What conformity assessment routes does the CRA recognise?
The CRA recognises four ways to demonstrate conformity with the essential cybersecurity requirements:
- internal control based on
- EU-type examination based on module B followed by conformity to EU-type based on module C
- full quality assurance based on
- where available and applicable, a European cybersecurity certification scheme specified under Article 27(9)
A cybersecurity certificate is not automatically a CRA conformity route. The relevant certification scheme must be specified for CRA purposes under Article 27(9), cover the applicable requirements or assurance conditions, and be available for the product category.
Article 32(1) lists the available CRA conformity assessment procedures; Annex VIII defines modules A, B, C, and H.
Section 6 summarises the CRA conformity assessment routes and their relative complexity and external involvement.