Cyber Resilience Act

Is there a CRA certification?

For most products with digital elements, the CRA needs no certificate. The manufacturer self-assesses, draws up a Declaration of Conformity, and affixes the CE mark. Here is when that is enough and when a real certificate applies.

The short answer

The CRA does not create a general product certificate. It works through conformity assessment. Most manufacturers use internal control, which is a self-assessment, and then affix the CE marking under their own responsibility. The document that proves conformity is the EU Declaration of Conformity, backed by the Annex VII technical file.

A certificate from an external body enters the picture only for certain important and critical products, or where a European cybersecurity certification scheme is used.

The conformity assessment routes (Article 32)

Internal control (Module A)

The manufacturer self-assesses against the essential requirements, compiles the technical file, draws up the Declaration of Conformity, and affixes the CE mark. No external body is involved. This is the route for most products.

EU-type examination (Module B and C)

A notified body examines the type and issues an EU-type examination certificate, then the manufacturer ensures production conformity. This applies to some important and critical products.

Full quality assurance (Module H)

A notified body assesses and audits the manufacturer's quality system covering design, production, and testing.

European cybersecurity certification (CSA schemes)

For specific critical products, conformity can rest on a European cybersecurity certificate issued under a scheme such as the EUCC, adopted under the Cybersecurity Act.

How to evidence CRA compliance

Whether or not a certificate is involved, the core evidence is the same. The EU Declaration of Conformity names the product and the standards applied. The Annex VII technical file holds the risk assessment, the Annex I control mapping, and the vulnerability handling records behind it.

CRA certification questions

Is there a CRA certificate?

For most products there is no certificate. The CRA works through conformity assessment. The manufacturer self-assesses, draws up an EU Declaration of Conformity, and affixes the CE marking. A certificate issued by an external body applies only to certain important and critical products or where a European cybersecurity certification scheme is used.

What does CRA certified mean when a buyer asks for it?

Usually it means the product meets the CRA and carries the CE mark. The evidence a buyer should ask for is the EU Declaration of Conformity and, where a third-party route was used, the notified body's certificate.

Can CVD Portal certify my product?

No. No software vendor can certify CRA compliance. Only a notified body or a European cybersecurity certification scheme issues certificates, and only where the route requires one. CVD Portal helps you run the assessment and assemble the evidence that supports your Declaration of Conformity.

Assemble your Declaration of Conformity

Run the CRA assessment and export an audit-ready Annex VII technical file and Declaration of Conformity.

Get Started for Free