1

    Cra Readiness Auditor

    Automated EU Cyber Resilience Act (CRA) auditing, SBOM generation, and compliance documentation for software repos.

    Updated Jun 2026
    Security scanned

    $99

    · or 495 credits

    30-day refund guarantee

    Secure checkout via Stripe

    Included in download

    • Generate CycloneDX 1.5 SBOMs from project manifests automatically
    • Map repository security gaps to specific EU CRA Articles and Annexes
    • terminal automation included
    • Instant install

    Sample input

    Perform a CRA readiness audit on my current repository and generate the required SBOM and incident runbooks.

    Sample output

    ### CRA Audit Summary **Location:** `/cra-readiness/` - **SBOM:** `sbom.cdx.json` (CycloneDX 1.5) - **Status:** 12 Met, 5 Open, 2 Partial - **Top Gaps:** Missing 24h ENISA notification procedure, Technical Doc skeleton incomplete. *This is a readiness aid and does not constitute legal advice.*

    About This Skill

    Audit Your Software for EU CRA Compliance

    The Cyber Resilience Act (CRA) introduces strict cybersecurity requirements for software products in the EU market, starting September 2026. This skill automates the complex task of auditing your repository against these specific legal obligations, saving developers and legal teams weeks of manual mapping.

    What it does

    This skill performs a comprehensive scan of your repository to extract dependency data, security policies, and update mechanisms. It then generates the exact artifacts required for CRA compliance:

    • CycloneDX SBOM: An industry-standard software bill of materials (v1.5).
    • Readiness Report: A detailed audit mapping your repo to specific CRA articles and essential requirements.
    • Compliance Templates: Ready-to-use vulnerability disclosure policies (SECURITY.md) and incident response runbooks mapped to ENISA's 24-hour reporting duty.
    • Technical Documentation: A structured skeleton for the required CRA technical dossiers.

    Why use this skill?

    Unlike generic vulnerability scanners, this tool is specifically tuned to the legal text of the Cyber Resilience Act. It doesn't just find bugs; it identifies gaps in your compliance framework—such as missing incident notification paths or insufficient update documentation—that carry significant regulatory risk.

    Supported Environments

    The auditor supports all major package managers including npm, pip/poetry, go-mod, and cargo. It operates entirely locally for privacy, with an optional path for online vulnerability enrichment.

    Use Cases

    • Generate CycloneDX 1.5 SBOMs from project manifests automatically
    • Map repository security gaps to specific EU CRA Articles and Annexes
    • Create ENISA-compliant 24-hour incident reporting runbooks
    • Generate technical documentation skeletons required for EU market entry
    • Prepare software products for the September 2026 CRA enforcement date

    Reviews

    No reviews yet - be the first to share your experience.

    Only users who have downloaded or purchased this skill can leave a review.

    Security Scanned

    Passed automated security review

    Permissions

    Terminal / Shell

    File Scopes

    cra-readiness-auditor/**

    Frequently Asked Questions