Independent information resource Product security · EU CRA
Conformity assessment / 01

How CRA Conformity Assessment Works

Follow the Cyber Resilience Act conformity assessment process from product classification and cybersecurity risk assessment through technical documentation, Article 32 procedure selection, verification, EU declaration of conformity and CE marking.

IN BRIEF

The conformity procedure is not the first compliance step. Manufacturers need enough product classification, risk, design and evidence work to know which Article 32 route applies and to support the resulting assessment. The exact procedure can range from manufacturer internal control under Module A to notified-body assessment through Module B plus C or Module H.

01 / 14

Step 1: Confirm the Product Is Within CRA Scope

Conformity assessment begins only after the manufacturer has determined that the product is a product with digital elements within the CRA's scope and has identified the manufacturer responsible for compliance. Scope analysis should be resolved before a team chooses a conformity procedure because exclusions, sector-specific rules or the absence of an in-scope commercial activity can change the regulatory position.

  • Confirm CRA scope.
  • Identify the responsible manufacturer.
  • Confirm the marketed product boundary.
  • Resolve relevant exclusions before procedure selection.
02 / 14

Step 2: Classify the Product

Next determine whether the product is in the default category, an important product in Annex III class I, an important product in class II or a critical product listed in Annex IV. This classification is central because Article 32 changes the available conformity procedures for important and critical products. Classification should be based on the product's core functionality and the applicable legal category description.

  • Default category.
  • Important class I.
  • Important class II.
  • Critical product.
  • Record the classification rationale.
03 / 14

Step 3: Complete the Cybersecurity Risk Assessment

Article 13 requires the manufacturer to undertake and document a cybersecurity risk assessment associated with the product. The assessment identifies the cybersecurity risks against which the product is designed, developed, produced, delivered and maintained and supports decisions about Annex I applicability. Conformity assessment uses the resulting technical and risk evidence rather than replacing this earlier engineering analysis.

  • Intended purpose.
  • Reasonably foreseeable use.
  • Threats and attack scenarios.
  • Applicable Annex I requirements.
  • Risk treatment decisions.
04 / 14

Step 4: Build the Technical Documentation

Before market placement, the manufacturer needs Article 31 technical documentation containing the relevant evidence used to demonstrate Annex I compliance and at least the Annex VII elements. This includes product information, design and architecture, vulnerability handling processes, cybersecurity risk assessment, support-period information, standards or technical solutions, test reports and the EU declaration of conformity when completed.

  • Product description.
  • Architecture and design.
  • Vulnerability handling.
  • Cybersecurity risk assessment.
  • Standards and technical solutions.
  • Test reports.
05 / 14

Step 5: Determine Whether Module A Is Available

For products not subject to a stricter Article 32 category rule, internal control based on Module A is available. Important class I products need an additional Article 32(2) analysis because the absence or partial application of relevant harmonised standards, common specifications or qualifying certification schemes can trigger mandatory Module B plus C or Module H for the affected essential cybersecurity requirements. Class II and critical products follow their own stricter routes.

  • Confirm product classification.
  • Check Article 32(2) for class I.
  • Check Article 32(3) for class II.
  • Check Article 32(4) for critical products.
  • Document the procedure-selection reasoning.
06 / 14

Step 6: Select the Permitted Article 32 Procedure

Article 32 procedures include Module A internal control, Module B followed by Module C, Module H full quality assurance and an applicable European cybersecurity certification scheme. The manufacturer should record why the selected route is permitted for the product. Procedure selection should not be based only on convenience because an important or critical classification can remove ordinary Module A from the available routes.

  • Module A where permitted.
  • Module B plus C where selected or required.
  • Module H where selected or required.
  • Applicable certification route where legally available.
07 / 14

Step 7: Verify Product Security Requirements

The conformity evidence must support the applicable product-security requirements in Annex I Part I. Verification can include architecture review, automated security tests, access-control testing, resilience testing, update testing, configuration review, code analysis, penetration testing or other suitable methods. The CRA does not require one testing technique to prove every requirement. Testing should follow the product's risk assessment and control map.

  • Map verification to Annex I requirements.
  • Identify the tested product version.
  • Use appropriate test methods.
  • Record expected and actual results.
  • Resolve failed requirements.
08 / 14

Step 8: Verify Vulnerability Handling Processes

Article 32 also covers the processes put in place by the manufacturer. The conformity assessment should therefore include evidence for Annex I Part II vulnerability handling, such as component and SBOM processes, vulnerability intake, testing and review, remediation, coordinated disclosure and secure update distribution. Product testing alone does not establish conformity of these manufacturer processes.

  • Component and SBOM process.
  • Vulnerability intake.
  • Testing and review.
  • Remediation workflow.
  • Coordinated vulnerability disclosure.
  • Secure update distribution.
09 / 14

Step 9: Complete Notified-Body Assessment Where Required

Where the selected or required route involves a notified body, the manufacturer supplies the applicable technical evidence and supports the assessment under Annex VIII. The notified body evaluates the matters within the relevant module and notification scope. If applicable requirements are not met, corrective action is required before the relevant certificate can be issued.

  • Select an appropriately notified body.
  • Confirm notification scope.
  • Supply required technical documentation.
  • Respond to assessment findings.
  • Complete corrective actions.
10 / 14

Step 10: Resolve Non-Conformities

Security testing or a notified-body assessment can identify gaps between the product or process and the applicable requirements. Those findings should feed back into engineering, risk assessment and technical documentation. Where a notified body finds the requirements have not been met, Article 47 requires appropriate corrective measures and prevents issuance of the conformity certificate until the relevant conditions are satisfied.

  • Record the finding.
  • Identify affected Annex I requirement.
  • Remediate the product or process.
  • Retest or reassess.
  • Update technical documentation.
11 / 14

Step 11: Finalise the Conformity Evidence

Before the final conformity conclusion, confirm that the assessed product version matches the release candidate and that the technical documentation contains current risk, architecture, vulnerability handling and test evidence. The conformity case should not rely on test reports for an obsolete build or a technical file that predates a material security change.

  • Confirm release identity.
  • Confirm current risk assessment.
  • Confirm current architecture.
  • Confirm current SBOM and vulnerability processes.
  • Confirm passing verification evidence.
12 / 14

Step 12: Draw Up the EU Declaration of Conformity

Once compliance has been demonstrated by the applicable conformity assessment procedure, the manufacturer draws up the EU declaration of conformity in accordance with Article 28. The declaration identifies the product and the relevant compliance framework. By drawing it up, the manufacturer assumes responsibility for the product's compliance.

  • Use the Article 28 declaration requirements.
  • Identify the covered product correctly.
  • Keep the declaration consistent with the technical file.
  • Manufacturer assumes compliance responsibility.
13 / 14

Step 13: Affix the CE Marking

Article 30 requires the CE marking to be affixed before the product is placed on the market. Depending on the product form, the marking can appear on the product, packaging and declaration as provided by Article 30. For software products, it can be affixed to the EU declaration of conformity or on the website accompanying the software product, with the relevant website section easily and directly accessible to consumers.

  • Affix the CE marking before market placement.
  • Follow Article 30 placement rules.
  • Apply software-specific placement rules where relevant.
  • Include notified-body identification where Article 30 requires it.
14 / 14

Step 14: Maintain Conformity After Release

The conformity process continues after the initial market-placement decision. Manufacturers must maintain conformity for products in series production and keep technical documentation updated where appropriate. Security-relevant changes can require renewed risk analysis, updated documentation and repeat verification. Where the change affects the basis of the conformity route, the manufacturer should reassess whether the existing procedure remains sufficient.

  • Monitor product changes.
  • Maintain technical documentation.
  • Repeat affected verification.
  • Review standards and certification references.
  • Preserve historical conformity evidence.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.