Answer the questions and see the reasoning.
The three module-based procedures
Module A is internal control: the manufacturer carries out the assessment and takes responsibility for demonstrating conformity. It is a substantive procedure with technical documentation and checks, not simply ticking a declaration.
Modules B+C combine EU-type examination by a notified body with conformity to the approved type based on internal production control. Module H uses full quality assurance with notified-body involvement. Annex VIII sets out the procedures.
Default products retain a choice
For a Default product, Article 32(1) permits internal control, B+C or H. A qualifying European cybersecurity certification scheme may also be relevant where the Commission has provided the necessary legal basis.
The absence of a harmonised standard does not by itself remove Module A for Default products. The manufacturer still needs to show how the essential requirements are met, based on a cybersecurity risk assessment and adequate evidence.
Class I: coverage matters
For Important Class I, internal control depends on applying the relevant harmonised standards, common specifications or qualifying certification under Article 32(2). Their availability, applicability and coverage of requirements matter.
An international standard, a draft European standard or an unrelated certificate is not automatically a CRA presumption of conformity. Where the statutory conditions are not met, the relevant requirements need an assessment using B+C or H. Check the current Official Journal references and adopted measures.
Class II, Critical and the FOSS exception
Important Class II generally requires B+C or H, with any certification route subject to its legal conditions. Critical categories follow Article 32(4): a mandatory certification requirement depends on the relevant delegated act; otherwise the Class II procedures apply.
Article 32(5) provides a specific internal-control option for Important Class I and Class II products qualifying as FOSS, if the technical documentation is made available to the public. It is not a blanket exception for proprietary products containing an open-source component, and it does not extend to Critical products.
Prepare the evidence before choosing a provider
Record the product boundary and category decision, map the applicable Annex I requirements and identify the evidence for each. If a notified body is required, verify the body’s notification scope and agree the relevant procedure.
Successful assessment supports the EU declaration of conformity and CE marking. The manufacturer remains responsible for the product and ongoing obligations even where a third party is involved. Reassess changes where they affect the original assessment.
Frequently asked questions
Can a Class I product always self-assess?
No. The conditions in Article 32(2), or the specific FOSS exception in Article 32(5), need to be met.
Is ISO 27001 a CRA product conformity certificate?
An organisational information-security certificate does not by itself establish conformity of a product with the CRA or satisfy an Article 32 certification route.
Does the tool verify that a standard is currently harmonised?
No. The route finder asks you to confirm legal applicability and coverage. Check official references and the source review date before relying on a particular standard.