Cyber Resilience Act
Presumption of conformity
Practical term
The presumption of conformity is the central evidentiary relief in the Cyber Resilience Act (CRA). Article 27 attaches it to published rulebooks: comply with one and your product is taken to meet the essential cybersecurity requirements in Annex I, without deriving compliance requirement by requirement.
It is not an exemption from the obligation. Article 6 still governs: a product with digital elements may be made available on the market only where it meets Part I of Annex I and the processes put in place by the manufacturer meet Part II. The presumption shifts how compliance is shown, not the standard against which it is measured.
Three routes, and no others
Article 27 recognises exactly three: the harmonised standard (paragraph 1), the common specification (paragraph 5) and the European cybersecurity certification scheme (paragraph 8).
- For a harmonised standard, the effect begins only when the reference is published in the Official Journal of the European Union. The Commission requests the drafting under Article 10(1) of Regulation (EU) No 1025/2012.
- A common specification is the fallback. Under paragraph 2 the Commission may lay one down only where a standardisation request was not accepted, the standards were not delivered on time or did not comply with the request, and where no reference to a suitable harmonised standard has been published in the Official Journal and none is expected within a reasonable period. Once the reference of a harmonised standard is published in the Official Journal, paragraph 6 obliges the Commission to repeal the implementing acts, or the parts of them, that cover the same essential cybersecurity requirements.
- For a certification scheme, the presumption rides on an EU statement of conformity or a European cybersecurity certificate issued under a scheme adopted pursuant to Regulation (EU) 2019/881.
Nothing else creates it. A company standard, a supplier declaration or a test mark may well evidence compliance, but the full burden of demonstration then stays with the manufacturer.
The reach stops where the rulebook stops
All three paragraphs carry the same limit: conformity is presumed only for those requirements that the rulebook, or parts of it, cover. Two consequences follow that are routinely underrated.
First, the presumption is divisible. Where a standard covers six of twelve applicable requirements, nothing changes for the other six. Second, Article 27 covers not only the product but expressly also the processes put in place by the manufacturer. The presumption can therefore reach Part I and Part II of Annex I alike, but only as far as the rulebook covers both. Standards describing product properties often say little about vulnerability handling.
What it saves in choosing a procedure
The tangible effect shows up with important products with digital elements. For class I under Annex III, Article 32(2) applies: where the manufacturer has not applied, or applied only in part, harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least “substantial”, or where none exist, the product must go through EU-type examination followed by production control (modules B and C) or full quality assurance (module H). Both routes involve a notified body.
Read the other way round: apply the rulebooks in full and a class I product can stay with the internal control procedure under module A, which Article 32(1), point (a), opens up. The presumption of conformity decides the cost and the schedule of an entire project here.
For class II a third party is involved regardless: Article 32(3) allows only modules B and C, module H, or, where available and applicable, a European certification scheme under Article 27(9) at assurance level at least “substantial”. For both classes, Article 27(9) itself has a further effect: where a European cybersecurity certificate at assurance level at least “substantial” is issued under a scheme the Commission has specified by delegated act, the obligation to have a third-party conformity assessment carried out under Article 32(2), points (a) and (b), and Article 32(3), points (a) and (b), falls away for the corresponding requirements.
Documentation duties, especially when you opt out
Annex VII, point 5 requires the technical documentation to list the harmonised standards applied in full or in part whose references have been published in the Official Journal, the common specifications and the European cybersecurity certification schemes. Where they are applied in part, the documentation must state which parts.
Applying none of them does not mean less paperwork; it means more. In that case you have to describe the solutions adopted to meet the requirements in Parts I and II of Annex I, together with a list of the other technical specifications applied. Forgoing the presumption is permitted, but it moves the work into the documentation.
A presumption is rebuttable
It does not bind market surveillance. Where an authority has sufficient reason to believe that a product presents a significant cybersecurity risk, Article 54(1) has it carry out its own conformity assessment without delay, where relevant in cooperation with the CSIRT concerned and whatever standards the manufacturer applied.
The CRA explicitly anticipates faulty rulebooks. Article 54(6), point (b) names shortcomings in harmonised standards, European cybersecurity certification schemes or common specifications as a possible cause of non-compliance. Where a national measure turns out to be justified and a standard is at fault, the Commission triggers the procedure under Article 11 of Regulation (EU) No 1025/2012 (Article 55(3)). Where a scheme or a common specification is at fault, it considers whether the underlying act should be amended or repealed (Article 55(4) and (5)).
Two other presumptions that are not this one
The term appears in two further places in the CRA that have nothing to do with Article 27. Article 40 concerns conformity assessment bodies themselves: a body that demonstrates it meets the criteria of the relevant harmonised standards whose references have been published in the Official Journal is presumed to meet the requirements of Article 39, in so far as those standards cover them. And Annex VIII, Part IV, point 3.3 has the notified body presume conformity with the requirements of point 3.2 for those elements of the quality system that comply with the corresponding specifications of the national standard implementing the relevant harmonised standard or technical specification.
Practical questions
-
No. Article 27 attaches the presumption to three groups only: harmonised standards whose references are published in the Official Journal, common specifications adopted by the Commission, and European cybersecurity certification schemes under Regulation (EU) 2019/881. An ISO certificate belongs to none of them. That does not make it worthless: where the rulebooks in Article 27 are not applied, Annex VII, point 5 requires you to describe the solutions adopted and to list the other relevant technical specifications applied, and under module H the standards applied belong in the quality system documentation anyway (Annex VIII, Part IV, point 3.2). The burden of showing each individual Annex I requirement still sits with the manufacturer.
-
Not automatically. Article 27(8) grants the presumption for the product and the processes the statement or certificate was issued for, and even then only in so far as they cover the requirements. A certified module inside a larger product carries at most the requirements relating to that module. Interaction, configuration and everything your product does beyond it you evidence yourself, and Article 13(5) requires due diligence when integrating third-party components in any case. Treat the supplier’s certificate as a building block of the technical documentation, not as a substitute for your own assessment.
-
Article 27(1) requires a reference published in the Official Journal. Once it is gone, the standard no longer carries the presumption, while the Annex I requirements stay exactly as they were. Compliance then has to be demonstrated independently for the requirements concerned. The CRA does not spell out what happens to products already placed on the market; Article 55(3) only provides that where a national measure is considered justified and the non-compliance is attributed to shortcomings in the harmonised standards, the Commission triggers the procedure under Article 11 of Regulation (EU) No 1025/2012.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.