# EU Cyber Resilience Act Classification (T0.10)

## Classification

cubie-eu is classified as **Annex IV (Critical) per CRA**, on the grounds that
it implements a Trusted Execution Environment integration and a hardware-rooted
attestation chain for AI inference. TEE implementations are explicitly listed
in Annex IV.

## Implications

- Third-party conformity assessment required (NOT self-assessment).
- Notified body engagement for cybersecurity (separate from EU AI Act notified
  body for Annex VII).
- CRA Annex I essential cybersecurity requirements apply in full.
- Vulnerability handling per CRA Annex I Part II (see `SECURITY.md`).

## Status

- [ ] CRA notified body identified (may be same body as EU AI Act Annex VII)
- [ ] CRA Annex II risk assessment documented
- [ ] CRA technical documentation drafted (separate from EU AI Act Annex IV)
- [ ] DoC signed (see `docs/declaration-of-conformity-template.md`)
- [ ] CE marking applied (CRA distinct from EU AI Act)
