Independent information resource Product security · EU CRA
CRA and overlapping EU regulation / 12

How to Coordinate CRA Conformity Assessment With Other EU Product Legislation

A practical guide to coordinating Cyber Resilience Act conformity assessment with other EU product legislation, including product classification, parallel conformity routes, notified bodies, standards, testing, CE marking and the single EU declaration of conformity.

IN BRIEF

Start by mapping every applicable Union act and its conformity route. Then align product versions, evidence baselines, standards, testing, notified-body interactions and change-control milestones. Reuse evidence where it genuinely demonstrates more than one requirement, but do not assume a pass under another product law establishes CRA conformity. CRA Article 28 requires a single EU declaration of conformity where the product is subject to more than one Union act requiring such a declaration.

01 / 12

Map Every Applicable Union Act Before Selecting a Conformity Route

Coordination should begin with a product-level applicability matrix. Identify the CRA and every other Union product law that applies, the product version and intended purpose covered, the essential requirements, the conformity procedure and the responsible internal owner. This prevents teams from discovering late that one law requires a different assessment route or additional third-party involvement.

02 / 12

Keep CRA Classification Separate From Classification Under Other Product Laws

CRA classification determines which Article 32 conformity routes are available for the product with digital elements. Another product law can use its own classes, categories, risk levels or modules. Record each classification independently even when the same product appears in several regulatory systems.

03 / 12

Select the Legally Available Conformity Procedure Under Each Act

The CRA provides internal control, EU-type examination followed by conformity to type, and full quality assurance routes subject to the conditions in Article 32. Other Union acts may prescribe different modules or conditions. A combined project plan can coordinate the work, but the selected procedure must remain legally valid under each act.

04 / 12

Coordinate Notified Bodies Without Assuming One Appointment Covers Everything

Where several laws require notified-body involvement, check the notified scope of each body. A body competent for one regulation, module or product category is not automatically notified for CRA work or another Union act. Where practical, a manufacturer can choose a body with multiple relevant notifications, but the legal competence should be verified separately.

05 / 12

Build One Evidence Architecture With Law-Specific Requirement Mapping

Architecture diagrams, product specifications, software inventories, risk analyses, test reports and change records can often support several conformity workstreams. Store them once where practical, then map each item to the specific CRA requirement and the specific requirement under the other applicable law. Shared evidence should reduce duplication without obscuring legal traceability.

06 / 12

Coordinate Testing Around Common Product Baselines

Testing is easier to reuse when all teams assess the same controlled hardware, firmware, software and remote-service baseline. Align test plans and release candidates so cybersecurity, safety, radio, machinery or other product testing does not rely on inconsistent product versions. Where one test supports several requirements, document the scope and limits of that reuse.

07 / 12

Use Harmonised Standards Only for the Requirements They Actually Cover

A harmonised standard can create a presumption of conformity only for the requirements and legal act covered by its citation and scope. A standard used in another Union regime may still provide useful technical evidence for CRA work, but it should not be treated as creating CRA presumption of conformity unless the CRA legal conditions are satisfied.

08 / 12

Coordinate Technical Documentation but Preserve Act-Specific Content

Manufacturers can maintain one controlled technical-documentation system with shared product evidence and law-specific sections or mappings. The CRA Annex VII content still needs to be identifiable, just as documentation required under another Union act must remain complete and reviewable for that act.

09 / 12

Use One EU Declaration Where Several Applicable Acts Require It

CRA Article 28(3) requires a single EU declaration of conformity where the product is subject to more than one Union legal act requiring such a declaration. The declaration must identify the Union acts concerned, including their publication references. The single declaration can therefore consolidate the formal declaration while the underlying conformity work remains act-specific.

10 / 12

Understand What the CE Mark Represents

Where several applicable Union harmonisation acts require CE marking, the CE mark represents the manufacturer's declaration that the product conforms to all applicable acts requiring that marking. It does not mean that all assessments used one procedure, one standard or one notified body.

11 / 12

Coordinate Findings and Corrective Actions Across Workstreams

A cybersecurity test failure can affect CRA evidence and may also affect safety or other product requirements. Use a shared corrective-action process that identifies every affected legal requirement and prevents one team from closing a finding while another regulatory consequence remains unresolved.

12 / 12

Use Change Control to Reopen Every Affected Conformity Decision

Software updates, new remote services, hardware revisions and major design changes can affect several conformity files at once. Change control should identify which legal acts, risk assessments, tests, declarations and notified-body interactions need review rather than treating each regulation as an isolated post-market process.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.