This document is under active development and has not been finalised.
Skip to content

Comprehensive Quality Assurance (Module H)

Overview

Comprehensive quality assurance under Module H is an alternative conformity assessment procedure for Class II products. Unlike Module B+C, this approach does not examine a single type specimen but rather the manufacturer's entire quality management system.

LEGAL BASIS

Art. 24(2) CRA: For Class II products, as an alternative to the EU type examination (Module B+C), comprehensive quality assurance (Module H) may be applied.

Annex VIII, Module H of the CRA describes the requirements for the quality management system.

Applicability

CategoryModule H applicable?
DefaultNo – Module A sufficient
Class INo – Module A* or B+C
Class IIYes (Alternative to Module B+C)
CriticalNo – EUCC required

Module H vs. Module B+C

CriterionModule B+CModule H
Object of assessmentIndividual type specimenEntire QMS
Suitable forFew product variantsMany product variants
PrerequisiteTechnical documentationCertified QMS
AdvantageFocused, faster for single productsCovers all products under the QMS
DisadvantageEach new product examined individuallyHigher initial effort
Recommended when1-3 Class II products4+ Class II products

Procedure

1. Build a Quality Management System

The QMS must cover the following areas:

Design Phase (Security by Design)

  • Cybersecurity requirements in product specifications
  • Threat modelling and risk assessment
  • Secure architecture principles
  • Security reviews in the design process

Development Phase (Secure Development)

  • Secure development guidelines (secure coding guidelines)
  • Code reviews with security focus
  • Static code analysis (SAST)
  • Dependency management and vulnerability scanning

Test Phase (Security Testing)

  • Dynamic analysis (DAST)
  • Penetration testing
  • Fuzzing
  • Integration testing of security functions

Production Phase (Secure Build & Release)

  • Reproducible builds
  • Signing of all artefacts (Cosign)
  • SBOM generation per release (SBOM Lifecycle)
  • Supply chain integrity verification

Operations Phase (Post-Market Surveillance)

2. Notified Body for QMS Assessment

  • Identify body via NANDO database
  • Body must be notified for CRA QMS assessments
  • Contract covering audit scope and surveillance intervals

3. QMS Audit

The notified body examines:

  1. QMS documentation – Process descriptions, policies, procedures
  2. Implementation – Whether documented processes are actually followed
  3. Effectiveness – Whether processes achieve the required cybersecurity level
  4. Annex I coverage – Whether all essential requirements are covered by the QMS

4. QMS Certificate

Upon successful audit, the notified body issues a QMS certificate. All products manufactured under this QMS are considered conformity-assessed.

5. Surveillance

  • Periodic audits by the notified body (typically annually)
  • Unannounced inspections are possible
  • Re-certification for significant changes to the QMS

Integration with Existing Standards

Module H integrates well with existing management systems:

StandardSynergy with Module H
ISO 27001 (ISMS)High overlap with security controls
ISO 9001 (QMS)Base QMS structure reusable
IEC 62443 (Industrial Security)Relevant for industrial IoT products
ISO/SAE 21434 (Automotive)Relevant for automotive software

LEVERAGE SYNERGIES

If a certified ISO 27001 or ISO 9001 management system already exists, it can serve as a foundation for the CRA QMS. The cybersecurity-specific requirements from Annex I must be supplemented.

Timeline

PhaseEstimated Duration
QMS build / extension6-12 months
Internal audits2-4 weeks
Selection of notified body2-4 weeks
External audit4-8 weeks
Remediation2-8 weeks
Certificate issuance1-2 weeks
Totalapprox. 9-15 months

Costs

Cost FactorEstimated Range
QMS build (internal/external)EUR 20,000 - 80,000
Initial auditEUR 15,000 - 40,000
Annual surveillance auditsEUR 5,000 - 15,000
Re-certification (every 3 years)EUR 10,000 - 30,000

Note: Values serve as guidance. With an existing ISO 27001/9001, the effort is significantly reduced.

Checklist: Module H

  • [ ] Product classification completed (Class II confirmed)
  • [ ] Decision Module H vs. Module B+C made and justified
  • [ ] QMS built or existing QMS extended
  • [ ] All phases covered (design, development, test, production, operations)
  • [ ] Annex I requirements embedded in QMS
  • [ ] Internal audits conducted
  • [ ] Notified body identified and contacted (NANDO)
  • [ ] Contract with notified body concluded
  • [ ] External audit passed / remediation implemented
  • [ ] QMS certificate received
  • [ ] Surveillance plan agreed
  • [ ] EU Declaration of Conformity issued (Template)
  • [ ] CE marking with notified body identification number

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT