From 9660724a2c69c3fab89e0629c33bbc1cb2ae0bad Mon Sep 17 00:00:00 2001
From: Benjamin Admin
Date: Sun, 14 Jun 2026 13:33:09 +0200
Subject: [PATCH] feat(cra): CRA Readiness Check lead-magnet on /sdk/cra (Track
A)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Low-friction, stateless readiness check (no project/DB): business-scope answers
(internet / parameter app / remote maintenance / updates / firmware / personal
data / critical infra) -> Annex III/IV classification (reuses _classify) + a
high-level guideline grouped Code / Prozess / Dokumentation (via Annex I
evidence_type) + conformity path + deadlines + rough effort + the "we implement"
hook and a CTA into the existing project workflow. Endpoint POST /api/v1/cra/
readiness. Reuse + reframe of the existing CRA module — no duplicate questionnaire.
Co-Authored-By: Claude Opus 4.7
---
.../sdk/cra/_components/ReadinessCheck.tsx | 152 ++++++++++++++++++
admin-compliance/app/sdk/cra/page.tsx | 3 +
.../compliance/api/cra_assess_routes.py | 63 ++++++++
.../tests/test_cra_readiness.py | 31 ++++
4 files changed, 249 insertions(+)
create mode 100644 admin-compliance/app/sdk/cra/_components/ReadinessCheck.tsx
create mode 100644 backend-compliance/tests/test_cra_readiness.py
diff --git a/admin-compliance/app/sdk/cra/_components/ReadinessCheck.tsx b/admin-compliance/app/sdk/cra/_components/ReadinessCheck.tsx
new file mode 100644
index 00000000..f788f84b
--- /dev/null
+++ b/admin-compliance/app/sdk/cra/_components/ReadinessCheck.tsx
@@ -0,0 +1,152 @@
+'use client'
+
+import { useState } from 'react'
+
+interface GuidelineItem {
+ req_id: string
+ title: string
+ category: string
+ annex_anchor: string
+ severity: string
+ effort_days?: number
+ measures: { id: string; name: string }[]
+}
+interface ReadinessResult {
+ in_scope: boolean
+ classification: string
+ rationale: string[]
+ conformity_path_hint: string
+ guideline: { code: GuidelineItem[]; process: GuidelineItem[]; document: GuidelineItem[] }
+ counts: { code: number; process: number; document: number }
+ total_effort_days: number
+ deadlines: { date: string; label: string }[]
+}
+
+const CLASS_LABEL: Record = {
+ CRITICAL: 'Kritisch', IMPORTANT_II: 'Wichtig (Klasse II)', IMPORTANT_I: 'Wichtig (Klasse I)',
+ STANDARD: 'Standard', NOT_IN_SCOPE: 'Nicht im CRA-Anwendungsbereich',
+}
+const BUCKETS: { key: 'code' | 'process' | 'document'; label: string; hint: string }[] = [
+ { key: 'code', label: 'Code / Technik', hint: 'im Produkt umzusetzen' },
+ { key: 'process', label: 'Prozesse', hint: 'organisatorisch zu etablieren' },
+ { key: 'document', label: 'Dokumentation', hint: 'nachzuweisen / beizulegen' },
+]
+
+export function ReadinessCheck({ onCreateProject }: { onCreateProject?: () => void }) {
+ const [intendedUse, setIntendedUse] = useState('')
+ const [flags, setFlags] = useState>({})
+ const [result, setResult] = useState(null)
+ const [loading, setLoading] = useState(false)
+
+ const toggle = (k: string) => setFlags((f) => ({ ...f, [k]: !f[k] }))
+
+ const run = async () => {
+ setLoading(true)
+ try {
+ const res = await fetch('/api/v1/cra/readiness', {
+ method: 'POST', headers: { 'Content-Type': 'application/json' },
+ body: JSON.stringify({ intended_use: intendedUse, ...flags }),
+ })
+ setResult(res.ok ? await res.json() : null)
+ } finally { setLoading(false) }
+ }
+
+ const QUESTIONS: { k: string; label: string }[] = [
+ { k: 'connected_to_internet', label: 'Hängt das Produkt am Internet (oder soll es)?' },
+ { k: 'user_parameter_app', label: 'Gibt es eine App, mit der Nutzer Parameter einstellen?' },
+ { k: 'remote_maintenance', label: 'Bietet ihr Fernwartung an?' },
+ { k: 'has_software_updates', label: 'Hat es Software-/Firmware-Updates?' },
+ { k: 'has_firmware', label: 'Enthält es Firmware (Embedded/IoT)?' },
+ { k: 'processes_personal_data', label: 'Verarbeitet es personenbezogene Daten?' },
+ { k: 'is_critical_infra_supplier', label: 'Wird es in kritischer Infrastruktur eingesetzt?' },
+ ]
+
+ return (
+
+
CRA-Readiness-Check
+
+ Was kommt mit dem Cyber Resilience Act auf Ihr Produkt zu? Ein paar Fragen — Sie bekommen sofort
+ eine auf Ihren Scope zugeschnittene Übersicht (Code, Prozesse, Dokumentation). Wir analysieren —
+ und setzen es mit Ihnen um.
+
+
+
+ )
+}
diff --git a/admin-compliance/app/sdk/cra/page.tsx b/admin-compliance/app/sdk/cra/page.tsx
index 69865ed2..cb9ca208 100644
--- a/admin-compliance/app/sdk/cra/page.tsx
+++ b/admin-compliance/app/sdk/cra/page.tsx
@@ -3,6 +3,7 @@
import React, { useState, useEffect, useCallback } from 'react'
import { useRouter } from 'next/navigation'
import { ClassificationBadge } from './_components/ClassificationBadge'
+import { ReadinessCheck } from './_components/ReadinessCheck'
interface CRAProject {
id: string
@@ -99,6 +100,8 @@ export default function CRAProjectsPage() {
+ setShowModal(true)} />
+
Quellen & Lizenz:
diff --git a/backend-compliance/compliance/api/cra_assess_routes.py b/backend-compliance/compliance/api/cra_assess_routes.py
index 9506cbd3..2792dbeb 100644
--- a/backend-compliance/compliance/api/cra_assess_routes.py
+++ b/backend-compliance/compliance/api/cra_assess_routes.py
@@ -18,6 +18,8 @@ from compliance.services.cra_finding_mapper import assess_findings_payload
from compliance.services.cra_snapshot_store import save_snapshot, list_snapshots, get_snapshot
from compliance.services.cra_use_case_controls import enrich_findings_with_breadth
from compliance.services.cra_component_findings import findings_from_components
+from compliance.api.cra_annex_i_data import ANNEX_I_REQUIREMENTS, MEASURES, DEADLINES
+from compliance.api.cra_routes import _classify # reuse the deterministic Annex III/IV classifier
from database import SessionLocal
from .tenant_utils import get_tenant_id
@@ -113,3 +115,64 @@ async def get_assess_snapshot(snapshot_id: str, tenant_id: str = Depends(get_ten
if not snap:
raise HTTPException(status_code=404, detail="Snapshot not found")
return snap
+
+
+# --- Lead-magnet readiness check (stateless, no project, no DB) ---
+
+class ReadinessRequest(BaseModel):
+ intended_use: Optional[str] = ""
+ connected_to_internet: Optional[bool] = False
+ has_software_updates: Optional[bool] = False
+ processes_personal_data: Optional[bool] = False
+ is_critical_infra_supplier: Optional[bool] = False
+ has_firmware: Optional[bool] = False
+ remote_maintenance: Optional[bool] = False # implies connectivity + updates
+ user_parameter_app: Optional[bool] = False # implies connectivity + updates
+
+
+# CRA Annex I evidence_type -> guideline bucket (Code / Prozess / Dokumentation).
+_GUIDELINE_BUCKET = {"code": "code", "hybrid": "code", "process": "process", "document": "document"}
+_PATH_HINT = {
+ "CRITICAL": "Konformitaet ueber benannte Stelle / EUCC (Modul H/C)",
+ "IMPORTANT_II": "Modul B+C oder harmonisierte Norm",
+ "IMPORTANT_I": "Self-Assessment bei harmonisierten Normen, sonst Modul B",
+ "STANDARD": "Self-Assessment (Modul A)",
+ "NOT_IN_SCOPE": "—",
+}
+
+
+@router.post("/readiness")
+async def readiness(body: ReadinessRequest):
+ """Low-friction CRA readiness check: business-scope answers -> Annex III/IV
+ classification + a high-level guideline grouped Code / Prozess / Dokumentation.
+ Reuses the deterministic classifier + Annex I spine. No project, no DB."""
+ intake = {
+ "intended_use": body.intended_use,
+ "connected_to_internet": bool(body.connected_to_internet or body.remote_maintenance or body.user_parameter_app),
+ "has_software_updates": bool(body.has_software_updates or body.remote_maintenance or body.user_parameter_app),
+ "processes_personal_data": bool(body.processes_personal_data),
+ "is_critical_infra_supplier": bool(body.is_critical_infra_supplier),
+ }
+ classification, rationale = _classify(intake)
+ in_scope = classification != "NOT_IN_SCOPE"
+ groups = {"code": [], "process": [], "document": []}
+ if in_scope:
+ for req in ANNEX_I_REQUIREMENTS:
+ bucket = _GUIDELINE_BUCKET.get(req.get("evidence_type", "process"), "process")
+ groups[bucket].append({
+ "req_id": req["req_id"], "title": req["title"], "category": req["category"],
+ "annex_anchor": req["annex_anchor"], "severity": req["severity"],
+ "effort_days": req.get("effort_days"),
+ "measures": [{"id": m, "name": MEASURES.get(m, m)} for m in req.get("mapped_measures", [])],
+ })
+ total_effort = sum(r["effort_days"] for g in groups.values() for r in g if r.get("effort_days"))
+ return {
+ "in_scope": in_scope,
+ "classification": classification,
+ "rationale": rationale,
+ "conformity_path_hint": _PATH_HINT.get(classification, ""),
+ "guideline": groups,
+ "counts": {k: len(v) for k, v in groups.items()},
+ "total_effort_days": total_effort,
+ "deadlines": list(DEADLINES),
+ }
diff --git a/backend-compliance/tests/test_cra_readiness.py b/backend-compliance/tests/test_cra_readiness.py
new file mode 100644
index 00000000..ca7c66cc
--- /dev/null
+++ b/backend-compliance/tests/test_cra_readiness.py
@@ -0,0 +1,31 @@
+"""Stateless CRA readiness check: scope answers -> classification + grouped guideline."""
+from fastapi import FastAPI
+from fastapi.testclient import TestClient
+from compliance.api.cra_assess_routes import router
+
+app = FastAPI()
+app.include_router(router, prefix="/api")
+client = TestClient(app)
+
+
+def test_connected_product_in_scope_with_grouped_guideline():
+ r = client.post("/api/v1/cra/readiness", json={
+ "intended_use": "App fuer Industrieanlagen", "connected_to_internet": True, "has_software_updates": True})
+ assert r.status_code == 200
+ d = r.json()
+ assert d["in_scope"] is True
+ assert d["counts"]["code"] > 0 and d["counts"]["process"] > 0 and d["counts"]["document"] > 0
+ assert d["total_effort_days"] > 0
+ assert len(d["deadlines"]) >= 1
+
+
+def test_remote_maintenance_implies_connectivity():
+ d = client.post("/api/v1/cra/readiness", json={"intended_use": "x", "remote_maintenance": True}).json()
+ assert d["in_scope"] is True
+
+
+def test_no_digital_element_not_in_scope():
+ d = client.post("/api/v1/cra/readiness", json={"intended_use": ""}).json()
+ assert d["in_scope"] is False
+ assert d["classification"] == "NOT_IN_SCOPE"
+ assert d["counts"]["code"] == 0