This document is under active development and has not been finalised.
Skip to content

Chapter 8: Conformity Assessment

8.1 Overview

The Conformity Assessment is the formal demonstration that a product with digital elements meets the essential cybersecurity requirements of the CRA. The type of assessment depends on the Product Classification.

LEGAL BASIS

Art. 24 CRA: The manufacturer shall carry out a Conformity Assessment before placing a product on the market. The procedure depends on the product category.

Art. 28 CRA: Following a successful Conformity Assessment, the manufacturer shall draw up an EU Declaration of Conformity and affix the CE marking.

8.2 Assessment Procedures by Product Category

CategoryProcedureDescription
StandardModule A (Internal Control)Manufacturer self-assessment
Class IModule A* or Module B+CSelf-assessment (where harmonised standards apply) or type examination
Class IIModule B+C or Module HType examination or comprehensive QA
CriticalEUCCEuropean Cybersecurity Certificate

* Module A for Class I only where harmonised standards are applied in full

8.3 Chapter Structure

SectionTopicDescription
8.1Internal Control (Module A)Self-assessment for Default and Class I*
8.2EU Type Examination (Module B+C)External examination for Class I and Class II
8.3Comprehensive Quality Assurance (Module H)QMS-based for Class II
8.4European Cybersecurity Certificate (EUCC)Certification for critical products (Annex IV)
8.5Product ClassificationCRA risk classes and classification
8.5aProduct Lists (Annex III & IV)Complete product category lists
8.5bCE Marking (Art. 29–30)CE marking requirements
8.6EU Declaration of ConformityAnnex V CRA, CE marking
8.7Simplified DoC (Annex VI)Annex VI: Abbreviated Declaration of Conformity
8.8User Information (Annex II)Annex II: Mandatory information for users

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT