Most products with digital elements are eligible for self-attestation under the CRA. Manufacturers can issue an EU Declaration of Conformity under Module A (internal production control) without hiring a notified body.
Self-attestation carries full legal responsibility. The signed declaration requires complete supporting evidence in the Annex VII technical file.
Eligibility for Self-Attestation
Product risk tiering determines the conformity route:
- Default products: Self-attestation is permitted under Module A. The manufacturer runs internal assessments and signs the declaration.
- Important products (Annex III Class I): Self-attestation is permitted only if the manufacturer applies cited harmonised European standards in full. Without harmonised standards, notified body review is required.
- Important products (Annex III Class II) and Critical products (Annex IV): Mandatory third-party assessment by a notified body or approved certification scheme. Self-attestation is not available.
Default products make up the majority of connected IoT devices, industrial sensors, and embedded hardware.
What Self-Attestation Requires
Module A requires a complete internal conformity assessment. The manufacturer must compile technical documentation under Annex VII before placing products on the market.
Signing the EU Declaration of Conformity confirms that full technical evidence exists and is ready for market surveillance review.
The Four Core Evidence Categories
Defensible self-attestation relies on four interconnected evidence pillars:
1. Risk Assessment Mapped to Annex I
Article 13 requires a documented cybersecurity risk assessment. Each identified risk must connect to an Annex I essential requirement and a corresponding technical control.
The assessment covers product security properties and ongoing vulnerability handling duties.
2. Design and Verification Records
Technical documentation must explain the security architecture rationale. Test records, automated scan reports, and verification logs must prove that technical controls operate as intended.
3. Vulnerability Handling Workflows
Manufacturers must operate a public Coordinated Vulnerability Disclosure (CVD) policy under Article 13. Internal procedures must handle intake, triage, patching, and Article 14 authority notifications.
Operating an active intake channel is a mandatory prerequisite for signing the Declaration of Conformity.
4. Software Bill of Materials (SBOM)
The manufacturer must generate and maintain an SBOM under Article 13(6). The SBOM must track components and dependencies throughout the product support period.
Best Practices for Self-Attestation
A defensible self-attestation process demonstrates five key qualities:
Complete coverage. Every Annex I essential requirement is evaluated with clear applicability decisions.
Clear traceability. Auditors can navigate from requirements to technical controls and underlying verification evidence.
Current records. Documentation reflects the version currently on the market.
Proportional detail. Documentation depth matches product complexity and operational risk.
Version control. Evidence is stored in access-controlled systems with immutable revision logs.
Summary
Self-attestation under Module A provides a practical conformity path for default-tier manufacturers. Preparing structured risk assessments, technical files, and CVD infrastructure ensures full compliance before market release.
The Ongoing Obligation
A Declaration of Conformity is signed at a point in time, but the compliance obligations it represents are continuous. If a vulnerability is discovered that was not addressed in the risk assessment, the assessment must be reviewed and updated. If the product is updated in a way that changes its risk profile, the documentation must be revised and, if the changes are significant, the declaration may need to be reissued.
Self-attestation is not a one-time filing. It is a statement that the product meets the requirements as of the date signed, backed by documentation that must remain accurate. Manufacturers who treat it as a completed task rather than an ongoing obligation will find themselves out of compliance the first time their product or its threat environment changes significantly.
The September 2026 deadline for vulnerability reporting obligations means that the internal processes required for self-attestation, particularly the VDP and the vulnerability handling documentation, must be established well before the December 2027 conformity deadline. Building these now, as operational infrastructure rather than documentation to be produced at the end, is the most effective path to a self-attestation process that holds up.