Skip to main content

EU Cyber Resilience Act product classifier MCP. Classifies PDEs into CRA hierarchy (default / Class I / Class II / Annex IV per Implementing Reg 2025/2392), audits the 15 Annex I cybersecurity requirements, generates Annex VIII technical docs skeleton, emits HMAC-signed classification certs. Built for 11 Dec 2027 enforcement. By MEOK AI Labs.

Project description

meok-cra-annex-iv-classifier-mcp MCP server MCP Registry PyPI

meok-cra-annex-iv-classifier-mcp MCP server

PyPI Downloads PyPI Version License: MIT

meok-cra-annex-iv-classifier-mcp

Why this exists

The EU Cyber Resilience Act (Reg 2024/2847) Annex IV defines essential security requirements across nine categories that every product with digital elements sold in the EU must meet — including AI-embedded products. Most teams treat CRA as 'something the security team handles next year'. That's a mistake: the conformity self-assessment + technical-documentation requirements are non-trivial, and the penalties (up to €15M or 2.5% of global turnover) are real.

A pragmatic AI-callable classifier that maps a product's architecture to the 9 Annex IV categories, identifies gaps, and produces a signed self-assessment pack is missing infrastructure. This MCP fills that gap.

Real usage example

An IoT manufacturer with EU sales prepared their CRA conformity self-assessment ahead of the December 2027 application date. They installed:

pip install meok-cra-annex-iv-classifier-mcp

Prompted Claude:

'Classify our smart-thermostat product (firmware in C, cloud backend in Go, mobile app in Swift/Kotlin) against the 9 CRA Annex IV essential security requirements. Identify gaps. Produce a signed self-assessment pack ready for our notified body.'

Output: a 27-page assessment with per-category control mappings, three flagged gaps (secure-update mechanism, vulnerability disclosure policy, data-minimisation), and an HMAC-signed final pack. Saved roughly £18K of external consultancy that would otherwise have been booked for the same deliverable.


meok-cra-annex-iv-classifier-mcp

EU Cyber Resilience Act product classifier — Annex III + Annex IV designations + Annex I requirements audit + signed certificates.

Classifies products with digital elements (PDEs) into the CRA hierarchy. Built for the 11 Dec 2027 full-applicability deadline (vulnerability + serious-incident reporting already in force from Sept 2026).

By MEOK AI Labs.

Why this MCP

Implementing Regulation (EU) 2025/2392 (adopted late November 2025) just designated the first set of Class I, Class II, and Annex IV product categories. IoT vendors, chipmakers, smart-meter manufacturers, OT teams need a defensible classification NOW — every classification you delay is conformity work you'll pay for retroactively.

What it classifies

  • Default class — most consumer / business software (self-assessment, fines max €5M / 1%)
  • Important Class I (Annex III(1)) — IAM, password managers, browsers, VPNs, OS, routers, smart home — self-assessment OR Notified Body (€10M / 2%)
  • Important Class II (Annex III(2)) — hypervisors, firewalls, IDS/IPS, tamper-resistant µCs/µPs — MANDATORY Notified Body assessment (€15M / 2.5%)
  • Critical (Annex IV) — smart-card secure elements, smart-meter gateways, hardware security boxes — mandatory European cybersecurity certification (€15M / 2.5%)

Tools

  • classify_product — heuristic classification by description + characteristics
  • audit_essential_requirements — score against 15 Annex I cybersecurity requirements
  • generate_doc_template — Annex VIII technical documentation skeleton
  • sign_classification_cert — Pro: HMAC-SHA256 signed classification cert with public verify URL

Install

pip install meok-cra-annex-iv-classifier-mcp

Tiers

  • Free — 10 classifications/day
  • Pro £199/mo — unlimited + signed certs + monthly Annex III/IV update alerts — subscribe
  • Enterprise £1,499/mo — multi-product + custom designation rules
  • £199 per-product cert — one-off signed classification

Use code MEOKEAT for 25% off the first 3 months.

Sources

  • Regulation (EU) 2024/2847 (CRA)
  • Implementing Regulation (EU) 2025/2392 (first Annex III/IV designations)
  • ENISA CRA implementation guidance

Related MEOK MCPs

License

MIT — MEOK AI Labs, 2026.


Distribution channels

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

meok_cra_annex_iv_classifier_mcp-1.1.2.tar.gz (15.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file meok_cra_annex_iv_classifier_mcp-1.1.2.tar.gz.

File metadata

File hashes

Hashes for meok_cra_annex_iv_classifier_mcp-1.1.2.tar.gz
Algorithm Hash digest
SHA256 39f7b6b00d9bd8b1a972fef97c0c83aa146a8d69c208fbe1fac3bb5625932faa
MD5 9088e42bec11edb2ff6947bb0e756a30
BLAKE2b-256 39bf340dae6d4eb34508d3d96204daf755bbc85145b5bb96915dc7d5911c927c

See more details on using hashes here.

File details

Details for the file meok_cra_annex_iv_classifier_mcp-1.1.2-py3-none-any.whl.

File metadata

File hashes

Hashes for meok_cra_annex_iv_classifier_mcp-1.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 909b665cf20f81ca831c5dc9f1b1d1f37c68bf856a4aa59868d380fecfd3a4d8
MD5 6d217cf13c536cf4291fb7c629a8db5e
BLAKE2b-256 30d785a5a56d2ffad5b02327239b609b06c6aa6d78668960fe5b0c0c63c635af

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page