Independent information resource Product security · EU CRA
Conformity assessment and CE marking

CRA Conformity Assessment and CE Marking

Understand Cyber Resilience Act conformity assessment and CE marking, including Article 32 procedures, Module A self-assessment, Module B plus C, Module H, important and critical product rules, technical documentation, the EU declaration of conformity and CE marking.

IN BRIEF

Most products with digital elements can use manufacturer self-assessment through Module A. Important class I products can use self-assessment only when the Article 32 conditions allow it. Important class II products require Module B plus C, Module H or an applicable qualifying certification scheme. Critical products follow the stricter Article 32(4) route. Conformity assessment must cover both the product requirements in Annex I Part I and the manufacturer's vulnerability handling processes in Part II.

01 / 18

Article 32 Is the Core CRA Conformity Assessment Rule

Article 32 requires the manufacturer to perform a conformity assessment of both the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements in Annex I are met. This dual scope is important. CRA conformity assessment does not examine only the released software or hardware. It also addresses manufacturer processes covered by Annex I Part II, including vulnerability handling.

  • Assess the product with digital elements.
  • Assess the manufacturer's relevant processes.
  • Determine whether Annex I requirements are met.
  • Use an Article 32 conformity procedure.
02 / 18

Start by Determining the Product Category

The conformity route depends heavily on product classification. Products that do not fall within the important or critical categories can generally use the ordinary Article 32 procedures, including internal control based on Module A. Important products with digital elements listed in Annex III are divided into class I and class II. Critical products are listed in Annex IV. The technical descriptions of important and critical product categories have also been specified by the Commission under the CRA framework.

  • Default-category product.
  • Important product class I.
  • Important product class II.
  • Critical product.
  • Confirm the applicable product-category description.
03 / 18

Article 32 Provides Four Main Conformity Routes

Article 32(1) lists the internal control procedure based on Module A, the EU-type examination procedure based on Module B followed by conformity to EU-type based on Module C, conformity assessment based on full quality assurance under Module H, and, where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9). Product classification determines whether all of these routes remain available for the particular product.

  • Module A: internal control.
  • Module B plus C: EU-type examination plus internal production control.
  • Module H: full quality assurance.
  • European cybersecurity certification scheme where available and applicable.
04 / 18

Module A Is the CRA Internal-Control Route

Annex VIII Part I defines internal control as the conformity assessment procedure under which the manufacturer fulfils the specified obligations and ensures and declares on its sole responsibility that the product satisfies Annex I Part I and that the manufacturer meets Annex I Part II. Module A is therefore manufacturer self-assessment, but it is not an exemption from the CRA's technical or documentation requirements.

  • Manufacturer carries responsibility.
  • Technical documentation is still required.
  • Design and development must satisfy applicable requirements.
  • Production and vulnerability handling must also be controlled.
  • CE marking follows successful conformity demonstration.
05 / 18

Self-Assessment Does Not Mean No Evidence

A manufacturer using Module A still needs the technical documentation described in Annex VII and must take the measures necessary so that design, development, production, vulnerability handling and their monitoring ensure conformity with Annex I Parts I and II. The manufacturer must be able to support its conformity conclusion with documented risk analysis, architecture, controls, vulnerability handling and verification evidence. Self-assessment changes who performs the assessment, not the substantive CRA security requirements.

  • Maintain Annex VII technical documentation.
  • Document cybersecurity risk assessment.
  • Verify applicable Annex I controls.
  • Maintain vulnerability handling evidence.
  • Retain evidence supporting the manufacturer's conclusion.
06 / 18

Important Class I Products Have Conditional Self-Assessment

Article 32(2) creates a stricter rule for important class I products. Where the manufacturer has not applied, or has applied only in part, relevant harmonised standards, common specifications or qualifying European cybersecurity certification schemes at assurance level at least substantial, or where those routes do not exist, the relevant product and manufacturer processes must be submitted to Module B followed by C or to Module H for the affected essential cybersecurity requirements. This means class I self-assessment is conditional rather than automatic.

  • Confirm the product is Annex III class I.
  • Check relevant harmonised standards.
  • Check relevant common specifications.
  • Check qualifying certification schemes.
  • Determine whether Article 32(2)'s third-party trigger applies.
07 / 18

Important Class II Products Use Stricter Procedures

Article 32(3) requires important class II products to demonstrate conformity using Module B followed by Module C, Module H, or, where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9) at assurance level at least substantial. Ordinary Module A self-assessment is therefore not the standard conformity route for class II important products.

  • Module B plus C.
  • Module H.
  • Qualifying substantial-assurance certification scheme.
  • Ordinary Module A is not the standard class II route.
08 / 18

Critical Products Follow Article 32(4)

Critical products with digital elements listed in Annex IV follow Article 32(4). They demonstrate conformity using a European cybersecurity certification scheme in accordance with Article 8(1), where the conditions in that provision are met. Where those conditions are not met, Article 32(4) directs the manufacturer to one of the procedures available under Article 32(3). The critical-product route should therefore be assessed separately from the ordinary default-product rules.

  • Confirm Annex IV classification.
  • Assess the Article 8(1) certification route.
  • Where Article 8(1) conditions are not met, use an Article 32(3) procedure.
  • Do not treat critical products as ordinary Module A products.
09 / 18

Annex III Free and Open-Source Software Has a Specific Exception

Article 32(5) provides a specific conformity-assessment rule for manufacturers of products with digital elements qualifying as free and open-source software that fall within Annex III categories. Those manufacturers may demonstrate conformity using one of the procedures referred to in Article 32(1), provided that the Article 31 technical documentation is made available to the public when the product is placed on the market. This is an important exception to the normal Annex III procedure rules.

  • Product must qualify as free and open-source software.
  • Product falls within an Annex III category.
  • Article 32(1) procedures become available.
  • Article 31 technical documentation must be publicly available at market placement.
10 / 18

Module B Plus C Separates Type Examination From Production Control

The Module B plus C route combines EU-type examination with conformity to EU-type based on internal production control. Module B involves examination of the technical design and conformity of a representative type, while Module C addresses conformity of production to the approved EU type. Under the CRA this combination is one of the third-party routes available or required for relevant important and critical products.

  • Module B: EU-type examination.
  • Module C: conformity to the approved EU type.
  • Notified-body participation occurs in Module B.
  • Production remains controlled against the approved type.
11 / 18

Module H Uses Full Quality Assurance

Module H is the conformity assessment route based on full quality assurance. It involves an approved quality system covering relevant product activities and assessment by a notified body. Article 32 allows Module H in several routes, including important class I where the third-party trigger applies and important class II. Article 30 also provides that the CE marking is followed by the notified body's identification number where the notified body is involved through the full quality assurance procedure.

  • Full quality assurance route.
  • Notified-body assessment.
  • Quality-system controls.
  • Periodic oversight under Annex VIII.
  • Notified-body identification number accompanies CE marking where Article 30(4) applies.
12 / 18

Technical Documentation Supports Every Route

The applicable procedure changes who assesses conformity and how, but the manufacturer still needs the Article 31 technical documentation required to demonstrate how the product and manufacturer processes meet Annex I. The documentation should contain at least the Annex VII elements, including the cybersecurity risk assessment, design and architecture evidence, vulnerability handling information and relevant test reports.

  • Article 31 technical documentation.
  • Annex VII minimum content.
  • Cybersecurity risk assessment.
  • Architecture and design evidence.
  • Vulnerability handling evidence.
  • Conformity test reports.
13 / 18

The Assessment Must Cover Annex I Part I and Part II

The CRA conformity case has two related dimensions. Annex I Part I contains product cybersecurity requirements, while Part II covers vulnerability handling requirements imposed on the manufacturer. Article 32 expressly refers to assessment of the product and the processes put in place by the manufacturer. A conformity programme that tests product controls but ignores the vulnerability handling system is therefore incomplete.

  • Part I product security.
  • Part II vulnerability handling.
  • Product verification.
  • Process verification.
  • One conformity conclusion supported by both.
14 / 18

Successful Assessment Leads to the EU Declaration of Conformity

Article 13 provides that once the applicable conformity assessment has demonstrated compliance of the product with Annex I Part I and the manufacturer processes with Annex I Part II, the manufacturer draws up the EU declaration of conformity in accordance with Article 28. By drawing up that declaration, the manufacturer assumes responsibility for the compliance of the product with digital elements.

  • Complete the applicable conformity procedure.
  • Demonstrate the required conformity.
  • Draw up the Article 28 EU declaration of conformity.
  • Manufacturer assumes responsibility for product compliance.
15 / 18

CE Marking Comes After Conformity Has Been Demonstrated

The CE marking is not the conformity assessment itself. It is affixed after compliance has been demonstrated through the applicable procedure and the manufacturer has drawn up the EU declaration of conformity. Article 30 requires the CE marking to be affixed before the product is placed on the market. For software, the CE marking can be affixed to the EU declaration of conformity or on the website accompanying the software product, with the relevant website section easily and directly accessible to consumers.

  • Conformity assessment comes first.
  • EU declaration of conformity follows successful assessment.
  • CE marking follows the conformity conclusion.
  • CE marking must be affixed before market placement.
  • Software has the Article 30 website or declaration options.
16 / 18

Notified Bodies Perform the Applicable Third-Party Assessment

Where a conformity procedure requires third-party assessment, the relevant body must be a notified body authorised for the CRA conformity activities concerned. Article 47 requires notified bodies to perform conformity assessments in accordance with Article 32 and Annex VIII and to apply the required degree of rigour while avoiding unnecessary burdens. If the notified body finds that applicable Annex I requirements or corresponding standards or common specifications are not met, it requires corrective measures and does not issue the certificate.

  • Use a CRA-notified body for applicable third-party procedures.
  • Confirm the body's notification scope.
  • Expect product-specific technical review.
  • Correct non-conformities before certification.
17 / 18

Conformity Is Not a One-Time Release Event

Manufacturers must maintain procedures so products that are part of a series remain in conformity. Product changes, development or production changes, relevant standards and other conformity references can affect the compliance position. A manufacturer should therefore revisit conformity evidence when a security-relevant change alters the product, its risk assessment, its controls or the assumptions supporting the chosen conformity route.

  • Maintain conformity in series production.
  • Review material product changes.
  • Review development and production changes.
  • Review changed standards and specifications.
  • Update technical evidence where necessary.
18 / 18

A Practical CRA Conformity Assessment Workflow

A practical workflow is to confirm CRA scope, classify the product, complete the Article 13 cybersecurity risk assessment, map Annex I requirements, build Article 31 technical documentation, select the Article 32 conformity route, complete the required product and process verification, resolve non-conformities, finalise the EU declaration of conformity and affix the CE marking before market placement. The route decision should be documented because it determines whether internal control is sufficient or notified-body participation is required.

  • 1. Confirm CRA scope.
  • 2. Classify the product.
  • 3. Complete the cybersecurity risk assessment.
  • 4. Map Annex I requirements.
  • 5. Assemble technical documentation.
  • 6. Select the Article 32 procedure.
  • 7. Perform the assessment.
  • 8. Resolve findings.
  • 9. Draw up the EU declaration of conformity.
  • 10. Affix the CE marking.
  • 11. Maintain continued conformity.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.