Cyber Resilience Act
Conformity assessment procedures
Practical term
The conformity assessment procedures of the Cyber Resilience Act (CRA) are listed in Article 32; Annex VIII sets out the modules word for word. There are four: the internal control procedure (module A), EU-type examination followed by conformity to type based on internal production control (modules B and C), conformity based on full quality assurance (module H) and, where available and applicable, a European cybersecurity certification scheme under Article 27(9).
Modules A, B, C and H examine the same subject matter: the product against Part I of Annex I, and the processes put in place by the manufacturer against Part II. What differs is the depth of the examination and whether a third party takes part. For the certificate as the fourth route, the scope depends on which requirements the scheme covers.
Who may choose which procedure
- Unclassified products, meaning the large majority: all four procedures in Article 32(1) are open. In practice it is module A.
- Class I of Annex III: module A stays available as long as harmonised standards, common specifications or a certification scheme at assurance level at least “substantial” are applied in full. Partial application, or the absence of such standards, moves the product into modules B and C or module H under Article 32(2).
- Class II: a third party is always involved, so modules B and C, module H, or a scheme at assurance level at least “substantial”. Recital 91 confirms that this holds even where harmonised standards are applied in full.
- Critical products in Annex IV: a European certification scheme where the Commission has made one mandatory under Article 8(1), otherwise the class II procedures.
Critical products therefore travel a stricter route, without the requirements themselves changing. For class I, what matters is whether the manufacturer can cover the requirement at issue in full with a Harmonised standard, a common specification or a certification scheme. Recital 80 calls the timely availability of harmonised standards particularly important here, because it keeps the internal control procedure open and helps avoid bottlenecks and delays in the work of conformity assessment bodies.
The four modules at a glance
The modules differ in who examines, and in what the examination fastens on.
- Module A: internal control: internal control with no notified body involved. The manufacturer draws up the Technical documentation, declares conformity on its sole responsibility and affixes the CE marking. The normal case for unclassified products, and for class I products whose requirements a standard covers in full.
- Module B: EU-type examination: EU-type examination by a notified body. What is examined and certified is one specific type, together with the vulnerability handling processes.
- Module C: conformity to type: follows on from module B and covers manufacture. The manufacturer ensures that the products shipped match the certified type. It never stands on its own.
- Module H: full quality assurance: full quality assurance. What is assessed and then kept under surveillance is not a type but the quality system for design, development, final inspection and vulnerability handling. It can carry whole product categories, and pays off where many models and frequent changes come together.
The difference shows on the finished product as well. The notified body’s identification number follows the CE marking only where that body is involved in the module H procedure (Article 30(4)). After modules B and C the CE marking stands alone, even though a body examined the product there too.
The certificate as a fourth route
The fourth route has a name of its own: European cybersecurity certification scheme. A European cybersecurity certificate issued under such a scheme at assurance level at least “substantial” eliminates the obligation to have a third-party conformity assessment carried out under Article 32(2), points (a) and (b), and Article 32(3), points (a) and (b). Two limits come with it. The relief reaches only as far as the certificate covers the requirements, and it applies only to schemes the Commission has specified for that purpose by delegated act under Article 27(9).
An exception for open-source products
A second shortcut sits in Article 32(5). Manufacturers of products qualifying as Free and open-source software that also fall under a category in Annex III may use any procedure in Article 32(1), module A included, even though the classification would otherwise push them into modules B and C or module H. The condition is that the technical documentation is made available to the public at the time the product is placed on the market. What is eased is the route, not the yardstick. Annex I applies unchanged.
What the CRA leaves open
Three questions that surface immediately in planning go unanswered in the Regulation. It sets no deadline within which a notified body must complete a procedure. It fixes no period of validity for the EU-type examination certificate, leaving it to the body to attach conditions. And it says nothing about how a later switch between modules is to be handled.
One relief for small suppliers is expressly regulated. Microenterprises and small enterprises may provide all elements of the technical documentation in a simplified format, for which the Commission specifies a form, and notified bodies must accept that form (Article 33(5)). Anyone who needs a body should still book the slot early. The chapter on the notification of conformity assessment bodies (Articles 35 to 51) applies from 11 June 2026, whereas the duty to carry out a conformity assessment applies only from the general date of application, 11 December 2027 (Article 71(2)).
Practical questions
-
Yes, the manufacturer picks the body freely. Two conditions attach: the application goes to a single body, and it must carry a written statement that the same application has not been lodged with any other body (Annex VIII, Part II, point 3). The language consequence in Article 31(4) is often missed: the technical documentation and all correspondence relating to the procedure must be drawn up in an official language of the Member State where the body is established, or in a language that body accepts. Choosing the body therefore also decides your translation effort.
-
Not on that ground alone. Article 7(1) states expressly that integrating a product which has the core functionality of an Annex III category does not in itself make the product it is integrated into subject to the procedures in Article 32(2) and (3). What governs is the core functionality of your own product. If that product falls under no Annex III category, the choice in Article 32(1) remains open. What this leaves untouched is due diligence for third-party components under Article 13(5).
-
As a rule the relevant procedure under Article 43 of Regulation (EU) 2024/1689. Notified bodies competent there for high-risk AI systems may also check the Annex I requirements of the CRA, provided their compliance with Article 39 CRA was assessed during their notification. Article 12(3) reverses that for one group of cases. Important products in Annex III and critical products in Annex IV that would otherwise face only internal control under Annex VI of the AI Regulation go through the CRA procedures as far as the cybersecurity requirements are concerned. The stricter route prevails.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.