The permitted CRA conformity assessment route depends on product classification and additional conditions. Default products can generally use internal control; important and critical products need a closer Article 32 analysis.
Apply this to your product

Answer the questions and see the reasoning.

Open conformity assessment

The three module-based procedures

Module A is internal control: the manufacturer carries out the assessment and takes responsibility for demonstrating conformity. It is a substantive procedure with technical documentation and checks, not simply ticking a declaration.

Modules B+C combine EU-type examination by a notified body with conformity to the approved type based on internal production control. Module H uses full quality assurance with notified-body involvement. Annex VIII sets out the procedures.

Article 32(1); Annex VIIICRA text

Default products retain a choice

For a Default product, Article 32(1) permits internal control, B+C or H. A qualifying European cybersecurity certification scheme may also be relevant where the Commission has provided the necessary legal basis.

The absence of a harmonised standard does not by itself remove Module A for Default products. The manufacturer still needs to show how the essential requirements are met, based on a cybersecurity risk assessment and adequate evidence.

Articles 13, 27 and 32(1)CRA text

Class I: coverage matters

For Important Class I, internal control depends on applying the relevant harmonised standards, common specifications or qualifying certification under Article 32(2). Their availability, applicability and coverage of requirements matter.

An international standard, a draft European standard or an unrelated certificate is not automatically a CRA presumption of conformity. Where the statutory conditions are not met, the relevant requirements need an assessment using B+C or H. Check the current Official Journal references and adopted measures.

Class II, Critical and the FOSS exception

Important Class II generally requires B+C or H, with any certification route subject to its legal conditions. Critical categories follow Article 32(4): a mandatory certification requirement depends on the relevant delegated act; otherwise the Class II procedures apply.

Article 32(5) provides a specific internal-control option for Important Class I and Class II products qualifying as FOSS, if the technical documentation is made available to the public. It is not a blanket exception for proprietary products containing an open-source component, and it does not extend to Critical products.

Prepare the evidence before choosing a provider

Record the product boundary and category decision, map the applicable Annex I requirements and identify the evidence for each. If a notified body is required, verify the body’s notification scope and agree the relevant procedure.

Successful assessment supports the EU declaration of conformity and CE marking. The manufacturer remains responsible for the product and ongoing obligations even where a third party is involved. Reassess changes where they affect the original assessment.

Articles 13, 28–32; Annexes V, VII and VIIICRA text

Frequently asked questions

Can a Class I product always self-assess?

No. The conditions in Article 32(2), or the specific FOSS exception in Article 32(5), need to be met.

Is ISO 27001 a CRA product conformity certificate?

An organisational information-security certificate does not by itself establish conformity of a product with the CRA or satisfy an Article 32 certification route.

Does the tool verify that a standard is currently harmonised?

No. The route finder asks you to confirm legal applicability and coverage. Check official references and the source review date before relying on a particular standard.

This guide supports an initial assessment. Your result depends on the product facts and the applicable measures. Read how to use this guidance.