On this page
- CRA assessment modules A, B, C and H are in Annex VIII.
- Important Class I and Class II have different conditions under Article 32.
- A harmonised standard gives a presumption only for covered requirements when its reference is published in the Official Journal.
- A generated declaration stays a draft until the required assessment and accountable signature are complete.
Which conformity-assessment route applies?
Article 32 and Annex VIII define the procedures. Classification is the starting point; applicable standards, specifications, certification schemes and delegated acts determine the next step. This is a planning summary, not a final route decision.
What do the modules mean?
Module A is manufacturer internal control. Module B is EU-type examination by a notified body; module C then addresses conformity to the approved type through internal production control. Module H covers full quality assurance assessed by a notified body. All appear in Annex VIII of the CRA.
Annex VI is the simplified EU declaration, not an assessment module. Annex V contains the full declaration model and Annex VII the technical documentation. Correct references matter when specifying deliverables to a consultant or assessment body.
What does a harmonised standard establish?
Article 27 limits presumption of conformity to requirements covered by the standard or relevant part, where its reference is published in the Official Journal. A draft standard, generic security certificate or familiar ISO framework does not automatically establish that presumption.
Record the edition, Official Journal reference, covered requirements, implementation evidence and uncovered requirements. Check the legal position at assessment time instead of copying an old standards list. The classification guide explains why technology stack cannot select the route.
What should the manufacturer prepare?
Start with product boundary and classification rationale, then assemble the risk assessment, requirement mapping, verification results and vulnerability-handling process. Use the technical-documentation guide to organise evidence. If a third party is required, confirm its notified or certification scope before planning the engagement.
An evidence system can retain artifacts and review history. It does not perform a notified-body assessment, issue a European cybersecurity certificate or assume manufacturer responsibility. Record external assessment results separately from internal evidence approval.
When can declaration and CE marking be completed?
Articles 28-30 govern the declaration and marking. The manufacturer assumes responsibility through the declaration; the required assessment must support it. A generated Annex V template remains a working document until product identity, legal references, assessment results and an authorised signature are in place.
Retain the signed declaration with its evidence and version. A later release must not silently inherit an assessment whose scope no longer covers it. Review changed functions and security properties before deciding whether previous evidence remains relevant.
Frequently asked questions
Which annex contains the CRA assessment modules?
Annex VIII contains modules A, B, C and H. Annex V is the full EU declaration model, Annex VI the simplified declaration, and Annex VII the technical documentation.
Can Important Class II use internal control if it follows standards?
No. Article 32(3) specifies B plus C, H, or an available and applicable European cybersecurity certification scheme at assurance level at least substantial. Standards alone do not make module A available.
Does every important product need the same external assessment?
No. Class I has the conditions in Article 32(2); Class II has separate options in Article 32(3). Critical products also require checking Article 8. Record the actual route and its basis for the product.