CRA Readiness Audit for EU Cyber Resilience Act
Flags the lines in your repo that break the EU Cyber Resilience Act - default passwords, disabled TLS checks, floating base images, an expired security.txt - naming the Annex each one fails.
Install
npx @readystack/cra-readiness-audit file
Node 18+. The same 28 rules as the VS Code extension, from a terminal or CI.
Free
- Check the open file against all 28 rules; Check only the lines you select; Reopen the last findings, with line numbers and severity; Read every rule that ships inside, with its Annex reference
--rules lists every rule
With a licence ($29 once)
- Check every file in the repository; Findings report as CSV, JSON or HTML; JSON output a build step can fail on
@readystack/cra-readiness-audit --dir ./templates --report html --out report.html
Blended EU engineering-and-consulting effort on CRA work is estimated at EUR 45 an hour, and the cheapest tooled route published runs EUR 4,000 per project per year.
Use from an AI agent (MCP)
Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:
{ "mcpServers": { "cra-readiness-audit": { "command": "npx", "args": ["-y", "@readystack/cra-readiness-audit", "--mcp"] } } }
Tools: check_text and check_file (free) · check_dir (licence; the full sweep is free for 7 days). The agent gets every finding with the line number.
Use in CI
- name: CRA Readiness Audit for EU Cyber Resilience Act
run: npx -y @readystack/cra-readiness-audit --dir . --ci
(container: docker run --rm -v "$PWD:/work" getreadystack/cra-readiness-audit --dir /work --ci)
Try the full run free for 7 days — no key needed. Then one licence, 7-day refund, no questions. Set READYSTACK_LICENSE=<key> or run --license <key> once.
Get a licence