CRA Compliance

The four conformity assessment routes under the EU Cyber Resilience Act

By CVD Portal
12 min read

The EU Cyber Resilience Act (CRA) defines a tiered system of conformity assessment procedures. The required compliance route depends on product classification. Selecting the wrong route creates legal risk that an invalid Declaration of Conformity cannot cure.

This guide outlines the four assessment routes, product classification tiers, and practical requirements for manufacturers.

Presumption of Conformity

When the European Commission cites a harmonised standard in the Official Journal of the EU, manufacturers applying that standard gain a legal presumption of conformity.

Applying cited harmonised standards provides strong legal backing for self-assessments. For Annex III Class I products, applying a cited harmonised standard in full is a mandatory condition for self-assessment.

Product Classification Tiers

Default Class

Products that do not fall under Annex III or Annex IV belong to the default class. This covers most products with digital elements.

Self-assessment under Module A (internal control) is permitted. Manufacturers select appropriate technical standards and issue the EU Declaration of Conformity on their own responsibility.

Important Class I

Self-assessment under Module A remains available if the manufacturer fully applies harmonised European standards carrying presumption of conformity. If harmonised standards are not applied in full, third-party assessment is mandatory.

Important Class II

Third-party assessment by a notified body is mandatory. The notified body conducts an EU Type Examination under Module B followed by Module C, or full quality assurance under Module H.

The notified body assesses both technical product properties and the manufacturer's vulnerability handling processes. Periodic audits verify ongoing compliance.

Critical Products

Critical products listed in Annex IV require formal certification under an approved European cybersecurity certification scheme, such as EUCC at assurance level substantial.

The Assessment Procedures

Module A: Internal Production Control

The manufacturer demonstrates that the product meets Annex I essential requirements on their own responsibility. The manufacturer issues the EU Declaration of Conformity and affixes the CE marking.

Module B + Module C: EU Type Examination

A notified body examines the technical product design and issues an EU Type Examination certificate. Module C provides internal production control for production units and product variants.

Module H: Full Quality Assurance

A notified body audits the manufacturer's quality management system. An approved quality system allows the manufacturer to declare conformity across covered product ranges.

Certification Schemes: EUCC

For Annex IV critical products, manufacturers must obtain certification under an approved scheme such as EUCC (European Cybersecurity Certification Scheme based on Common Criteria).

Open Source Software

Commercial open-source software must comply with conformity assessment rules. Open-source stewards maintaining software components follow a dedicated light-touch framework under Article 24.

Voluntary Third-Party Assessment

Manufacturers of default-class products can voluntarily pursue EU Type Examination. An independent certificate provides verified proof of security in enterprise procurement and regulated supply chains.

Key Takeaways

  1. Product classification determines the required conformity assessment procedure.
  2. Default products can self-assess under Module A.
  3. Important Class I products require full harmonised standards for self-assessment.
  4. Important Class II products require a notified body assessment.
  5. Critical products require European cybersecurity certification.
  • Identify which classification tier each of your products falls into before selecting a conformity assessment route.
  • For Important Class 1, using a harmonized standard is not sufficient: the standard must carry presumption of conformity and must be fully applied.
  • For Important Class 2, budget for periodic notified body audits of your vulnerability handling process. This is an ongoing obligation, not a one-time assessment.
  • Voluntary EU Type Examination for default-class products provides the strongest available proof of compliance and is increasingly sought in B2B and procurement contexts.
  • Open source software has flexibility similar to the default class, but is not exempt from conformity obligations.

Vulnerability Handling: The Process Requirement That Runs Through Every Tier

One thread that runs through every classification tier is vulnerability handling. For Important Class 2 and above, the notified body will audit it directly on a periodic basis. For default-class products, it is part of the essential requirements the manufacturer self-declares against. Across the board, the CRA treats vulnerability handling not as an optional best practice but as a core product compliance requirement.

The reporting obligations that sit on top of that process, under Article 14, come into force on 11 September 2026. That deadline applies to products already on the market, regardless of where a manufacturer stands on the broader conformity assessment timeline.

Stay compliant with the Cyber Resilience Act

Check your readiness with the CRA Readiness Checklist, or compare plans on pricing.

Get Started for Free

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.