From b0f78ae9a3951980643d25604cabff2a7cf2ec0b Mon Sep 17 00:00:00 2001 From: Benjamin Admin Date: Sun, 14 Jun 2026 14:26:08 +0200 Subject: [PATCH] feat(cra): readiness derives obligations from Machinery Reg 2023/1230 too MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Machine/plant builders are hit by BOTH the CRA and the new Machinery Regulation. New machinery_reg_cyber.py models its two well-corroborated Annex III cyber-with- safety essential requirements (1.1.9 protection against corruption, 1.2.1 control- system safety incl. foreseeable manipulation) in our own words; EU legal text is freely reusable (Commission Decision 2011/833/EU, source acknowledged), harmonised standards referenced by identifier only. The readiness check asks "is it machinery?" and, if so, adds these obligations tagged "Maschinen-VO" alongside the CRA ones — the combination is visible (regulations list + per-item source badge). Co-Authored-By: Claude Opus 4.7 --- .../sdk/cra/_components/ReadinessCheck.tsx | 12 +++++ .../compliance/api/cra_assess_routes.py | 17 +++++++ .../compliance/api/machinery_reg_cyber.py | 50 +++++++++++++++++++ .../tests/test_cra_readiness.py | 10 ++++ 4 files changed, 89 insertions(+) create mode 100644 backend-compliance/compliance/api/machinery_reg_cyber.py diff --git a/admin-compliance/app/sdk/cra/_components/ReadinessCheck.tsx b/admin-compliance/app/sdk/cra/_components/ReadinessCheck.tsx index 379f961d..00324f1d 100644 --- a/admin-compliance/app/sdk/cra/_components/ReadinessCheck.tsx +++ b/admin-compliance/app/sdk/cra/_components/ReadinessCheck.tsx @@ -10,12 +10,14 @@ interface GuidelineItem { severity: string effort_days?: number measures: { id: string; name: string }[] + source?: string } interface ReadinessResult { in_scope: boolean classification: string rationale: string[] conformity_path_hint: string + regulations: string[] guideline: { code: GuidelineItem[]; process: GuidelineItem[]; document: GuidelineItem[] } counts: { code: number; process: number; document: number } total_effort_days: number @@ -52,6 +54,7 @@ export function ReadinessCheck({ onCreateProject }: { onCreateProject?: () => vo } const QUESTIONS: { k: string; label: string }[] = [ + { k: 'is_machinery', label: 'Ist es eine Maschine/Anlage (CE nach Maschinenrecht)?' }, { k: 'connected_to_internet', label: 'Hängt das Produkt am Internet (oder soll es)?' }, { k: 'user_parameter_app', label: 'Gibt es eine App, mit der Nutzer Parameter einstellen?' }, { k: 'remote_maintenance', label: 'Bietet ihr Fernwartung an?' }, @@ -110,6 +113,12 @@ export function ReadinessCheck({ onCreateProject }: { onCreateProject?: () => vo · Konformität: {result.conformity_path_hint} +
+ Betroffene Verordnungen: + {result.regulations.map((r) => ( + {r} + ))} +

{result.counts.code + result.counts.process + result.counts.document} Pflichten · grobe Schätzung ~{result.total_effort_days} Personentage. Das ist ein Überblick zur Klärung — keine Rechtsberatung. @@ -124,6 +133,9 @@ export function ReadinessCheck({ onCreateProject }: { onCreateProject?: () => vo