Assess the EU CRA (Regulation 2024/2847) Annex I essential requirements subset: machine-readable SBOM, top-level dependency coverage, vulnerability handling policy, secure-by-default, and selected conformity route. Outputs gaps list and route verdict. Second node of the cra-product-conformance chain.
EU CRA 2024/2847Annex IConformity AssessmentFull applicability Dec 2027W3C VC §13.11PDF ExportZero PII
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Scope
Second node of the cra-product-conformance chain (art-138→139→140). Assesses the CRA Annex I essential requirements checklist for a product: is an SBOM present and machine-readable, do top-level dependencies appear in the SBOM, is there a vulnerability handling policy, is the product secure by default, and has a valid conformity route been selected. Penalty for non-compliance: up to €15M or 2.5% of global annual turnover. Full applicability 11 Dec 2027; vulnerability reporting (Article 14) applies from 11 Sep 2026.
Pass the execution_hash above as parent_hashes[1] when calling assess_cra_vuln_reporting_readiness (art-140) to complete the cra-product-conformance chain.
Ask your agent
Copy this paragraph into Claude, OpenClaw, or any MCP-aware agent to run this exact tool, with this sample, and verify the artifact.
Run the AINumbers MCP tool `check_cra_annex1_completeness`. Task: Check EU CRA (Regulation 2024/2847) Annex I essential requirements: sbom_present, sbom_machine_readable, top_level_deps_covered, vuln_handling_policy_present, secure_by_default, and conformity_route (self_assessment/eu_type_examination/full_quality_assurance).
Call it with arguments: {"policy_parameters":{"sbom_present":true,"sbom_machine_readable":true,"top_level_deps_covered":true,"vuln_handling_policy_present":true,"secure_by_default":true,"conformity_route":"self_assessment"}}
Verify before trusting: call `verify_execution_hash` on mcp.ainumbers.co (https://mcp.ainumbers.co/mcp) with the parameter `claimed_hash` set to the returned `execution_hash`, passing the full artifact the run returned (the object containing `policy_parameters` + `output_payload` + `execution_hash`; equivalently `policy_parameters` + `output_payload` with `claimed_hash`), not the bare hash string, or re-run the in-page WebMCP tool `check_cra_annex1_completeness`.
Return the ledger link https://ledger.ainumbers.co/ so a human can re-verify without contacting us.
PII rule: All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Open the tool with the sample prefilled: https://ainumbers.co/chaingraph/art-139-cra-annex1-completeness-checker.html#p=v1.H4sIAAAAAAAA_wGyAE3_eyJzYm9tX3ByZXNlbnQiOnRydWUsInNib21fbWFjaGluZV9yZWFkYWJsZSI6dHJ1ZSwidG9wX2xldmVsX2RlcHNfY292ZXJlZCI6dHJ1ZSwidnVsbl9oYW5kbGluZ19wb2xpY3lfcHJlc2VudCI6dHJ1ZSwic2VjdXJlX2J5X2RlZmF1bHQiOnRydWUsImNvbmZvcm1pdHlfcm91dGUiOiJzZWxmX2Fzc2Vzc21lbnQifdCYO66yAAAA