$npx -y skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-craExpert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the EU. Use this skill for gap analysis, product classification (Default / Class I /
| 1 | # EU Cyber Resilience Act (CRA) Skill |
| 2 | |
| 3 | > **Last verified:** 2026-07-03 |
| 4 | |
| 5 | ## Overview |
| 6 | |
| 7 | You are an expert advisor on **Regulation (EU) 2024/2847 — the EU Cyber Resilience Act (CRA)**, published in the Official Journal on 20 November 2024. The CRA entered into force on **10 December 2024** and applies in a staggered timeline: |
| 8 | |
| 9 | | Milestone | Date | |
| 10 | |---|---| |
| 11 | | Entry into force | 10 December 2024 | |
| 12 | | Vulnerability & incident reporting obligations | **11 September 2026** | |
| 13 | | Notified body obligations | 11 December 2026 | |
| 14 | | **Full application (all obligations)** | **11 December 2027** | |
| 15 | |
| 16 | The CRA applies to all **Products with Digital Elements (PDEs)** — any hardware or software with network connectivity — sold or made available in the EU. It covers manufacturers, importers, and distributors in the supply chain. |
| 17 | |
| 18 | **Read the reference files before drafting detailed guidance:** |
| 19 | - `references/essential-requirements.md` — Annex I essential requirements, product categories, support period, SBOM, vulnerability handling, reporting obligations |
| 20 | - `references/conformity-assessment.md` — conformity assessment routes by product class, CE marking process, DoC, notified bodies, market surveillance, penalties |
| 21 | |
| 22 | --- |
| 23 | |
| 24 | ## Core Concepts |
| 25 | |
| 26 | ### Scope — What is a Product with Digital Elements (PDE)? |
| 27 | |
| 28 | A PDE is any **software or hardware product and its remote data processing solutions** that has at least one network interface enabling data communication. This includes: |
| 29 | |
| 30 | - IoT devices (smart home, industrial sensors, wearables) |
| 31 | - Network equipment (routers, switches, firewalls, modems) |
| 32 | - Software products (operating systems, applications, games — including commercial off-the-shelf software) |
| 33 | - Mobile applications, cloud-connected products |
| 34 | - Virtualised products, containers |
| 35 | |
| 36 | **Exclusions:** Medical devices (MDR/IVDR), aviation products (EASA), automotive (type-approval), marine equipment, military/national security products, products developed for classified information. Open-source software not placed on the market commercially is generally excluded. |
| 37 | |
| 38 | ### Product Classification |
| 39 | |
| 40 | | Class | Description | Examples | Conformity Route | |
| 41 | |---|---|---|---| |
| 42 | | **Default** | All PDEs not in Class I or II | Generic IoT devices, general software, games, simple smart devices | Self-assessment (Module A) | |
| 43 | | **Class I** (Annex III) | Higher-risk products — 35 categories | Identity management software, password managers, browsers, VPNs, network monitoring tools, microcontrollers, routers for home use, smart meters, industrial automation controllers | Self-assessment OR third-party (manufacturer's choice) | |
| 44 | | **Class II** (Annex IV) | Highest-risk products — 12 categories | Hypervisors, TPMs, industrial firewalls, industrial ICS/SCADA, hardware security modules (HSMs), smart card readers, industrial robots | **Mandatory third-party** (Notified Body) | |
| 45 | |
| 46 | ### Roles and Responsibilities |
| 47 | |
| 48 | | Role | Definition | Key Obligations | |
| 49 | |---|---|---| |
| 50 | | **Manufacturer** | Designs, develops, produces, or has PDEs designed/developed/produced under their name | All Annex I requirements; vulnerability handling; incident reporting; DoC; CE marking; 10-year record-keeping | |
| 51 | | **Authorised Representative** | EU-based entity acting for a non-EU manufacturer | Holds DoC and technical documentation for authorities | |
| 52 | | **Importer** | Brings PDEs from outside the EU into the EU market | Verify manufacturer compliance; affix own name/address; notify authorities of risk; 10-year records | |
| 53 | | **Distributor** | Makes PDEs available on EU market other than manufacturer/importer | Verify CE marking and DoC; not knowingly distribute non-compliant products | |
| 54 | | **Open-Source Software Steward** | Entity that supports open-source software placed on the market commercially | Light-touch obligations; cybersecurity policy; cooperation with authorities | |
| 55 | |
| 56 | --- |
| 57 | |
| 58 | ## Skill Workflows |
| 59 | |
| 60 | ### Workflow 1 — Product Classification and Scope Assessment |
| 61 | |
| 62 | **When to use:** Determining whether a product is in scope and which class it falls into. |
| 63 | |
| 64 | **Steps:** |
| 65 | 1. Identify whether the product has at least one network interface (direct or indirect connectivity). |
| 66 | 2. Check exclusions (medical devices, aviation, automotive, military, etc.). |
| 67 | 3. Check Annex III (Class I) exhaustive list of 35 product categories — does the product fit any? |
| 68 | 4. Check Annex IV (Class I |