If you're shipping hardware or software into the EU and it connects to a network, you need to know about the Cyber Resilience Act, and this skill walks you through the compliance maze. It helps you figure out if your product is a PDE, whether it's Default, Class I, or Class II (which determines if you need a notified body), and what you actually have to do for conformity assessment and CE marking. The gap analysis workflow against Annex I requirements is solid, covering everything from secure-by-default configs to the 24-hour vulnerability reporting obligations to ENISA. The regulation goes into full effect December 2027, so if you're a manufacturer, importer, or distributor, you've got time to get your SBOM and vulnerability handling processes sorted.
npx -y skills add sushegaad/claude-skills-governance-risk-and-compliance --skill eu-cra --agent claude-codeInstalls into .claude/skills of the current project.
Select a file.
hoodini/ai-agents-skills
addyosmani/agent-skills
giuseppe-trisciuoglio/developer-kit
agamm/claude-code-owasp