treat CRA as 'something the security team handles next year'. That's a mistake: the conformity self-assessment + technical-documentation requirements are non-trivial, and the penalties (up to €15M or 2.5% of global turnover) are real.

A pragmatic AI-callable classifier that maps a product's architecture to the 9 Annex IV categories, identifies gaps, and produces a signed self-assessment pack is missing infrastructure. This MCP fills that gap.

Real usage example

An IoT manufacturer with EU sales prepared their CRA conformity self-assessment ahead of the December 2027 application date. They installed:

pip install meok-cra-annex-iv-classifier-mcp

Prompted Claude:

'Classify our smart-thermostat product (firmware in C, cloud backend in Go, mobile app in Swift/Kotlin) against the 9 CRA Annex IV essential security requirements. Identify gaps. Produce a signed self-assessment pack ready for our notified body.'

Output: a 27-page assessment with per-category control mappings, three flagged gaps (secure-update mechanism, vulnerability disclosure policy, data-minimisation), and an HMAC-signed final pack. Saved roughly £18K of external consultancy that would otherwise have been booked for the same deliverable.


meok-cra-annex-iv-classifier-mcp

EU Cyber Resilience Act product classifier — Annex III + Annex IV designations + Annex I requirements audit + signed certificates.

Classifies products with digital elements (PDEs) into the CRA hierarchy. Built for the 11 Dec 2027 full-applicability deadline (vulnerability + serious-incident reporting already in force from Sept 2026).

By MEOK AI Labs.

Why this MCP

Implementing Regulation (EU) 2025/2392 (adopted late November 2025) just designated the first set of Class I, Class II, and Annex IV product categories. IoT vendors, chipmakers, smart-meter manufacturers, OT teams need a defensible classification NOW — every classification you delay is conformity work you'll pay for retroactively.

What it classifies

  • Default class — most consumer / business software (self-assessment, fines max €5M / 1%)
  • Important Class I (Annex III(1)) — IAM, password managers, browsers, VPNs, OS, routers, smart home — self-assessment OR Notified Body (€10M / 2%)
  • Important Class II (Annex III(2)) — hypervisors, firewalls, IDS/IPS, tamper-resistant µCs/µPs — MANDATORY Notified Body assessment (€15M / 2.5%)
  • Critical (Annex IV) — smart-card secure elements, smart-meter gateways, hardware security boxes — mandatory European cybersecurity certification (€15M / 2.5%)

Tools

  • classify_product — heuristic classification by description + characteristics
  • audit_essential_requirements — score against 15 Annex I cybersecurity requirements
  • generate_doc_template — Annex VIII technical documentation skeleton
  • sign_classification_cert — Pro: HMAC-SHA256 signed classification cert with public verify URL

Install

pip install meok-cra-annex-iv-classifier-mcp

Tiers

  • Free — 10 classifications/day
  • Pro £199/mo — unlimited + signed certs + monthly Annex III/IV update alerts — subscribe
  • Enterprise £1,499/mo — multi-product + custom designation rules
  • £199 per-product cert — one-off signed classification

Use code MEOKEAT for 25% off the first 3 months.

Sources

  • Regulation (EU) 2024/2847 (CRA)
  • Implementing Regulation (EU) 2025/2392 (first Annex III/IV designations)
  • ENISA CRA implementation guidance

Related MEOK MCPs

License

MIT — MEOK AI Labs, 2026.


Distribution channels

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

meok_cra_annex_iv_classifier_mcp-1.1.1.tar.gz (14.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file meok_cra_annex_iv_classifier_mcp-1.1.1.tar.gz.

File metadata

File hashes

Hashes for meok_cra_annex_iv_classifier_mcp-1.1.1.tar.gz
Algorithm Hash digest
SHA256 7bb7a1b2efc248c9a9cc109e3aa504d34cddb1df1cccbd4b857eb952c6a8c262
MD5 95f6a41021f79f9f4f3ce59f4bc030f9
BLAKE2b-256 a37603e469fbcdb07d06772045560e5b45b558491609b21389fa83b6e19229f6

See more details on using hashes here.

File details

Details for the file meok_cra_annex_iv_classifier_mcp-1.1.1-py3-none-any.whl.

File metadata

File hashes

Hashes for meok_cra_annex_iv_classifier_mcp-1.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 9b93dba238c99012d1ba55477afe7593126464ee5f2247b109bbcc699fd9a4f6
MD5 738fd6f476f29d9316bfd831335fba36
BLAKE2b-256 7a430e58a829105d290157311ec72dd25c61a511bff79aec3baa83a4e01c26c9

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page