What conformity assessment routes does the CRA recognise?
The CRA recognises four ways to demonstrate conformity with the essential cybersecurity requirements:
- internal control based on module A
- EU-type examination based on module B followed by conformity to EU-type based on module C
- full quality assurance based on module H
- where available and applicable, a European cybersecurity certification scheme specified under Article 27(9)
Article 32(1) lists the available CRA conformity assessment procedures; Annex VIII defines modules A, B, C, and H.
Section 6 summarises the CRA conformity assessment routes and their relative complexity and external involvement.