Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
hardware-compliance-handbook — AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and machine-readable for LLMs and agents. | Kitploit
Ferramentas/GitHubGitHub/platanor/hardware-compliance-handbook
IoT SecurityCloud SecurityHardware SecuritySupply Chain SecurityLearning & EducationCurated Resources
GitHubplatanor/hardware-compliance-handbook

hardware-compliance-handbook

AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and machine-readable for LLMs and agents.

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Ver Repositório
30366há 16 diasRevisado pelo Kitploit
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

Hardware Compliance Knowledge Base

A fact-checked, open reference on the EU laws that govern hardware and IoT cybersecurity — CRA, RED, NIS2, and the Cybersecurity Act/EUCC, in one place instead of four.

License: CC BY 4.0 Regulations covered Maintained by

Prepared by Platanor Technologies (platanor.com) — an embedded security firm for IoT device manufacturers.

Contents: Quick start · What this is · Repository structure · Methodology · Using with an LLM · Claude Skill · Feedback · License · Discussions


Quick start

  • Just want an answer? Open cra/faq.md, red/faq.md, nis2/faq.md, or csa/faq.md — each is a practical Q&A for hardware/IoT manufacturers, no legal background required.
  • Working with an LLM? Drop a processed guide into your prompt and ask, e.g.: "Using cra/product-risk-classes.md and red/essential-requirements.md, does a Wi-Fi-connected baby monitor need a notified body, or can we self-assess?"
  • Need the exact legal wording? Every processed guide links back to its source in primary-sources/ — full official text, chunked by article.
  • Want this loaded automatically in Claude? See Installing this as a Claude Skill.

⚠️ Disclaimer — read before use

This is NOT legal advice. The materials in this repository are a reference knowledge base on the main pieces of EU law that touch hardware and IoT cybersecurity — the Cyber Resilience Act (Regulation (EU) 2024/2847), the Radio Equipment Directive (Directive 2014/53/EU and its cybersecurity delegated act), the NIS2 Directive (Directive (EU) 2022/2555), and the Cybersecurity Act (Regulation (EU) 2019/881, including the EUCC certification framework) — prepared to help you orient yourself in the topic, not to inform legal or compliance decisions.

  • We make an effort to keep facts accurate and checked against the primary text of each regulation (EUR-Lex), but we give no guarantee of completeness or currency — this legislation and its supporting standards (M/606, harmonised standards, delegated/implementing acts) are still under development and can change.
  • Before making any decision about your product's or organisation's compliance — consult a qualified lawyer or regulatory advisor who can assess your specific case.
  • This is a living, growing knowledge base: materials are regularly expanded, corrected, and re-verified. What is accurate today may have changed in a deadline or an interpretation — always check a file's last-verified date against the current state of the regulation.
  • Found an error or inaccuracy? We'd appreciate the feedback (see "Feedback" below).

What this is

Hardware and IoT manufacturers selling into the EU are increasingly subject to more than one regulation at once — the CRA governs the product, RED governs radio equipment specifically (with its own overlapping cybersecurity requirements), NIS2 governs certain organisations in critical sectors (including some manufacturers and their customers), and the Cybersecurity Act provides the voluntary certification framework (EUCC) that sits alongside all of them. This repository exists because treating any one of these in isolation gives an incomplete picture — a manufacturer can be in full CRA compliance and still miss a RED-specific requirement, or misjudge whether NIS2 reaches them indirectly through a customer's supply-chain obligations.

The repository has two layers:

  1. Processed guides (cra/, red/, nis2/, csa/) — shorter, structured reference documents per regulation: overview, definitions/scope, essential requirements or obligations, deadlines, penalties, and a practical FAQ. Easy to use for a quick grasp of a topic, and each one is written to flag how it relates to the other three regulations, not just to stand alone.
  2. Primary sources (primary-sources/) — the full official text of each regulation and related act, unmodified. The source of truth for exact quotes, for humans and LLMs alike.

The processed guides have been fact-checked against the primary text of each regulation and related sources (M/606, delegated/implementing acts) — methodology described below.

Repository structure

CRA — Cyber Resilience Act (Regulation (EU) 2024/2847)

FileWhat it covers
cra/overview.mdAdoption context, scope, structure of the regulation (chapters and annexes)
cra/definitions.mdOfficial definitions and terminology (product with digital elements, RDPS, critical/important product, etc.)
cra/essential-requirements.mdAnnex I essential cybersecurity requirements + status of harmonised standards development (mandate M/606); cross-referenced against ENISA's Secure by Design and Default Playbook
cra/product-risk-classes.mdProduct risk classification: Default, Important Class I/II, Critical
cra/obligations-by-role.mdManufacturer, importer, and distributor obligations (Chapter II)
cra/timeline-deadlines.mdKey deadlines and transitional provisions
cra/vulnerability-reporting.mdVulnerability and severe-incident reporting (Article 14)
cra/penalties-enforcement.mdPenalties and market surveillance
cra/self-assessment-maturity-model.mdENISA SME Cyber Resilience Maturity Assessment Model
cra/faq.mdPractical FAQ for hardware/IoT manufacturers

RED — Radio Equipment Directive (2014/53/EU + cybersecurity delegated act)

Baixar ferramenta