Conformity Assessment

CRA conformity assessment is the legal procedure used to show that a in-scope product and the manufacturer's processes meet Annex I. Product classification helps choose the route, but the assessment itself is a separate step.

Assessment object

The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met.

Regulation (EU) 2024/2847, Article 32(1)

Article 32 is about both sides of Annex I. The product must meet the product cybersecurity requirements in Part I. The manufacturer's vulnerability-handling processes must meet Part II.

A positive assessment supports the technical documentation, the EU declaration of conformity, and the CE marking. It does not change the product category. The category decides which assessment routes are open.

Conformity routes

Article 32 names four routes. The right route depends mainly on the product category, the use of harmonised standards or common specifications, and whether an applicable cybersecurity certification scheme can be used.

Module A

Internal control. The manufacturer assesses the product and declares conformity on its own responsibility.

Module B plus Module C

A notified body examines the type. The manufacturer then controls production against that type.

Module H

Full quality assurance. A notified body assesses the manufacturer's quality system for the in-scope products.

Cybersecurity certification

An applicable European cybersecurity certification scheme can be used when Article 27 or Article 8 makes that route available.

Classification and route selection

The default route is broad. The stricter routes appear when the product is an important or critical product, or when a Class I product cannot rely fully on the relevant standards, common specifications, or certification.

Standards and certification

Article 27 explains how standards, common specifications, and cybersecurity certification can support conformity. They are not the same thing, and they do not all have the same legal effect.

  • A harmonised standard gives a presumption of conformity only for the Annex I requirements covered by the published standard reference.
  • A common specification can also create a presumption of conformity for the requirements it covers.
  • A European cybersecurity certificate can create a presumption of conformity for the covered requirements.
  • A certificate specified by delegated act under Article 27(9), at assurance level at least substantial, can remove the need for third-party assessment for the corresponding requirements.

Documentation, declaration, and CE marking

Conformity assessment produces legal outputs. The manufacturer draws up technical documentation before placing the product on the market and keeps it updated during the support period when appropriate. The EU declaration of conformity states that the applicable Annex I requirements have been met.

  • Technical documentation contains the data or details used to show that the product and processes meet Annex I.
  • The EU declaration of conformity follows the model structure in Annex V, or the simplified route in Annex VI when that is used.
  • CE marking is affixed before the product is placed on the market; for software, it can appear on the declaration or on the website accompanying the software product.
  • If Module H is used, the CE marking is followed by the notified body's identification number.

Sources