Conformity Assessment
CRA conformity assessment is the legal procedure used to show that a in-scope product and the manufacturer's processes meet Annex I. Product classification helps choose the route, but the assessment itself is a separate step.
Assessment object
The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met.
Regulation (EU) 2024/2847, Article 32(1)
Article 32 is about both sides of Annex I. The product must meet the product cybersecurity requirements in Part I. The manufacturer's vulnerability-handling processes must meet Part II.
A positive assessment supports the technical documentation, the EU declaration of conformity, and the CE marking. It does not change the product category. The category decides which assessment routes are open.
Conformity routes
Article 32 names four routes. The right route depends mainly on the product category, the use of harmonised standards or common specifications, and whether an applicable cybersecurity certification scheme can be used.
Module A
Internal control. The manufacturer assesses the product and declares conformity on its own responsibility.
Module B plus Module C
A notified body examines the type. The manufacturer then controls production against that type.
Module H
Full quality assurance. A notified body assesses the manufacturer's quality system for the in-scope products.
Cybersecurity certification
An applicable European cybersecurity certification scheme can be used when Article 27 or Article 8 makes that route available.
Classification and route selection
The default route is broad. The stricter routes appear when the product is an important or critical product, or when a Class I product cannot rely fully on the relevant standards, common specifications, or certification.
Default products can use Article 32(1), including Module A. The manufacturer may still choose a stricter route.
Class I products can remain under Article 32(1) only for the requirements covered by applied harmonised standards, common specifications, or certification at assurance level at least substantial. Otherwise, Module B plus C or Module H is needed for those requirements.
Class II products use Module B plus C, Module H, or an applicable European cybersecurity certification scheme at assurance level at least substantial.
Annex IV critical products use certification under Article 8(1) when that route is triggered. If the Article 8(1) conditions are not met, they follow the Class II routes in Article 32(3).
Important free and open-source software in Annex III can use the Article 32(1) routes if the Article 31 technical documentation is public when the product is placed on the market.
Standards and certification
Article 27 explains how standards, common specifications, and cybersecurity certification can support conformity. They are not the same thing, and they do not all have the same legal effect.
- A harmonised standard gives a presumption of conformity only for the Annex I requirements covered by the published standard reference.
- A common specification can also create a presumption of conformity for the requirements it covers.
- A European cybersecurity certificate can create a presumption of conformity for the covered requirements.
- A certificate specified by delegated act under Article 27(9), at assurance level at least substantial, can remove the need for third-party assessment for the corresponding requirements.
Documentation, declaration, and CE marking
Conformity assessment produces legal outputs. The manufacturer draws up technical documentation before placing the product on the market and keeps it updated during the support period when appropriate. The EU declaration of conformity states that the applicable Annex I requirements have been met.
- Technical documentation contains the data or details used to show that the product and processes meet Annex I.
- The EU declaration of conformity follows the model structure in Annex V, or the simplified route in Annex VI when that is used.
- CE marking is affixed before the product is placed on the market; for software, it can appear on the declaration or on the website accompanying the software product.
- If Module H is used, the CE marking is followed by the notified body's identification number.