Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
hardware-compliance-handbook — AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and machine-readable for LLMs and agents. | Kitploit
工具/GitHubGitHub/platanor/hardware-compliance-handbook
IoT SecurityCloud SecurityHardware SecuritySupply Chain SecurityLearning & EducationCurated Resources
GitHubplatanor/hardware-compliance-handbook

hardware-compliance-handbook

AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and machine-readable for LLMs and agents.

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
3036615天前Kitploit 审核通过
内容在请求的语言中不可用。显示英文版本。

Hardware Compliance Knowledge Base

A fact-checked, open reference on the EU laws that govern hardware and IoT cybersecurity — CRA, RED, NIS2, and the Cybersecurity Act/EUCC, in one place instead of four.

License: CC BY 4.0 Regulations covered Maintained by

Prepared by Platanor Technologies (platanor.com) — an embedded security firm for IoT device manufacturers.

Contents: Quick start · What this is · Repository structure · Methodology · Using with an LLM · Claude Skill · Feedback · License · Discussions


Quick start

  • Just want an answer? Open cra/faq.md, red/faq.md, nis2/faq.md, or csa/faq.md — each is a practical Q&A for hardware/IoT manufacturers, no legal background required.
  • Working with an LLM? Drop a processed guide into your prompt and ask, e.g.: "Using cra/product-risk-classes.md and red/essential-requirements.md, does a Wi-Fi-connected baby monitor need a notified body, or can we self-assess?"
  • Need the exact legal wording? Every processed guide links back to its source in primary-sources/ — full official text, chunked by article.
  • Want this loaded automatically in Claude? See Installing this as a Claude Skill.

⚠️ Disclaimer — read before use

This is NOT legal advice. The materials in this repository are a reference knowledge base on the main pieces of EU law that touch hardware and IoT cybersecurity — the Cyber Resilience Act (Regulation (EU) 2024/2847), the Radio Equipment Directive (Directive 2014/53/EU and its cybersecurity delegated act), the NIS2 Directive (Directive (EU) 2022/2555), and the Cybersecurity Act (Regulation (EU) 2019/881, including the EUCC certification framework) — prepared to help you orient yourself in the topic, not to inform legal or compliance decisions.

  • We make an effort to keep facts accurate and checked against the primary text of each regulation (EUR-Lex), but we give no guarantee of completeness or currency — this legislation and its supporting standards (M/606, harmonised standards, delegated/implementing acts) are still under development and can change.
  • Before making any decision about your product's or organisation's compliance — consult a qualified lawyer or regulatory advisor who can assess your specific case.
  • This is a living, growing knowledge base: materials are regularly expanded, corrected, and re-verified. What is accurate today may have changed in a deadline or an interpretation — always check a file's last-verified date against the current state of the regulation.
  • Found an error or inaccuracy? We'd appreciate the feedback (see "Feedback" below).

What this is

Hardware and IoT manufacturers selling into the EU are increasingly subject to more than one regulation at once — the CRA governs the product, RED governs radio equipment specifically (with its own overlapping cybersecurity requirements), NIS2 governs certain organisations in critical sectors (including some manufacturers and their customers), and the Cybersecurity Act provides the voluntary certification framework (EUCC) that sits alongside all of them. This repository exists because treating any one of these in isolation gives an incomplete picture — a manufacturer can be in full CRA compliance and still miss a RED-specific requirement, or misjudge whether NIS2 reaches them indirectly through a customer's supply-chain obligations.

The repository has two layers:

  1. Processed guides (cra/, red/, nis2/, csa/) — shorter, structured reference documents per regulation: overview, definitions/scope, essential requirements or obligations, deadlines, penalties, and a practical FAQ. Easy to use for a quick grasp of a topic, and each one is written to flag how it relates to the other three regulations, not just to stand alone.
  2. Primary sources (primary-sources/) — the full official text of each regulation and related act, unmodified. The source of truth for exact quotes, for humans and LLMs alike.

The processed guides have been fact-checked against the primary text of each regulation and related sources (M/606, delegated/implementing acts) — methodology described below.

Repository structure

CRA — Cyber Resilience Act (Regulation (EU) 2024/2847)

FileWhat it covers
cra/overview.mdAdoption context, scope, structure of the regulation (chapters and annexes)
cra/definitions.mdOfficial definitions and terminology (product with digital elements, RDPS, critical/important product, etc.)
cra/essential-requirements.mdAnnex I essential cybersecurity requirements + status of harmonised standards development (mandate M/606); cross-referenced against ENISA's Secure by Design and Default Playbook
cra/product-risk-classes.mdProduct risk classification: Default, Important Class I/II, Critical
cra/obligations-by-role.mdManufacturer, importer, and distributor obligations (Chapter II)
cra/timeline-deadlines.mdKey deadlines and transitional provisions
cra/vulnerability-reporting.mdVulnerability and severe-incident reporting (Article 14)
cra/penalties-enforcement.mdPenalties and market surveillance
cra/self-assessment-maturity-model.mdENISA SME Cyber Resilience Maturity Assessment Model
cra/faq.mdPractical FAQ for hardware/IoT manufacturers

RED — Radio Equipment Directive (2014/53/EU + cybersecurity delegated act)

下载工具