← MCP Scorecard

Best Security & Supply Chain MCP Servers (2026)

14 servers, ranked on the proofof.ai 100-point production-readiness rubric. Updated 2026-06-07.

What are the best Security & Supply Chain MCP servers?

The highest-scored are cisa-kev-mcp (90/100), cra-compliance-mcp (90/100), credential-manager-mcp (90/100). Full ranking below — each links to its detailed scorecard.

#MCP serverScoreWhat it doesInstall
1cisa-kev-mcp90CISA Known Exploited Vulnerabilities feed + remediation deadlines for US federal + criticapip install cisa-kev-mcp
2cra-compliance-mcp90EU Cyber Resilience Act (Regulation 2024/2847) compliance for AI agents. Product classificpip install cra-compliance-mcp
3credential-manager-mcp90Credential Manager MCP Server by MEOK AI Labspip install credential-manager-mcp
4meok-c2pa-durable-mcp90MEOK C2PA Durable Content Credentials MCP — C2PA 2.2 with soft + hard binding (Digimarc-copip install meok-c2pa-durable-mcp
5meok-cra-annex-iv-classifier-mcp90EU Cyber Resilience Act product classifier MCP. Classifies PDEs into CRA hierarchy (defaulpip install meok-cra-annex-iv-classifier-mcp
6meok-cra-art14-reporter-mcp90MEOK CRA Article 14 Reporter MCP — actively-exploited-vulnerability notification with 24h/pip install meok-cra-art14-reporter-mcp
7mitre-atlas-mcp90MITRE ATLAS — Adversarial Threat Landscape for AI Systems. Tactics + techniques for attackpip install mitre-atlas-mcp
8mitre-attack-mcp90MITRE ATT&CK matrix lookup, tactic/technique/sub-technique mapper, and incident-to-techniqpip install mitre-attack-mcp
9sbom-cyclonedx-mcp90Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. pip install sbom-cyclonedx-mcp
10sigstore-cosign-mcp90Sigstore cosign + rekor transparency log verification for signed container images + git tapip install sigstore-cosign-mcp
11slsa-supply-chain-mcp90SLSA (Supply chain Levels for Software Artifacts) v1.0 framework. Compute SLSA level + rempip install slsa-supply-chain-mcp
12trust-chain-mcp90Trust Chain MCP server. Tools: create trust anchor, verify chain, add attestation. Built bpip install trust-chain-mcp
13firmware-attestation-mcp88Firmware Attestation MCP — hardware trust layer for sovereign AI. Scan firmware, checkpip install firmware-attestation-mcp
14supply-chain-mcp86Supply chain management and logistics tools for AI agents. Capabilities: shipment trackingpip install supply-chain-mcp

How are these scored?

Each MCP server is scored 0-100 across 10 categories (README, tool design, examples, tests/CI, transports, metadata, reliability, security, docs, provenance). See the methodology.