CRA Compliance MCP
<!-- mcp-name: io.github.CSOAI-ORG/cra-compliance-mcp -->
> ### ๐ Free tier: 50 calls/day. Need audit-ready proof?
> **Pro (ยฃ199/mo)** turns every result into an **HMAC-signed attestation** with a **public verify URL**
> your auditor validates without an account โ EU AI Act Art 11/12 ready.
> โ Start: **https://proofof.ai** ยท `pip install meok-attestation-verify` to verify any cert.
[](https://proofof.ai/scorecard/cra-compliance-mcp.html)
# Cra Compliance MCP
[](https://meok.ai)
[](https://councilof.ai/payg)
[](https://councilof.ai/api/gspc)
[](LICENSE)
[](https://pypi.org/project/cra_compliance_mcp/)
> EU Cyber Resilience Act (Reg 2024/2847) compliance MCP for products with digital elements
EU Cyber Resilience Act (Reg 2024/2847) compliance MCP for products with digital elements. CE marking, vulnerability disclosure, SBOM. MIT
---
## ๐ Quick Start
```bash
# Install via pip
pip install cra_compliance_mcp
# Or install via Smithery
npx -y @smithery/cli@latest install cra-compliance-mcp --client claude
```
## โก Pay-per-call (PAYG) โ no subscription
This MCP supports universal pay-per-call billing across the MEOK compliance fleet:
```bash
# One-time setup
export MEOK_PAYG_KEY="your_topup_token"
# Every tool call now deducts ยฃ0.05 from your balance.
# When balance hits zero, the tool returns a top-up URL.
# Works across all 7 MEOK compliance MCPs with the same token.
```
- **No subscription** โ top up once, deduct per call.
- **ยฃ0.05/call default** (configurable via `MEOK_PAYG_RATE_GBP`).
- **USDC on Base L2 accepted** โ set `MEOK_X402_RECEIVER` and pay via stablecoin.
- **Backward-compatible** โ when `MEOK_PAYG_KEY` is unset, behaviour is unchanged.
**Get a token**: [councilof.ai/payg](https://councilof.ai/payg) (ยฃ10 / ยฃ50 / ยฃ200 top-up tiers).
## โจ Features
- MCP protocol compliant
- Easy installation
- Well-documented API
- Production-ready
- Active maintenance
## ๐ Documentation
- [Full Documentation](https://docs.meok.ai/cra-compliance-mcp)
- [API Reference](https://meok-attestation-api.vercel.app)
- [EU AI Act Compliance Guide](https://councilof.ai)
## ๐ก๏ธ Compliance
This MCP server is built with **EU AI Act compliance** built-in:
- โ
Article 9 โ Risk Management System
- โ
Article 13 โ Transparency & Instructions for Use
- โ
Article 15 โ Bias Detection & Testing
- โ
Article 26 โ FRIA Support (where applicable)
- โ
Article 50 โ AI Content Watermarking (where applicable)
Need help getting compliant? **[Book a free 15-min diagnostic โ](mailto:nicholas@meok.ai?subject=Compliance%20diagnostic)**
## ๐ข Enterprise
Need custom development, SLA guarantees, or white-label deployment?
- **Pro:** ยฃ79/mo โ Full MCP suite + EU AI Act tracking
- **Enterprise:** ยฃ499/mo โ Custom dev + SLA + Dedicated support
[View Pricing โ](https://councilof.ai/payg) | [Contact Sales โ](mailto:sales@meok.ai)
## ๐ค Part of the MEOK Ecosystem
This server is part of the **[MEOK AI Labs](https://meok.ai)** ecosystem โ 26 PyPI packages ยท ~16,300 monthly installs.
| Domain | Purpose |
|--------|---------|
| [councilof.ai](https://councilof.ai) | EU AI Act compliance marketplace |
| [safetyof.ai](https://safetyof.ai) | AI safety & monitoring |
| [meok.ai](https://meok.ai) | Sovereign AI platform |
| [cobolbridge.ai](https://cobolbridge.ai) | Legacy modernization |
## ๐ License
MIT ยฉ [CSOAI-ORG](https://github.com/CSOAI-ORG)
---
<p align="center">
<sub>Built with ๐ by <a href="https://meok.ai">MEOK AI Labs</a> ยท UK Companies House 16939677</sub>
</p>
## Configuration
Add to your `claude_desktop_config.json` (Claude Desktop) or your MCP client config:
```json
{
"mcpServers": {
"cra-compliance-mcp": {
"command": "uvx",
"args": ["cra-compliance-mcp"]
}
}
}
```
Or: `pip install cra-compliance-mcp` then run the `cra-compliance-mcp` command (stdio transport).
## Examples
Once configured, ask your assistant, for example:
- "Use `classify_product` to โฆ"
- "Use `audit_annex_i` to โฆ"
- "Use `sbom_skeleton` to โฆ"
TDQS
Scored across 7 tools
Each tool serves a distinct compliance function (audit, classification, roadmap, timeline, SBOM, attestation, reporting readiness) with no overlapping purposes, making it easy for agents to select the correct tool.
All names use underscore_separated words but mix verb-noun (e.g., audit_annex_i) and noun-noun patterns (e.g., enforcement_status, sbom_skeleton), showing moderate inconsistency.
7 tools is appropriate for a compliance server covering classification, auditing, roadmap, timelines, SBOM, attestation, and reporting readiness without being overwhelming or insufficient.
The tool set covers the main CRA requirements (classification, auditing, roadmap, enforcement info, SBOM, attestation, reporting readiness). A minor gap is the lack of a dedicated vulnerability handling audit tool, but Annex I audit covers it partially.