| name | arckit-eu-cra |
| title | User Input |
| description | [COMMUNITY] Assess EU Cyber Resilience Act (CRA, Regulation 2024/2847) compliance obligations for products with digital elements placed on the EU market |
| author | tractorjuice |
| author_url | https://github.com/tractorjuice/arc-kit/tree/main/arckit-codex/skills/arckit-eu-cra |
| license | MIT |
| version | 0.1.1 |
| execution_mode | open |
| jurisdiction | eu |
| practice | cybersecurity |
| language | en |
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified DPO / RSSI / legal counsel before reliance. Citations to ANSSI / CNIL / EU regulations may lag the current text — verify against the source.
You are helping an enterprise architect generate a EU Cyber Resilience Act (CRA) Compliance Assessment (Regulation EU 2024/2847) for a product with digital elements (software or hardware) placed or made available on the EU market. The CRA entered into force December 2024, with full obligations applying by 11 December 2027.
User Input
$ARGUMENTS
Instructions
Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.
Step 0: Read existing artifacts from the project context
MANDATORY (warn if missing):
- REQ (Requirements) — Extract: product functional requirements, security requirements (NFR-SEC-xxx), software update requirements, vulnerability management requirements, SBOM requirements
- If missing: warn that CRA scoping and classification require a clear product description
RECOMMENDED (read if available, note if missing):
- RISK (Risk Register) — Extract: security risks, vulnerability risks, third-party component risks, supply chain risks
- SECD (Secure by Design) — Extract: existing security controls, secure development practices, vulnerability handling procedures already in place
- PRIN (Architecture Principles, 000-global) — Extract: secure-by-default principles, software bill of materials policy, disclosure policy
OPTIONAL (read if available, skip silently):
- DATA (Data Model) — Extract: data processed by the product (personal data triggers GDPR intersection)
- NIS2 (NIS2 Assessment) — Extract: if product is used by NIS2-scoped operators, CRA incident reporting overlaps with NIS2
Step 0b: Read external documents and policies
- Read any external documents in — extract existing vulnerability disclosure policies, CE marking documentation, SBOM files, ANSSI correspondence, existing conformity assessment documentation