CRA conformity assessment is where the Cyber Resilience Act becomes expensive. Read Annex III of the Cyber Resilience Act and you will find that important class I products can self-assess. Read Article 32(2) and check the Official Journal, and you will find they currently cannot.
As things stand, every product in Annex III or Annex IV needs a notified body — with one exception, which is available only to open-source software. This is the most expensive fact in the Regulation and it is not visible from a plain reading of the annexes.
The four CRA conformity assessment procedures

Article 32(1) of Regulation (EU) 2024/2847 offers four routes, and Annex VIII sets out what each involves.
| Route | What it is |
|---|---|
| Module A | Internal control. Self-assessment; no notified body |
| Module B + C | EU-type examination by a notified body, followed by conformity to type based on internal production control |
| Module H | Full quality assurance — an approved quality system covering design, development, final inspection and vulnerability handling, under continuing surveillance |
| Certification scheme | A European cybersecurity certification scheme under Article 27(9), where available and applicable |
Which are available depends on the tier.
| Tier | Routes available |
|---|---|
| Default | Any, including module A |
| Important class I | Module A only where harmonised standards, common specifications or a certification scheme at assurance level at least “substantial” exist and are applied in full. Otherwise module B+C or module H |
| Important class II | Module B+C, module H, or a certification scheme at level at least “substantial”. Never module A |
| Critical | A certification scheme under Article 8(1); or, where the Article 8(1) conditions are not met, any class II route |
The CRA conformity assessment condition in Article 32(2), and why it is not met
Article 32(2) bites in two situations. Where the manufacturer has not applied, or has applied only in part, harmonised standards, common specifications or a qualifying certification scheme — or where such instruments do not exist.
The second limb is the operative one today, because no harmonised standard has been cited in the Official Journal under Regulation (EU) 2024/2847.
That can be established four ways, and all four agree:
- An EUR-Lex legislation search on the Regulation number returns only the Regulation itself — no implementing or delegated act citing standards.
- The Regulation’s own EUR-Lex record shows no amendments and no linked implementing acts.
- The Commission has no harmonised-standards page for this Regulation. It publishes one per instrument as soon as the first citation lands, so the absence of the page is stronger evidence than the absence of a search hit.
- A search for the CEN/CENELEC standardisation request surfaces nothing relevant.
One honest caveat on method: a standardisation request issues as a C-series Commission Implementing Decision, which is not reliably full-text searchable on EUR-Lex. So point 4 cannot prove no request was issued — and in fact Article 27(1) makes the request mandatory for the Commission, so one has almost certainly been made.
It does not matter. A request confers nothing. Only a citation in the Official Journal creates a presumption of conformity, and there is none.
No common specification exists either, and the structure of Article 27(2) explains why one could not yet. A common specification may be adopted only where the Commission has requested a harmonised standard and the request was not accepted, or the standards were not delivered on time, or they do not comply with the request — and no reference has been published and none is expected within a reasonable period. The fallback is conditioned on the primary route having failed. That route has not concluded.
What follows for CRA conformity assessment
All 19 Annex III class I categories currently require a third-party CRA conformity assessment. Class I nominally has a self-assessment option; the precondition for it does not exist.
All 4 class II categories require it too, but that was always so — Article 32(3) never offered module A.
All 3 Annex IV critical categories require it. Article 8(1) empowers the Commission to determine by delegated act which critical products must obtain a European cybersecurity certificate, but only where a scheme covering them has been adopted and is available to manufacturers. No such delegated act exists, and Article 8(1) says expressly that in its absence, Annex IV products take the Article 32(3) routes — the class II ones.
A second route from 26 March 2027: Article 32(5a)
Regulation (EU) 2025/327, the European Health Data Space, amends the CRA and inserts a new Article 32(5a) with effect from 26 March 2027. Under it, manufacturers of products classified as EHR systems under that Regulation demonstrate conformity with the CRA’s Annex I requirements using the conformity assessment procedure in Chapter III of Regulation (EU) 2025/327 — not the Article 32 procedures described here.
The same amendment extends Articles 13(4) and 31(3) to those products, so the combined risk assessment and the single technical documentation set reach EHR systems too. If you place an EHR system on the market, diarise that date.
The one CRA conformity assessment exception: Article 32(5)
There is a single exception, and it is narrow.
Article 32(5) provides that manufacturers of products qualifying as free and open-source software which fall under the Annex III categories shall be able to demonstrate conformity using one of the Article 32(1) procedures — which includes module A — provided that the technical documentation referred to in Article 31 is made available to the public at the time of the placing on the market.
Three conditions, all required:
- The product qualifies as free and open-source software — source openly shared, licensing providing free and open access, modifiability and redistributability.
- The technical documentation is made available to the public. The whole Annex VII file, not a summary.
- At the time of the placing on the market. Not afterwards, and not on request.
The price of self-assessment is publishing the technical file — which under Annex VII includes the system architecture description, the cybersecurity risk assessment, the test reports and the vulnerability handling process description. For an open-source project that is often acceptable and sometimes actively desirable. For a proprietary product the route does not exist at all.
If you rely on Article 32(5), record the qualification determination, where the documentation is published, and the date. A file published late does not satisfy the condition.
What a notified body does in a CRA conformity assessment
Two things surprise manufacturers coming to this from other Union legislation.
It assesses your processes, not only your product. Under module B the notified body examines the technical design and development against Annex I Part I and the vulnerability handling processes against Part II, and the certificate attests to both. Annex VIII Part II point 8 then requires the body to carry out periodic audits of those processes. It is a recurring examination of an operating system of work, not a one-off review of a document set.
It will test your own solutions. Annex VIII Part II point 4.4 requires the body, where harmonised standards have not been applied, to carry out examinations and tests to check that the solutions adopted by the manufacturer meet the corresponding essential requirements. On the current standards position that applies to every product, so expect your own design decisions to be examined directly rather than checked against a standard.
Two CRA conformity assessment formalities are worth knowing before you apply. Annex VIII Part II point 3.2 requires a written declaration that the same application has not been lodged with any other notified body — one body at a time, absolutely. And point 7 requires you to inform the body of all modifications to the approved type and the vulnerability handling processes that may affect conformity; such modifications require an addition to the original certificate, not merely a note.
CRA conformity assessment: module B+C or module H
Both bring recurring notified body involvement, so the choice is about how your product is built and released rather than which is lighter.
Module B+C suits a product with discrete, identifiable versions. The body examines a type; you then run production controls to keep manufactured units conforming to it. Every substantial change means going back for an addition to the certificate.
Module H suits continuously delivered software, because the body approves a quality system covering design, development, final inspection and vulnerability handling, and you maintain it across the support period under surveillance. That surveillance includes an assessment visit to your premises and access to design, development, production, inspection, testing and storage sites.
One consequence of the choice shows up on the product itself, and it runs opposite to the habit built under other Union legislation. Under Article 30(4), the notified body’s identification number follows the CE marking only where module H applies. A module B+C product does not carry the body’s number after the marking, even though a body was involved. Applying the usual habit here produces an incorrectly marked product — and improper use of the CE marking is directly observable and among the first things a market surveillance authority can check.
CRA conformity assessment paperwork is heavier without standards, not lighter
It is tempting to think the absence of harmonised standards leaves a gap in the technical documentation. It does the opposite.
Annex VII point 5 requires the file to list the harmonised standards, common specifications and certification schemes applied in full or in part — and, where they have not been applied, descriptions of the solutions adopted to meet the Annex I requirements, including a list of other relevant technical specifications applied. Where an instrument is applied only partly, the documentation must specify which parts.
So citing a standard would have been the light option. Demonstrating conformity directly against each of the thirteen Annex I Part I properties and the eight Part II requirements, with evidence, is substantially more work — and it is the work the Regulation always contemplated for the case where no standard exists.
One trap to avoid: if you apply a respected international standard as your chosen solution, record it in Annex VII point 5 as a technical specification. Do not put it in element 6 of the EU declaration of conformity, which asks for the standards “in relation to which conformity is declared”. Doing so asserts a presumption of conformity that does not exist and misstates the basis of the declaration.
Book your CRA conformity assessment early, because capacity is new
Chapter IV — the designation and notification of conformity assessment bodies — has applied since 11 June 2026. Bodies can already be designated. That is what makes “book your notified body” actionable advice rather than an aspiration.
But the pool is new, every manufacturer faces the same 11 December 2027 deadline, and the assessment is not quick — particularly when the body has to test your own solutions rather than check them against a standard. Before applying, confirm the body is notified under this Regulation (designation under other Union legislation does not carry over), that its designation scope covers your product category, and what its lead time actually is.
If you are a smaller organisation, ask about fees. Article 32(6) requires the specific interests and needs of microenterprises and SMEs, including start-ups, to be taken into account in setting conformity assessment fees, and those fees to be reduced proportionately.
The CRA conformity assessment position will change
The first citation of a harmonised standard in the Official Journal flips nineteen class I categories from notified-body assessment to a self-assessment option overnight — for the requirements that standard covers, and only where you apply it in full. Partial application leaves you in Article 32(2).
Two other developments would matter as much. A delegated act under Article 27(9) specifying which European cybersecurity certification schemes can demonstrate conformity would be significant beyond the presumption itself: the issuance of a certificate at assurance level at least “substantial” eliminates the obligation to carry out a third-party conformity assessment for the corresponding requirements. For a manufacturer with several Annex III products, one scheme certificate could become cheaper than repeated type examinations. And a delegated act under Article 8(1) would change the route for critical products.
None of these exists as at 14 August 2026. Check the Official Journal and the Commission’s standards pages monthly, and record the negative findings as well as the changes — a dated negative is evidence your position was current, while an unrecorded check is indistinguishable from no check.
Making the CRA conformity assessment determination
Work through it in order, and record the reasoning at each step rather than only the answer:
- Is the product in scope at all?
- What tier — default, class I, class II, or critical? See CRA product classification.
- Does it qualify as free and open-source software, and will the technical documentation be published at placing on the market?
- Do harmonised standards, common specifications or a qualifying scheme exist for the applicable requirements? Today: no.
- If they exist, are they applied in full?
- For Annex IV, is there a delegated act under Article 8(1)? Today: no.
- Is the product also a high-risk AI system? If so, Article 12(3) prevents it reaching a lighter cybersecurity assessment through the AI Act’s internal-control procedure.
The EU CRA Toolkit carries that determination as a controlled procedure, with the standards position held in a single currency supplement so a citation is a one-document edit rather than a pack-wide sweep. The Regulation as a whole is covered in the EU CRA guide, and the obligation that arrives first — Article 14 reporting, from 11 September 2026 — in the CRA reporting deadline.