CRA conformity assessment: Modules A, B + C and H, notified bodies and CE marking
Before a product with digital elements carries the CE marking under the Cyber Resilience Act, its manufacturer must demonstrate conformity with the essential requirements through one of three procedures — internal control, EU-type examination plus conformity to type, or full quality assurance — with the available choice depending on whether the product is default, important or critical.
By the Vellaci teamPublished Updated 4 min readOperational guidance, not legal advice
Key facts
- Legal basis
- Art. 32 and Annex VIII; declaration Art. 28 and Annex V; CE marking Art. 29–30
- Module A
- Internal control — manufacturer alone
- Modules B + C
- EU-type examination by a notified body, then conformity to type
- Module H
- Full quality assurance audited by a notified body
- Presumption of conformity
- Harmonised standards / common specifications applied in full (Art. 27)
- Notified bodies
- Designation provisions apply from 11 June 2026
- Applies
- 11 December 2027 for products placed on the market from that date
The three procedures
Module A, internal control: the manufacturer draws up the technical documentation, ensures the design and production meet the essential requirements, and issues the EU declaration of conformity on its own responsibility. No third party is involved.
Modules B + C, EU-type examination and conformity to type: a notified body examines the technical design (and, where needed, a specimen) and issues an EU-type examination certificate; the manufacturer then ensures production conforms to the approved type and declares conformity. Changes to the approved type must be notified to the body.
Module H, full quality assurance: a notified body assesses and periodically audits the manufacturer's quality system covering design, development, production and vulnerability handling; the manufacturer declares conformity for products produced under that system. Suited to organisations with many products and a mature process.
A European cybersecurity certificate issued under a scheme adopted pursuant to the Cybersecurity Act can substitute for these procedures where the certificate covers the essential requirements at the relevant assurance level.
Which routes are open to which products
| Product class | Module A | Modules B + C | Module H | European certificate |
|---|---|---|---|---|
| Default | Yes | Yes | Yes | Yes (where a scheme exists) |
| Important — Class I | Only with fully applied harmonised standards / common specifications / European scheme | Yes | Yes | Yes |
| Important — Class II | No | Yes | Yes | Yes, at assurance level 'substantial' or higher |
| Critical | No | Yes (until a delegated act mandates certification) | Yes (same) | Mandatory where a delegated act says so |
Harmonised standards and the presumption of conformity
Products in conformity with harmonised standards whose references are published in the Official Journal, or with common specifications adopted by the Commission, are presumed to conform with the essential requirements those standards cover (Article 27). The Commission has issued a standardisation request for the CRA; until the harmonised standards are published, manufacturers can align with the state of the art (IEC 62443-4-1/4-2, ETSI EN 303 645 for consumer IoT, ISO/IEC 27034, NIST SSDF) and document the mapping, but the presumption of conformity — and, for Class I, the self-assessment route — depends on the harmonised standards themselves.
Notified bodies
Notified bodies are conformity assessment bodies designated by a Member State and notified to the Commission. The provisions on their designation apply from 11 June 2026 so that capacity exists before December 2027. Capacity will be scarce in the first years: manufacturers of Class II products and Class I products without fully applied standards should engage a body early, prepare the technical documentation to Annex VII depth, and expect the body to look closely at the vulnerability-handling process, not only at the product's design.
Declaration of conformity and CE marking
After a successful procedure the manufacturer draws up the EU declaration of conformity following Annex V — identifying the product, the manufacturer, the procedure, the notified body where applicable and the standards applied — and affixes the CE marking. For software, the marking may appear on the declaration, on the website or in accompanying documentation. Both the declaration and the technical documentation are kept for ten years after placing on the market or for the support period, whichever is longer.
Planning backwards from December 2027
- Settle classification per product with documented reasoning (now).
- Choose the procedure per product; for B + C or H, shortlist notified bodies and request slots (from June 2026).
- Complete the cybersecurity risk assessment and map the essential requirements to controls and evidence.
- Assemble Annex VII documentation progressively: design, development and vulnerability-handling processes, SBOM, test reports, support period.
- Run the procedure, draw up the declaration, affix the marking, and keep everything retrievable for ten years.
Frequently asked questions
- Do products already on the market need conformity assessment?
- Only when placed on the market from 11 December 2027 or when substantially modified after that date. Products placed earlier and not substantially modified are not re-assessed — but Article 14 reporting has applied to them since 11 September 2026 regardless.
- Does ISO 27001 or IEC 62443 certification replace conformity assessment?
- No. They are strong evidence for the process side and may map onto the harmonised standards, but conformity assessment under the CRA is a separate procedure with its own declaration and, where required, a notified body.
- Who signs the declaration?
- The manufacturer, taking responsibility for the product's compliance. Where an authorised representative is mandated, it may keep the declaration available but the manufacturer remains responsible.