Conformity assessment

The process by which a manufacturer demonstrates that a product with digital elements satisfies the essential cybersecurity requirements of Annex I. Article 32 establishes four available procedures: Module A (self-assessment), Module B+C, Module H, and EUCC certification. The required procedure depends on the product classification and whether harmonised standards are fully applied.

Source citations

Regulation text

Article 3(27) of Regulation (EU) 2024/2847 defines conformity assessment as:

"the process demonstrating whether the essential cybersecurity requirements set out in Annex I of this Regulation relating to a product with digital elements have been fulfilled".

Article 32 sets out the available procedures.

Available procedures

Module A — Internal Production Control (self-assessment)

  • Manufacturer draws up technical documentation and EU DoC
  • No involvement of a notified body
  • Available to: all default products, and Class I important products where harmonised standards are fully applied

Module B + Module C — EU-Type Examination + Conformity to Type

  • Module B: Notified body examines technical documentation and tests a representative specimen
  • Module C: Manufacturer declares conformity to the examined type
  • Required for: Class I important products where harmonised standards are not fully applied; available for Class II

Module H — Full Quality Assurance

  • Notified body audits and approves the manufacturer's entire quality management system covering design, production, and testing
  • Available as an alternative to Module B+C for Class I and Class II products

EUCC — EU Cybersecurity Certification Scheme

  • Formal certification by an accredited conformity assessment body under Regulation (EU) 2019/881 (the Cybersecurity Act)
  • Required for: critical products (Annex IV) once relevant delegated act is in force; available as an alternative for important products

Decision tree summary

Product classificationStandards fully applied?Procedure
DefaultModule A
Important Class IYesModule A
Important Class INoModule B+C or Module H
Important Class IIEitherModule B+C, Module H, or EUCC
Critical (Annex IV)EitherEUCC (once delegated act) / Module B+C or H until then

Role of the notified body

For procedures requiring a notified body (Module B+C, Module H), the manufacturer must select a notified body designated for the relevant product category and submit the technical documentation for assessment before CE marking is affixed.

Conformity assessment — CRA Compliance Hub