Conformity assessment is how the manufacturer demonstrates that both the product and the manufacturer’s processes meet the applicable essential cybersecurity requirements in CRA Annex I. Select the route according to the product’s core functionality, not merely a feature or component integrated into it.
1. Classify the product first
- Other (“default”) products: products whose core functionality is not listed in Annex III or IV.
- Important products, Class I: categories in Annex III, Class I.
- Important products, Class II: categories in Annex III, Class II.
- Critical products: categories in Annex IV.
Commission Implementing Regulation (EU) 2025/2392 provides the technical descriptions. Integrating a component that falls within Annex III or IV does not by itself put the whole product in that category. The question is whether the core functionality of the product as a whole matches the technical description.
2. Select the route
| Category | When module A internal production control is available | When a third party or certification scheme is required |
|---|---|---|
| Other products | The manufacturer may use module A even without harmonised standards, but must document how the requirements were met. | The manufacturer may voluntarily choose the stricter B + C or H route. |
| Important — Class I | Module A is available where harmonised standards, common specifications, or an available and applicable European cybersecurity certification scheme at least at “substantial” assurance level are fully applied to the relevant requirements. | If those means do not exist or are not fully applied, use B + C or H for the affected requirements. |
| Important — Class II | No, except for the specific qualifying free and open-source software route in Article 32(5). | B + C, H, or an available and applicable European cybersecurity certification scheme at least at “substantial” assurance level. |
| Critical | Not as the ordinary route. | Where the Commission requires certification for the category under Article 8(1), use the specified European cybersecurity certification scheme. Until the Article 8(1) conditions are met, use one of the Class II routes. |
Module A — internal production control: the manufacturer prepares the technical documentation, assesses the product and its production/process measures, issues the EU declaration of conformity and affixes CE marking under its sole responsibility.
Modules B + C: a notified body performs EU-type examination (module B). The manufacturer then ensures, under its own responsibility, that production conforms to the approved type (module C).
Module H — full quality assurance: a notified body assesses and periodically audits the manufacturer’s approved quality system covering design, development, production, final inspection and testing.
3. Complete the evidence package
Whichever route applies, the manufacturer:
- performs a cybersecurity risk assessment and takes its outcome into account throughout planning, design, development, production, delivery and maintenance;
- prepares Annex VII technical documentation, including proportionate evidence and an SBOM in a machine-readable format;
- performs or commissions the selected conformity-assessment procedure;
- resolves identified non-conformities;
- draws up the Article 28/Annex V EU declaration of conformity;
- affixes CE marking under Articles 29 and 30 before placing the product on the market; and
- keeps the technical documentation and EU declaration for at least 10 years after the product is placed on the market or for the support period, whichever is longer.
The manufacturer remains responsible for conformity when a notified body is involved. A third-party certificate does not replace the manufacturer’s EU declaration or its ongoing support-period obligations.
Related links: Product categories · Find a notified body · EU declaration · CE marking