Independent information resource Product security · EU CRA
CRA readiness, templates, tools and software / 10

CRA Conformity Assessment Checklist

A practical Cyber Resilience Act conformity assessment checklist covering product classification, Article 32 route selection, technical documentation, notified-body involvement, standards, EU declaration of conformity and CE marking.

IN BRIEF

Start with classification because it controls the available route. Default-category products generally retain self-assessment flexibility, important class I products can use self-assessment only under specified conditions, and important class II and critical products face stricter third-party or qualifying certification routes. Keep the route decision linked to the product's technical evidence and final declaration.

01 / 11

Confirm Product Scope and Classification First

Do not select a conformity route before confirming the product boundary and classification. The Article 32 options depend on whether the product is in the default category, important class I, important class II or critical. Keep the classification record with the conformity file.

02 / 11

Determine Which Article 32 Procedures Are Available

Article 32 provides internal control based on Module A, EU-type examination based on Module B followed by conformity to type based on Module C, and full quality assurance based on Module H. The legally available choice depends on the product category and applicable conditions.

03 / 11

Check Whether Self-Assessment Is Allowed

Default-category products generally retain self-assessment flexibility. Important class I products can use internal control only where the specified standards, common specifications or qualifying certification conditions are satisfied. Important class II and critical products require stricter routes. Record why self-assessment is or is not available.

04 / 11

Plan Notified-Body Involvement Where Required

Where the selected route requires a notified body, verify that the body is formally notified for the relevant CRA activity, module and product scope. A cybersecurity testing laboratory is not automatically a CRA notified body.

05 / 11

Complete the Technical Documentation Before Assessment

Article 31 and Annex VII evidence should be current before the assessment proceeds. Confirm product description, architecture, cybersecurity risk assessment, vulnerability-handling evidence, SBOM, standards or specifications and test reports are linked to the product version being assessed.

06 / 11

Map Annex I Requirements to Evidence

The conformity assessment determines whether the product and manufacturer processes meet applicable Annex I requirements. Maintain a requirement-to-evidence mapping so assessors can see the design, process, test and risk evidence supporting each applicable requirement.

07 / 11

Record Standards and Presumption-of-Conformity Evidence

Where harmonised standards, common specifications or qualifying certification schemes are used, record the exact references, scope and product evidence. Do not claim presumption of conformity beyond the requirements actually covered by the relevant standard or scheme.

08 / 11

Track Findings and Corrective Actions

Assessment findings should have owners, corrective actions, evidence of closure and retest or reassessment where required. A dashboard status should link to the underlying finding rather than showing conformity as a simple percentage.

09 / 11

Draw Up the EU Declaration of Conformity

Once conformity has been demonstrated through the applicable procedure, the manufacturer draws up the EU declaration of conformity in accordance with the CRA. Verify that product identity, legislation, standards and notified-body information are accurate where applicable.

10 / 11

Affix CE Marking After the Conformity Process

CE marking follows the conformity process. The checklist should prevent teams from treating the mark as a marketing graphic detached from the legal evidence. Confirm that the product and documentation support the declaration before marking.

11 / 11

Maintain Continued Conformity After Market Placement

Article 13 requires procedures for products that are part of a series of production to remain in conformity. Product changes, vulnerability findings, standards updates and process changes should trigger review of the conformity evidence where appropriate.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.