Compliance journey
CRA conformity assessment routes
Self-assessment or a notified body? How you prove compliance depends on your product's risk class.
Once you know your product is in scope and you have met the essential requirements, you still have to demonstrate that formally. That is what conformity assessment is: the procedure by which a manufacturer shows a product meets the CRA before affixing the CE marking. The CRA offers several routes, and the one available to you is driven mainly by your product's risk class.
The three risk classes, quickly
- Default — most products. Lower systemic risk.
- Important — listed in Annex III, split into class I and the higher class II. Examples include things like password managers, network management tools, and certain security-relevant components.
- Critical — listed in Annex IV. The highest-risk categories, where the strongest assurance is expected.
The routes (assessment "modules")
The CRA reuses the EU's standard toolbox of conformity-assessment modules. In plain terms, the choices are:
Internal control (self-assessment)
The manufacturer performs the assessment itself: it builds the product to the essential requirements, compiles the technical documentation, and takes responsibility by drawing up the EU Declaration of Conformity. No external body is involved. This is the lightest route and is generally available for default products — and, importantly, for important products when the manufacturer fully applies the relevant harmonised standards (or common specifications / a European cybersecurity certification scheme) that cover the requirements.
Third-party assessment (notified body)
An independent, accredited organisation — a notified body — examines the product and/or the manufacturer's quality processes and issues a certificate. The main forms are:
- Type examination + production conformity — the body examines a representative sample ("the type"), then the manufacturer ensures ongoing units match it.
- Full quality assurance — the body assesses and audits the manufacturer's quality management system covering design and production.
Third-party assessment becomes necessary for important class II products where you cannot (or choose not to) rely fully on harmonised standards, and it is the expectation for the most sensitive critical products, which may also require a European cybersecurity certificate at a defined assurance level.
How to choose your route — a simple flow
- Is the product Default? → Self-assessment (internal control).
- Is it Important (Annex III)? → Self-assessment if you fully apply the relevant harmonised standards / common specs / certification scheme; otherwise a notified-body route.
- Is it Critical (Annex IV)? → Expect third-party assessment, and potentially mandatory certification at a set assurance level.
Whatever the route, you still produce these
- Technical documentation — the evidence file: risk assessment, how each essential requirement is met, test results, SBOM, support-period decision, and update mechanism.
- EU Declaration of Conformity — your signed statement that the product conforms.
- CE marking — affixed once the applicable procedure is complete.
Keep the documentation current for the product's support period and available for market-surveillance authorities on request.
General information, not legal advice. The binding rules on modules and classes are in Regulation (EU) 2024/2847 and its annexes.