← Back to CRA Guide Last updated: September 5, 2026
EU Regulation 2024/2847 • Articles 32-33

CRA Conformity Assessment: How to Certify Your Product

The conformity assessment procedures manufacturers must follow to demonstrate CRA compliance. Self-assessment vs. third-party certification based on product classification.

What is Conformity Assessment?

Conformity assessment is the process of demonstrating that your product meets CRA requirements. The procedure you follow depends on your product's classification.

The Big Question

Can you self-assess, or do you need third-party certification?

Most products can use self-assessment (Module A), but Important Class I products require third-party assessment in practice (no harmonised CRA standards published as of 2026), and Class II and Critical products always require third-party involvement.

Conformity Assessment by Product Category

Default Products
Self-Assessment (Module A)

Internal control procedure. No third-party involvement required.

Examples: Consumer apps, games, productivity software, smart home devices
Important Class I
Third-Party Assessment Required in Practice

Module A self-assessment is only permitted once harmonised CRA standards are published and fully applied (Article 32). No harmonised CRA standards have been published as of 2026. You must engage a notified body for Module B+C or Module H until standards are published.

Examples: Password managers, VPN clients, browsers, routers
Important Class II
Third-Party Assessment Required

Module B+C (EU-type examination) or Module H (full quality assurance). Must involve a Notified Body.

Examples: Hypervisors, firewalls, container runtimes, SIEM systems
Critical
EU Cybersecurity Certification

Must obtain certification under the EU Cybersecurity Certification Framework.

Examples: Smart meters, HSMs, smartcard operating systems

Not sure which category your product falls into?

Take Classification Assessment →

Module A: Internal Control (Self-Assessment)

For Default products, Module A self-assessment applies. Class I products may only use Module A once harmonised CRA standards are published (Article 32) — no harmonised CRA standards exist as of 2026, so Class I products currently require third-party assessment.

1

Prepare Technical Documentation

Create documentation per Annex VII covering design, risk assessment, and security measures.

2

Conduct Internal Conformity Assessment

Verify your product meets all applicable Annex I requirements internally.

3

Draw Up EU Declaration of Conformity

Create the formal declaration stating compliance with CRA.

Declaration Template →
4

Apply CE Marking

Affix the CE marking to your product, packaging, and documentation.

5

Maintain Records for 10 Years

Keep technical documentation and declaration available for authorities.

Module B+C: EU-Type Examination

For Class II products, you need third-party assessment from a Notified Body.

Module B: EU-Type Examination

  • Submit technical documentation to Notified Body
  • Notified Body examines product design
  • Testing and evaluation performed
  • Certificate of EU-type examination issued

Module C: Conformity to Type

  • Production follows approved type
  • Internal production control maintained
  • Quality management for manufacturing
  • Products match certified design

⏰ Plan Ahead

Third-party assessment can take several months. Notified Bodies will be in high demand as the December 2027 deadline approaches. Start the process early.

What is a Notified Body?

A Notified Body is an organization designated by EU Member States to assess conformity of products. They are authorized third-party assessors.

How to Find a Notified Body

The EU maintains the NANDO database of Notified Bodies. Once CRA-specific bodies are designated (expected 2025-2026), they will be listed there.

Costs

Third-party assessment involves fees. Costs vary based on product complexity, typically ranging from €10,000 to €100,000+ for complex products.

⏱️

Timeline

Initial assessment typically takes 3-6 months. Plan to begin the process at least 12 months before you need to ship.

Technical Documentation (Annex VII)

Regardless of assessment type, you need technical documentation that includes:

  • General description: Product design and functionality
  • Risk assessment: Cybersecurity risk analysis per Article 13
  • Security design: How requirements are implemented
  • Vulnerability handling: Processes for Part II compliance
  • SBOM: Software Bill of Materials
  • Test reports: Evidence of security testing
  • Support period: Declared security support duration
  • User instructions: Security guidance for users

CE Marking

After successful conformity assessment, you must affix the CE marking:

CE Marking Rules

  • Visible, legible, and indelible
  • Minimum 5mm height
  • On product, packaging, or documentation
  • For Class II: includes Notified Body number

What CE Means

  • Product meets EU requirements
  • Conformity assessment completed
  • Technical documentation available
  • Legal to sell in EU market

Related CRA Articles

Determine Your Assessment Path

Take our free assessment to understand which conformity assessment procedure applies to your product.