The EU Cyber Resilience Act (CRA) defines a tiered system of conformity assessment procedures. The required compliance route depends on product classification. Selecting the wrong route creates legal risk that an invalid Declaration of Conformity cannot cure.
This guide outlines the four assessment routes, product classification tiers, and practical requirements for manufacturers.
Presumption of Conformity
When the European Commission cites a harmonised standard in the Official Journal of the EU, manufacturers applying that standard gain a legal presumption of conformity.
Applying cited harmonised standards provides strong legal backing for self-assessments. For Annex III Class I products, applying a cited harmonised standard in full is a mandatory condition for self-assessment.
Product Classification Tiers
Default Class
Products that do not fall under Annex III or Annex IV belong to the default class. This covers most products with digital elements.
Self-assessment under Module A (internal control) is permitted. Manufacturers select appropriate technical standards and issue the EU Declaration of Conformity on their own responsibility.
Important Class I
Self-assessment under Module A remains available if the manufacturer fully applies harmonised European standards carrying presumption of conformity. If harmonised standards are not applied in full, third-party assessment is mandatory.
Important Class II
Third-party assessment by a notified body is mandatory. The notified body conducts an EU Type Examination under Module B followed by Module C, or full quality assurance under Module H.
The notified body assesses both technical product properties and the manufacturer's vulnerability handling processes. Periodic audits verify ongoing compliance.
Critical Products
Critical products listed in Annex IV require formal certification under an approved European cybersecurity certification scheme, such as EUCC at assurance level substantial.
The Assessment Procedures
Module A: Internal Production Control
The manufacturer demonstrates that the product meets Annex I essential requirements on their own responsibility. The manufacturer issues the EU Declaration of Conformity and affixes the CE marking.
Module B + Module C: EU Type Examination
A notified body examines the technical product design and issues an EU Type Examination certificate. Module C provides internal production control for production units and product variants.
Module H: Full Quality Assurance
A notified body audits the manufacturer's quality management system. An approved quality system allows the manufacturer to declare conformity across covered product ranges.
Certification Schemes: EUCC
For Annex IV critical products, manufacturers must obtain certification under an approved scheme such as EUCC (European Cybersecurity Certification Scheme based on Common Criteria).
Open Source Software
Commercial open-source software must comply with conformity assessment rules. Open-source stewards maintaining software components follow a dedicated light-touch framework under Article 24.
Voluntary Third-Party Assessment
Manufacturers of default-class products can voluntarily pursue EU Type Examination. An independent certificate provides verified proof of security in enterprise procurement and regulated supply chains.
Key Takeaways
- Product classification determines the required conformity assessment procedure.
- Default products can self-assess under Module A.
- Important Class I products require full harmonised standards for self-assessment.
- Important Class II products require a notified body assessment.
- Critical products require European cybersecurity certification.
- Identify which classification tier each of your products falls into before selecting a conformity assessment route.
- For Important Class 1, using a harmonized standard is not sufficient: the standard must carry presumption of conformity and must be fully applied.
- For Important Class 2, budget for periodic notified body audits of your vulnerability handling process. This is an ongoing obligation, not a one-time assessment.
- Voluntary EU Type Examination for default-class products provides the strongest available proof of compliance and is increasingly sought in B2B and procurement contexts.
- Open source software has flexibility similar to the default class, but is not exempt from conformity obligations.
Vulnerability Handling: The Process Requirement That Runs Through Every Tier
One thread that runs through every classification tier is vulnerability handling. For Important Class 2 and above, the notified body will audit it directly on a periodic basis. For default-class products, it is part of the essential requirements the manufacturer self-declares against. Across the board, the CRA treats vulnerability handling not as an optional best practice but as a core product compliance requirement.
The reporting obligations that sit on top of that process, under Article 14, come into force on 11 September 2026. That deadline applies to products already on the market, regardless of where a manufacturer stands on the broader conformity assessment timeline.