Cyber Resilience Act

Conformity assessment

Legal definition Art. 3(27) CRA

“the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled”
Regulation (EU) 2024/2847, Art. 3(27) CRA

Conformity assessment is the process by which a manufacturer establishes and evidences that its product meets the essential cybersecurity requirements in Annex I. It is the precondition for the EU declaration of conformity and the CE marking.

What is assessed matters: the product and the processes put in place by the manufacturer. Annex I has two parts (product properties in Part I, vulnerability handling in Part II), and both belong in the assessment.

The four routes

Article 32 names four conformity assessment procedures. Three of them rest on the modules in Annex VIII:

  • Internal control (Module A): the manufacturer assesses on its own, without an external body. It compiles the technical documentation, carries out the assessment and declares conformity.
  • EU type-examination followed by conformity to type (Modules B and C): a notified body examines a type; the manufacturer then ensures production matches it.
  • Full quality assurance (Module H): a notified body assesses and monitors the manufacturer’s quality system as a whole.

The fourth route is, where available and applicable, a European cybersecurity certification scheme under Article 27(9). Which route is available depends on the product category. For most products Module A is enough. For the categories classed as important or critical, the Cyber Resilience Act (CRA) sets stricter requirements. That is where a notified body enters, unless conformity can be presumed by another route.

The shortcut through harmonised standards

Applying a Harmonised standard in full lets you rely on the presumption of conformity: the product is deemed compliant with the requirements the standard covers. That simplifies the demonstration considerably, because not every requirement has to be derived individually.

The practical catch: harmonised standards for the CRA are still being developed. Until they exist, compliance has to be evidenced another way, for example through recognised standards without harmonised status or through your own carefully documented reasoning.

What has to exist at the end

Whichever route is chosen, the outcome must be verifiable: Technical documentation supporting the assessment, and an EU declaration of conformity. Both must be kept available to market surveillance authorities for at least ten years after placing on the market. If the support period runs longer, that longer period applies.

For planning this means assessment is not an event shortly before launch but a process running alongside development. Its evidence is created where decisions are made, not retrospectively.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.