Cyber Resilience Act
CRA conformity assessment: choosing the procedure
A CRA conformity assessment shows that a product with digital elements meets the essential requirements in Annex I before it carries the CE marking. Most products can use internal control, while important products in Annex III and critical products in Annex IV need harmonised standards, a notified body or a certification scheme.
Free plan, no card required.
When conformity assessment applies
Conformity assessment, the EU declaration of conformity and the CE marking apply to products placed on the market from 11 December 2027. Chapter IV of the Regulation, which lets Member States notify the bodies that will assess products, has applied since 11 June 2026 so that those bodies can be in place in time.
Products placed on the market before December 2027 do not need a CRA conformity assessment unless they are substantially modified afterwards, but their manufacturers must already report under Article 14.
Which procedure for which product
Article 32 sets the routes. The category of the product decides how much independent checking is needed. The Commission described the important and critical categories technically in Implementing Regulation (EU) 2025/2392.
| Product category | Possible procedures |
|---|---|
| Default products | Internal control (module A); EU-type examination with conformity to type (modules B and C); full quality assurance (module H); or an EU cybersecurity certification scheme |
| Important, class I (Annex III) | Module A only when harmonised standards, common specifications or a certification scheme at level substantial are applied in full; otherwise modules B and C, or H |
| Important, class II (Annex III) | Modules B and C, module H, or a certification scheme at least at level substantial |
| Critical (Annex IV) | A European cybersecurity certification scheme where a delegated act requires one; otherwise the class II routes |
Important and critical product categories
Annex III lists 19 class I categories, among them identity and privileged-access management, browsers, password managers, VPNs, operating systems, routers, modems and switches, smart-home security products and connected toys, and four class II categories: hypervisors and container runtimes, firewalls and intrusion detection or prevention systems, and tamper-resistant microprocessors and microcontrollers. Annex IV lists three critical categories, including smart meter gateways and smartcards.
Free and open-source products in Annex III may use internal control if their technical documentation is made public.
Harmonised standards
Applying a harmonised standard gives a presumption of conformity and opens the internal-control route for class I products. The Commission's standardisation request M/606 of 3 February 2025 asks CEN, CENELEC and ETSI for 41 European standards, with deadlines between August 2026 and October 2027. Until references are published in the Official Journal, manufacturers work from the Annex I requirements directly and from existing standards they judge relevant.
The EU declaration of conformity and CE marking
Once the assessment is done, the manufacturer draws up the EU declaration of conformity following Annex V, takes responsibility for the product's compliance by signing it, and affixes the CE marking. The declaration and the technical documentation are kept for at least ten years after the product is placed on the market or for the support period, whichever is longer.
- Technical documentation per Annex VII, including the SBOM and vulnerability-handling process.
- Test and review records showing how each Annex I requirement is met.
- The chosen conformity assessment procedure and, where needed, the notified body's certificate.
- The signed EU declaration of conformity.
Common mistakes to avoid
Most delays in conformity work come from evidence that was never recorded rather than from the assessment itself.
- Classifying the product late, after the design makes a stricter procedure expensive.
- Treating the SBOM as a one-off export instead of a record kept per release.
- Leaving the support period undecided, although it shapes the whole vulnerability-handling commitment.
- Assessing the device but not the remote data processing solutions it depends on.
- Keeping test results and decisions in e-mails instead of in the technical documentation.
Available in KROMSE today
KROMSE does not run conformity assessments today; it produces evidence that goes into the technical file.
- SBOMs in CycloneDX and SPDX for every scan.
- Known-vulnerability, secrets and misconfiguration findings with the evidence and coverage limits of each scan.
- Recorded human decisions and a signed audit-log export.
- A CRA evidence pack in JSON and PDF.
Coming next
On the roadmap, not available yet. Dates are targets, not promises; this page changes the day a capability is live.
- Coming · Q4 2026CRA conformity assessment. A guided workflow will map your evidence to the Annex I requirements, for a person to review and complete.
- Coming · Q4 2026EU Declaration of Conformity generator. KROMSE will draft the EU Declaration of Conformity from your product record, for your signatory to check and sign.
- Coming · Q1 2027Machinery Regulation evidence. KROMSE will collect evidence for the cybersecurity-related requirements of the EU Machinery Regulation (EU) 2023/1230, next to your CRA record.
Frequently asked questions
Do all products need a notified body under the CRA?
No. Most products with digital elements can use internal control, where the manufacturer assesses conformity itself. A notified body or certification is needed for important class II and critical products, and for class I products when harmonised standards or equivalent specifications are not applied in full.
When is CE marking under the CRA required?
For products placed on the EU market from 11 December 2027. Before then, and for products placed on the market earlier and not substantially modified, the CRA's conformity requirements do not apply, although Article 14 reporting already does.
Is IEC 62443 a harmonised standard for the CRA?
Not as of this review. The Commission's standardisation request M/606 asks European standards bodies for new CRA standards and does not reference IEC 62443. The IEC 62443 series remains useful evidence, especially for industrial products, but applying it does not by itself give a presumption of conformity.
What is module A in the Cyber Resilience Act?
Module A is internal control: the manufacturer checks that the product meets the essential requirements, prepares the technical documentation and declares conformity on its sole responsibility, without a notified body. It is available for default products and, under conditions, for important class I products.
Who signs the EU declaration of conformity?
The manufacturer. By drawing up and signing the declaration it takes responsibility for the product's compliance. The declaration follows the model in Annex V and must be kept, together with the technical documentation, for the required period.