Article 32 ยท Regulation (EU) 2024/2847

Which CRA conformity assessment route applies to my product?

Verified against the Official Journal text on

The route depends on your product's classification. Default products can self-assess using internal control (module A). Class I important products may self-assess only where they apply harmonised standards, common specifications, or an eligible certification in full; otherwise they take a notified-body route (module B plus C, or module H). Class II important products must use a notified-body route or certification, with no plain self-assessment. Critical products need a European cybersecurity certificate where the Commission requires one. Open-source manufacturers get relief, and SME fees must be reduced proportionately.

Basis: Art. 32(1)-(6)

Judgment call: Whether a product falls into a Class I, Class II, or critical category is a classification judgment that turns on core functionality and the technical descriptions in Implementing Regulation (EU) 2025/2392, not on the plain-language labels.

Default: self-assessment under internal control Art. 32(1), Annex VIII

For a product that is not an important or critical category, the manufacturer chooses freely among the procedures in Article 32(1): the internal control procedure (module A), EU-type examination (module B) followed by conformity to type (module C), full quality assurance (module H), or, where available and applicable, a European cybersecurity certification scheme. Internal control means you assess your own product and processes against the essential requirements and declare conformity on your own responsibility, without a notified body.

For most SMEs shipping ordinary software, this is the route, which makes compliance a documentation and process exercise you can run yourself rather than an external audit.

Class I: self-assessment only with standards applied in full Art. 32(2), Art. 7

An important product in Class I (Annex III) narrows the choice. You can still use internal control, but only where you have applied harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial" in full to the relevant essential requirements. Where you have not, or where such standards do not exist for the requirement in question, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both of which involve a notified body.

Class II and critical products Art. 32(3), Art. 32(4), Art. 8

A Class II important product removes plain self-assessment altogether. It must use EU-type examination plus conformity to type (modules B and C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least "substantial". There is no internal-control-only path for Class II.

Critical products (Annex IV) go a step further. Where the Commission has required a European cybersecurity certificate at assurance level at least "substantial" for the category (under Article 8(1)), that certificate is the route. Where those conditions are not met, the critical product falls back to the Class II procedures.

Open-source relief and SME fees Art. 32(5), Art. 32(6)

Two proportionality features matter here. First, a manufacturer of free and open-source software that falls under an Annex III category may demonstrate conformity using the ordinary Article 32(1) procedures (including internal control) despite the important-product listing, provided the technical documentation is made available to the public when the product is placed on the market. Second, the specific interests and needs of SMEs, including start-ups, must be taken into account when setting conformity assessment fees, and those fees must be reduced proportionately.

The modules behind the names Annex VIII

Annex VIII spells out the procedures the article refers to. Module A (internal control) is the self-assessment where you draw up the technical documentation, ensure compliance, affix the CE marking, and declare conformity. Module B (EU-type examination) is where a notified body examines your design and vulnerability handling and attests conformity; it is paired with module C (conformity to type). Module H (full quality assurance) is the notified-body route based on an approved quality system rather than examining a specimen.

What you must do

  • Perform the conformity assessment for your classification: internal control (module A) for default products, restricted for Class I, notified-body routes or certification for Class II and critical. (Art. 32(1)-(4))
  • For an open-source product in an Annex III category, you may use the Article 32(1) procedures if the technical documentation is made public at placing on the market. (Art. 32(5))

The dates that decide your planning

11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Can I self-certify my product under the CRA?

For a default (non-listed) product, yes: internal control (module A) is available and you declare conformity on your own responsibility. For important and critical products the self-assessment path is restricted or removed. (Art. 32(1), Art. 32(2), Art. 32(3))

What is a notified-body route?

A conformity assessment where an independent notified body is involved: either EU-type examination (module B) plus conformity to type (module C), or full quality assurance (module H). These apply to important and critical products and to Class I where standards are not applied in full. (Art. 32(2), Art. 32(3), Annex VIII)

What do critical products need?

A European cybersecurity certificate at assurance level at least "substantial" where the Commission has required one for the category under Article 8(1). Where those conditions are not met, the critical product uses the Class II procedures instead. (Art. 32(4), Art. 8)

Is there any help for small companies with the cost?

Yes. The specific interests and needs of microenterprises and SMEs, including start-ups, must be taken into account when conformity assessment fees are set, and those fees must be reduced proportionately. (Art. 32(6))

Which route is yours depends on classification

The free Vexwatch Scope Checker flags whether your product may be an important or critical category, which is what decides your conformity assessment route, before you commit to a path.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.