Server data from the Official MCP Registry
EU Cyber Resilience Act product classifier MCP. Classifies PDEs into CRA hierarchy (default / Cla...
EU Cyber Resilience Act product classifier MCP. Classifies PDEs into CRA hierarchy (default / Cla...
This MCP provides EU CRA product classification tools with reasonable architecture but exhibits several security concerns that should be addressed. The server implements tier-based access control (free/pro/enterprise) but lacks robust input validation, contains an SSRF mitigation pattern that is incomplete, and the remote attestation API integration could leak sensitive audit data. Token handling via environment variables is appropriate, but the code lacks comprehensive error handling and input sanitization on user-supplied classification data. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
3 files analyzed · 13 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-csoai-org-meok-cra-annex-iv-classifier-mcp": {
"args": [
"meok-cra-annex-iv-classifier-mcp"
],
"command": "uvx"
}
}
}From the project's GitHub README.
The EU Cyber Resilience Act (Reg 2024/2847) Annex IV defines essential security requirements across nine categories that every product with digital elements sold in the EU must meet — including AI-embedded products. Most teams treat CRA as 'something the security team handles next year'. That's a mistake: the conformity self-assessment + technical-documentation requirements are non-trivial, and the penalties (up to €15M or 2.5% of global turnover) are real.
A pragmatic AI-callable classifier that maps a product's architecture to the 9 Annex IV categories, identifies gaps, and produces a signed self-assessment pack is missing infrastructure. This MCP fills that gap.
An IoT manufacturer with EU sales prepared their CRA conformity self-assessment ahead of the December 2027 application date. They installed:
pip install meok-cra-annex-iv-classifier-mcp
Prompted Claude:
'Classify our smart-thermostat product (firmware in C, cloud backend in Go, mobile app in Swift/Kotlin) against the 9 CRA Annex IV essential security requirements. Identify gaps. Produce a signed self-assessment pack ready for our notified body.'
Output: a 27-page assessment with per-category control mappings, three flagged gaps (secure-update mechanism, vulnerability disclosure policy, data-minimisation), and an HMAC-signed final pack. Saved roughly £18K of external consultancy that would otherwise have been booked for the same deliverable.
EU Cyber Resilience Act product classifier — Annex III + Annex IV designations + Annex I requirements audit + signed certificates.
Classifies products with digital elements (PDEs) into the CRA hierarchy. Built for the 11 Dec 2027 full-applicability deadline (vulnerability + serious-incident reporting already in force from Sept 2026).
By MEOK AI Labs.
Implementing Regulation (EU) 2025/2392 (adopted late November 2025) just designated the first set of Class I, Class II, and Annex IV product categories. IoT vendors, chipmakers, smart-meter manufacturers, OT teams need a defensible classification NOW — every classification you delay is conformity work you'll pay for retroactively.
classify_product — heuristic classification by description + characteristicsaudit_essential_requirements — score against 15 Annex I cybersecurity requirementsgenerate_doc_template — Annex VIII technical documentation skeletonsign_classification_cert — Pro: HMAC-SHA256 signed classification cert with public verify URLpip install meok-cra-annex-iv-classifier-mcp
Use code MEOKEAT for 25% off the first 3 months.
cra-compliance-mcp — full CRA compliance auditai-bom-mcp — SBOM generation for Annex VIIImeok-attestation-verify — verify signed certsMIT — MEOK AI Labs, 2026.
pip install meok-cra-annex-iv-classifier-mcp (this package)Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
by mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
by Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
by mcp-marketplace · Developer Tools
Scaffold, build, and publish TypeScript MCP servers to npm — conversationally
by Taylorwilsdon · Productivity
Control Gmail, Calendar, Docs, Sheets, Drive, and more from your AI