CRA self-assessment is not a simplified cybersecurity standard. Under Module A, the manufacturer assumes sole responsibility for declaring conformity and must still prepare technical documentation, ensure design, development, production and vulnerability handling meet Annex I, perform appropriate verification, draw up the EU declaration of conformity and affix the CE marking. The key eligibility question is the product's Article 32 classification and any class-specific conditions.
CRA Self-Assessment Means Module A Internal Control
Under the CRA, manufacturer self-assessment corresponds to the internal control procedure based on Module A in Annex VIII. Under this procedure, the manufacturer fulfils the specified obligations and ensures and declares on its sole responsibility that the product satisfies Annex I Part I and the manufacturer meets the Part II vulnerability handling requirements. Self-assessment therefore describes who performs and assumes responsibility for the conformity assessment, not a reduction of the underlying cybersecurity obligations.
- Module A is internal control.
- Manufacturer carries sole responsibility.
- Part I product requirements still apply.
- Part II vulnerability handling requirements still apply.
Default-Category Products Can Generally Use Module A
Products that do not fall within the stricter important or critical categories can generally use the Article 32(1) internal-control route. The Commission describes this default category as allowing manufacturer self-assessment irrespective of the technical specification used to demonstrate conformity. The manufacturer must still perform the required risk assessment, technical documentation and verification work supporting its conformity conclusion.
- Confirm the product is not Annex III or Annex IV.
- Module A remains available.
- Technical documentation remains mandatory.
- Annex I conformity still has to be demonstrated.
Important Class I Products Need a Second Eligibility Test
An Annex III class I classification does not automatically prohibit self-assessment, but Article 32(2) creates conditions that determine whether Module A remains available. The manufacturer must examine whether relevant harmonised standards, common specifications or qualifying European cybersecurity certification schemes at assurance level at least substantial exist and have been applied to the relevant essential cybersecurity requirements.
- First confirm class I status.
- Identify relevant conformity references.
- Determine whether they exist.
- Determine whether they have been applied fully.
- Record the route decision.
Class I Third-Party Assessment Is Triggered in Specific Cases
Article 32(2) requires Module B followed by C or Module H for the relevant essential cybersecurity requirements where the manufacturer has not applied or has applied only in part the relevant harmonised standards, common specifications or qualifying certification schemes, or where those conformity references do not exist. Manufacturers should therefore avoid the oversimplified rule that all class I products can self-assess.
- Relevant standard not applied.
- Relevant standard only partly applied.
- Relevant common specification not applied or partly applied.
- Relevant qualifying certification route not applied or partly applied.
- Relevant conformity reference does not exist.
Fully Applying the Relevant Class I Route Can Preserve Self-Assessment
Where the Article 32(2) mandatory third-party conditions are not triggered, a class I manufacturer can retain the internal-control route for the relevant conformity case. This is why class I should be described as conditional self-assessment rather than automatic self-assessment or automatic third-party assessment. The manufacturer should preserve evidence showing which harmonised standards, common specifications or qualifying certification schemes were relied upon and their scope of application.
- Check each relevant essential requirement.
- Record the applicable conformity reference.
- Record full or partial application.
- Preserve standards or certification evidence.
- Document why Module A remains available.
Important Class II Products Do Not Use Ordinary Module A
Article 32(3) requires important class II products to demonstrate conformity using Module B followed by Module C, Module H, or, where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9) at assurance level at least substantial. Ordinary Module A internal control is therefore not the standard route for class II products.
- Module B plus C.
- Module H.
- Applicable substantial-assurance certification scheme.
- No ordinary Module A route under Article 32(3).
Critical Products Have Their Own Article 32(4) Rule
Critical products listed in Annex IV should not be analysed using the ordinary default-product self-assessment rule. Article 32(4) directs critical products to a European cybersecurity certification scheme in accordance with Article 8(1) where the conditions in that provision are met. Where those conditions are not met, the product uses one of the procedures referred to in Article 32(3).
- Confirm Annex IV status.
- Check the Article 8(1) certification conditions.
- If those conditions are not met, use an Article 32(3) procedure.
- Do not rely on ordinary Module A.
Free and Open-Source Annex III Products Have a Specific Exception
Article 32(5) provides that manufacturers of products with digital elements qualifying as free and open-source software that fall within the categories in Annex III may demonstrate conformity using one of the Article 32(1) procedures, provided that the Article 31 technical documentation is made available to the public when the product is placed on the market. Because Article 32(1) includes Module A, this creates a specific self-assessment possibility that differs from the normal Annex III rules.
- Manufacturer must be dealing with qualifying free and open-source software.
- Product falls within Annex III.
- Article 32(1) procedures become available.
- Technical documentation must be public at market placement.
The FOSS Exception Does Not Remove Annex I Obligations
Article 32(5) changes the conformity procedure available to qualifying Annex III free and open-source software manufacturers. It does not remove the applicable Annex I security requirements, Article 13 manufacturer duties or Article 31 technical-documentation obligation. A manufacturer using Module A through this provision still needs evidence sufficient to support its declaration of conformity.
- Annex I still applies.
- Article 13 duties still apply.
- Technical documentation still applies.
- Public technical documentation is a condition of the special route.
Module A Still Requires Annex VII Technical Documentation
Annex VIII Part I requires the manufacturer using internal control to draw up the technical documentation described in Annex VII. This includes product description, architecture and design information, vulnerability handling, cybersecurity risk assessment, support-period information, applicable standards or technical solutions and test reports. Self-assessment should therefore be planned as an evidence-producing compliance process.
- Annex VII technical documentation.
- Cybersecurity risk assessment.
- Architecture and design.
- Vulnerability handling.
- Standards mapping.
- Security test evidence.
Module A Covers Design, Development, Production and Vulnerability Handling
Annex VIII Part I requires the manufacturer to take all measures necessary so that design, development, production and vulnerability handling processes and their monitoring ensure compliance with Annex I Parts I and II. A Module A assessment that consists only of reviewing the final product binary or hardware unit would therefore miss significant parts of the required conformity case.
- Design.
- Development.
- Production.
- Vulnerability handling.
- Monitoring of the relevant processes.
Self-Assessment Still Needs Security Verification
The manufacturer needs evidence supporting its claim that the applicable Annex I requirements are met. Depending on the product and risk, verification can include security testing, code review, architecture review, configuration inspection, resilience testing, update testing, vulnerability process review and other appropriate methods. Module A does not mean that the manufacturer can declare conformity without a technical basis.
- Verify applicable controls.
- Record test scope.
- Record product versions.
- Resolve failed requirements.
- Retain conformity evidence.
Using a Harmonised Standard Is Not the Same as Outsourcing Assessment
A harmonised standard can support presumption of conformity for the matters it covers, but applying a standard and using a notified body are different concepts. For class I important products, the status and application of relevant standards can determine whether Article 32(2) triggers third-party assessment. The manufacturer should therefore document both the standards position and the conformity procedure selected.
- Identify relevant harmonised standards.
- Record their scope.
- Record full or partial application.
- Separate standards evidence from procedure selection.
Self-Assessment Ends With the Manufacturer's Conformity Declaration
After the manufacturer has completed the Module A requirements and determined that the product and relevant processes satisfy the CRA, the manufacturer draws up the EU declaration of conformity and affixes the CE marking. The manufacturer assumes responsibility for the resulting compliance claim. Module A therefore places significant evidentiary and decision-making responsibility directly on the manufacturer.
- Complete technical documentation.
- Reach documented conformity conclusion.
- Draw up EU declaration of conformity.
- Affix CE marking.
- Retain supporting evidence.
Recheck Self-Assessment Eligibility After Material Changes
A product's conformity route should not be treated as permanently fixed without review. A change in core functionality can affect classification. A new harmonised standard or common specification can affect the Article 32 analysis. Product modifications can invalidate earlier test evidence. Manufacturers should therefore include conformity-route review in change management when a change could affect classification, standards coverage or the basis of the previous assessment.
- Review classification changes.
- Review new standards.
- Review new common specifications.
- Review certification availability.
- Review security-relevant product changes.
A Practical CRA Self-Assessment Decision Test
Start by identifying whether the product is default, important class I, important class II or critical. Default products can generally proceed with Module A. For class I, analyse Article 32(2) and the status and application of relevant standards, common specifications and qualifying certification schemes. Class II follows Article 32(3). Critical products follow Article 32(4). For qualifying Annex III free and open-source software, separately test the Article 32(5) public-technical-documentation exception.
- 1. Determine classification.
- 2. If default, Module A is generally available.
- 3. If class I, apply the Article 32(2) test.
- 4. If class II, use an Article 32(3) route.
- 5. If critical, apply Article 32(4).
- 6. If qualifying Annex III FOSS, check Article 32(5).
- 7. Document the conclusion.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.