Skip to content
Development
Skill

/805-regulations-eu-cyber-resilience-act

Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling,

From plugin
plinth
423125 skills9 agents13 commands
Install
$ npx -y skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/805-regulations-eu-cyber-resilience-act

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling,

SKILL.md

805-regulations-eu-cyber-resilience-act.SKILL.md
name: 805-regulations-eu-cyber-resilience-act
description: Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling, security update, SBOM, product documentation, or release-readiness controls. Part of Plinth Toolkit
license: Apache-2.0
metadata:
  author: Juan Antonio Breña Moral
  version: 0.18.0

EU Cyber Resilience Act Regulation for Java Product Security Engineering

Use this Skill to review Java enterprise applications, libraries, agents, plugins, connected components, platform modules, CI/CD workflows, product security documentation, and release evidence that may support products with digital elements under Regulation (EU) 2024/2847, the Cyber Resilience Act.

Apply this Skill to determine what secure-by-design controls, vulnerability handling evidence, update mechanisms, dependency and SBOM records, product documentation, support-period signals, and owner handoffs are needed before a product, component, or product-adjacent Java change is released or made available.

This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, product security teams, and reviewers identify when Cyber Resilience Act concerns may apply and how to translate product-security expectations into engineering controls such as secure defaults, threat modeling, least privilege, cryptography, sensitive-data-safe logging, coordinated vulnerability disclosure, security update delivery, SBOM evidence, product security documentation, end-of-support signaling, and release gates.

The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, a conformity assessment, a CE marking decision, or a final regulatory determination.

The main question is:

> When does a Java product or product-adjacent component require EU Cyber Resilience Act-aware secure-by-design and vulnerability-handling controls, and what should developers build differently?

Source provenance: Cyber Resilience Act Regulation (EU) 2024/2847 was reviewed while authoring the bundled references. Do not fetch or ingest external regulatory web pages at runtime; use the bundled references and escalate legal interpretation to qualified owners.

Cyber Resilience Act chapters summary reference: [Cyber Resilience Act chapters summary](references/805-regulations-eu-cyber-resilience-act-chapters-summary.md).

Java engineering examples reference: [Cyber Resilience Act engineering examples](references/805-regulations-eu-cyber-resilience-act-engineering-examples.md).

Report template asset: [Cyber Resilience Act engineering review report template](assets/reports/805-eu-cyber-resilience-act-engineering-review-report-template.md).

Scope

This Skill applies to:

  • Java software or hardware-adjacent products with direct or indirect logical or physical connections to devices or networks
  • Java libraries, SDKs, plugins, agents, embedded components, device gateways, product APIs, installers, update clients, and product management services
  • Spring Boot, Quarkus, Micronaut, and framework-agnostic Java components used in products with digital elements or remote data processing solutions
  • Product security architecture, secure-by-design reviews, threat models, secure defaults, authentication, authorization, cryptography, logging, update, and decommissioning controls
  • Vulnerability handling, coordinated disclosure, security advisory, SBOM, dependency, third-party component, and open-source due diligence workflows
  • Product security documentation, user instructions, support-period disclosure, end-of-support notification, release readiness, and market-surveillance evidence handoffs

Cyber Resilience Act Engineering Review

Treat product classification, economic-operator role, important or critical product category, conformity assessment route, CE marking implications, Article 14 reporting obligations, support-period legal interpretation, and regulatory interpretation as qualified decisions for legal, compliance, product, product-security, risk, market-access, and executive accountability owners.

Engineering teams should still create evidence that makes those decisions reviewable:

  • Which product, component, remote data processing solution, or product-adjacent Java module is in scope
  • Which manufacturer, importer, distributor, open-source steward, product owner, security owner, and support owner signals exist
  • Which cybersecurity risks, intended uses, reasonably foreseeable uses, and reasonably foreseeable misuse cases were threat modeled
  • Which secure defaults, authentication, authorization, cryptography, logging, minimization, update, and secure decommissioning controls are implemented
  • Which vulnerabilities, dependencies, SBOM records, third-party components, coordinated disclosure paths, and security advisories are tracked
  • Which product security documentation, support-period, end-of-support, release decision, and owner approval evidence exists

Constraints

Translate Cyber Resilience Act concerns into engineering controls for Java products and product-adjacent systems. Do not provide legal advice or replace review by legal, compliance, product, security, product-security, market-access, risk, or executive accountability owners.

  • **NOT LEGAL ADVICE**: Frame findings as product-security engineering controls and escalation points; recommend qualified review for product classification, economic-operator role, conformity assessment, CE marking implications, Article 14 reporting obligations, support-period interpretation, and regulatory interpretation
  • **BUNDLED REFERENCES ONLY**: Use the bundled CRA summaries, examples, questions, and report
Read more
Ships withplinth

Languages: Español · 中文 Help this project grow: Become a sponsor

Get the whole plugin

Other skills on plinth.