FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Market Surveillance and Enforcement

Can ADCO trigger a Union-wide dependency assessment that leads to SBOM requests?

Yes.

Article 13(25) allows ADCO to decide to conduct a Union-wide dependency assessment for specific categories of products with digital elements. For that purpose, market-surveillance authorities may request manufacturers of those categories to provide the relevant SBOMs. The authorities may then provide ADCO only anonymised and aggregated information about software dependencies.

Citations
Cyber Resilience Act

Article 13(25) allows ADCO dependency assessments and SBOM requests for specific product categories.

CRA Market Surveillance and Enforcement

Can CRA market-surveillance authorities formally cooperate with researchers, scientific bodies, or consumer organisations?

Yes.

Article 52(12) requires market-surveillance authorities to support, where relevant, cooperation with stakeholders, including scientific, research, and consumer organisations.

Citations
Cyber Resilience Act

Article 52(12) requires relevant stakeholder cooperation, including scientific, research, and consumer organisations.

CRA Module B+C

What is Module B+C under the Cyber Resilience Act?

Module B+C is a two-step conformity-assessment route.

Module B is EU-type examination by a notified body. Module C is conformity to the approved type based on the manufacturer's internal production control. Together, they cover both the examination of the product type and the manufacturer's obligation to keep actual production in line with that approved type.

Citations
Cyber Resilience Act

Identifies Module B+C as EU-type examination followed by conformity to EU-type based on internal production control.

European Commission CRA FAQs

Explains the practical distinction between the notified-body examination step and the manufacturer's production-control step.

CRA Module B+C

When is Module B+C mandatory under the Cyber Resilience Act?

Module B+C is one of the mandatory third-party routes for:

- important products of class I where Article 32(2) requires third-party assessment for the relevant requirements

- important products of class II, such as hypervisors and container runtime systems, firewalls, intrusion detection and prevention systems, and tamper-resistant microprocessors or microcontrollers

- critical products listed in Annex IV, unless the applicable certification route under Article 8(1) applies

Citations
Cyber Resilience Act

Sets when class I, class II, and critical products must use Module B+C, Module H, or an applicable cybersecurity certification route.

CRA Module B+C

Can a manufacturer also choose Module B+C voluntarily under the Cyber Resilience Act?

Yes.

Article 32(1) allows manufacturers to use Module B+C for products generally covered by paragraph 1, even where module A would also be available.

Citations
Cyber Resilience Act

Allows manufacturers to choose Module B+C among the general Article 32(1) conformity assessment procedures.

European Commission CRA FAQs

Distinguishes voluntary use of a notified-body route from the default internal-control route where third-party assessment is not required.

CRA Module B+C

Does Module B+C always involve a notified body under the Cyber Resilience Act?

Yes.

Module B is the notified-body part of the route. Module C then follows with the manufacturer's own internal production control against the approved type.

Citations
Cyber Resilience Act

Module B is performed by a notified body; Module C is the manufacturer's internal production-control step.

CRA Module B+C

How many notified bodies can be involved in one CRA module B application?

Only one.

The manufacturer must lodge the EU-type examination application with a single notified body of its choice and must declare that the same application has not been lodged with any other notified body.

Citations
Cyber Resilience Act

Requires the Module B application to go to one notified body and include a declaration that no duplicate application was lodged elsewhere.

CRA Module B+C

What does the manufacturer have to submit for CRA module B?

The application must include:

- the manufacturer details and, where relevant, the authorised representative's details

- a declaration that the same application has not been lodged with another notified body

- technical documentation that allows conformity to be assessed, including an adequate analysis and assessment of the risks

- supporting evidence for the adequacy of the technical design, development solutions, and vulnerability-handling processes

Where necessary, the supporting evidence must include test results from the manufacturer's own laboratory or another testing laboratory acting on its behalf and under its responsibility.

Citations
Cyber Resilience Act

Lists the manufacturer details, non-duplicate-application declaration, technical documentation, risk analysis, supporting evidence, and test evidence required for Module B.

CRA Module B+C

Does CRA module B cover only the product's technical design, or also vulnerability handling?

It covers both.

EU-type examination is not limited to the product's technical design and development. The notified body also examines the vulnerability-handling processes put in place by the manufacturer against Part II of Annex I.

Citations
Cyber Resilience Act

Shows that EU-type examination covers both the product's technical design and the manufacturer's vulnerability-handling processes.

CRA Module B+C

Does the CRA notified body assess only documents, or also specimens and tests?

It assesses both.

Annex VIII Part II requires examination of the technical documentation and supporting evidence, plus examination of specimens of one or more critical parts of the product. The notified body must also carry out appropriate examinations and tests, or have them carried out.

Citations
Cyber Resilience Act

Requires the notified body to examine documentation, supporting evidence, specimens of critical parts, and appropriate examinations or tests.

CRA Module B+C

What exactly does the notified body check during CRA module B?

The notified body checks:

- whether the technical documentation and supporting evidence are adequate

- whether the examined specimens match the documentation

- which elements were designed and developed using relevant harmonised standards or technical specifications and which were not

- whether the manufacturer's chosen solutions satisfy the applicable essential cybersecurity requirements

Citations
Cyber Resilience Act

Sets the notified body's checks on documentation, specimens, harmonised-standard use, and alternative solutions.

CRA Module B+C

Can CRA module B tests be carried out at the manufacturer's site or elsewhere?

Yes.

Annex VIII Part II point 4.5 says the notified body and the manufacturer agree on the location where the examinations and tests will be carried out.

Citations
Cyber Resilience Act

Allows the manufacturer and notified body to agree where Module B examinations and tests are performed.

CRA Module B+C

What does the manufacturer receive if CRA module B is successful?

The manufacturer receives an EU-type examination certificate.

The certificate identifies the approved type and the vulnerability-handling processes, and it records the conclusions of the examination and any validity conditions.

Citations
Cyber Resilience Act

Defines the EU-type examination certificate contents when the type and vulnerability-handling processes meet Annex I.

CRA Module B+C

What happens under CRA Module B+C if the notified body concludes that the type or vulnerability-handling processes do not comply?

It must refuse to issue the EU-type examination certificate and give detailed reasons for the refusal. Annex VIII frames that refusal around both the type and the vulnerability-handling processes, so a process failure can block the certificate even if the product design evidence is otherwise strong.

Citations
Cyber Resilience Act

Requires refusal and detailed reasons when the type or vulnerability-handling processes do not satisfy the applicable requirements.

CRA Module B+C

Under CRA Module B+C, does the EU-type examination certificate approve only the type or also vulnerability-handling processes?

It covers both.

Annex VIII Part II point 6 ties the certificate to both the approved type and the examined vulnerability-handling processes. That is why later modifications to either can matter for certificate validity.

Citations
Cyber Resilience Act

Ties the certificate to both the approved type and the examined vulnerability-handling processes.

Page 24 of 58