FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Module B+C

In what language can CRA Module B+C technical documentation and correspondence be submitted to the notified body?

They must be in an official language of the Member State where the notified body is established, or in another language acceptable to that body.

That rule applies to the technical documentation and correspondence relating to any CRA conformity assessment procedure, including Module B+C.

Citations
CRA Module B+C

Under CRA Module B+C, does every change after certification have to go back to the notified body?

No.

The legal trigger in Annex VIII Part II point 7 is any modification to the approved type or the vulnerability-handling processes that may affect conformity with Annex I or the conditions for validity of the certificate. Those changes require additional approval from the notified body in the form of an addition to the original certificate.

The practical split is evidence-based: changes that may affect Annex I conformity or certificate-validity conditions need notified-body approval; changes that do not affect those points should still be recorded internally so the manufacturer can explain why reassessment was not triggered.

Citations
Cyber Resilience Act

Defines which approved-type and vulnerability-handling-process changes require an addition to the original certificate.

CRA Module B+C

After a substantial modification, does the new CRA Module B+C assessment have to start from scratch for unchanged parts?

Not necessarily.

Not necessarily. For the CRA certificate, the notified-body trigger remains whether the modification to the approved type or vulnerability-handling processes may affect Annex I conformity or certificate-validity conditions.

The Blue Guide gives the product-law evidence principle for modified products: when a modified product is treated as new, technical documentation has to be updated only as far as the modification affects applicable requirements, and tests or documentation need not be repeated for aspects not impacted by the modification. In practice, a Module B+C reassessment file should identify the changed parts, explain why any unchanged parts are still covered by existing evidence, and submit the affected type or process changes for approval where Annex VIII point 7 is triggered.

Citations
Cyber Resilience Act

Requires additional notified-body approval when changes to the approved type or vulnerability-handling processes may affect conformity or certificate validity.

CRA Module B+C

Do the periodic audits under CRA Module B+C cover the whole production system in the same way as module H?

No.

Under Annex VIII Part II point 8, the periodic audit duty is specifically to ensure that the vulnerability-handling processes in Part II of Annex I are implemented adequately. Module C separately leaves production conformity control to the manufacturer. So this is narrower than a module H full-quality-assurance assessment.

Citations
Cyber Resilience Act

Limits Module B periodic audits to vulnerability-handling processes while Module C leaves production conformity control with the manufacturer.

CRA Module H

What is Module H under the CRA?

Module H is the conformity-assessment procedure based on full quality assurance.

Under this route, the manufacturer operates an approved quality system for design, development, final product inspection and testing, and vulnerability handling, and a notified body assesses and surveils that system.

Citations
Cyber Resilience Act

Article 32(1)(c) lists Module H as a CRA conformity-assessment route; Annex VIII Part IV explains the full-quality-assurance procedure.

CRA Module H

When can Module H be used?

Module H is available under Article 32(1) as one way to demonstrate CRA conformity for products with digital elements and the manufacturer's related processes.

It becomes one of the required third-party routes where Article 32(2) applies to an important class I product because harmonised standards, common specifications, or qualifying certification schemes are missing, unavailable, or only partly applied; where Article 32(3) applies to an important class II product; and where Article 32(4) applies to a critical product and the Article 8(1) certification route is not available.

Citations
Cyber Resilience Act

Article 32(1)-(4) sets the available and mandatory conformity-assessment routes for general, important, and critical products.

CRA Module H

Can a manufacturer choose Module H voluntarily?

Yes.

Where Article 32(1) is enough for the product, the manufacturer may choose Module H instead of Module A or Module B+C. That is a business and certification choice: it adds notified-body assessment and surveillance, but can support a broader approved quality-system route.

Citations
Cyber Resilience Act

Article 32(1) allows Module A, Module B+C, Module H, or an applicable European cybersecurity certification scheme where Article 32 does not require a stricter route.

CRA Module H

Does Module H cover one product, a product category, or both?

Module H can cover the products with digital elements, or product categories, included in the approved quality system.

It does not automatically cover the manufacturer's whole portfolio. The application and quality-system documentation need a defined scope, and new or substantially modified products need the quality system to be updated and reassessed before they are treated as covered.

Citations
Cyber Resilience Act

Annex VIII Part IV point 1 refers to the products or product categories concerned by the full-quality-assurance procedure.

European Commission CRA FAQs

Section 6.3 explains why Module H may suit manufacturers with numerous product types or frequent updates, while still requiring notified-body assessment.

CRA Module H

Does Module H always involve a notified body?

Yes.

The quality system must be assessed by a notified body, and the manufacturer remains under notified-body surveillance after approval.

Citations
Cyber Resilience Act

Annex VIII Part IV points 3 and 4 require notified-body assessment of the quality system and surveillance after approval.

CRA Module H

What does the approved quality system have to cover?

It must ensure compliance of the covered products with Part I of Annex I and compliance of the manufacturer's vulnerability-handling processes with Part II of Annex I.

It must also cover the relevant lifecycle controls, including design, development, production controls, final product inspection and testing, and vulnerability handling, and it must remain effective throughout the support period.

Citations
Cyber Resilience Act

Annex VIII Part IV points 1, 2, and 3.2 define the product, vulnerability-handling, lifecycle, and support-period coverage of the approved quality system.

CRA Module H

What has to be submitted in a Module H application?

The application to the notified body must include:

- the manufacturer details and, where relevant, the authorised representative's details

- the technical documentation for one model of each category of products intended to be manufactured or developed

- the quality-system documentation

- a declaration that the same application has not been lodged with any other notified body

Citations
Cyber Resilience Act

Annex VIII Part IV point 3.1 lists the required contents of a Module H application to the notified body.

CRA Module H

Does Module H still require technical documentation?

Yes.

Module H does not supersede the Article 31 and Annex VII documentation duties. The application must include technical documentation for one model of each covered product category, and the Commission FAQ notes that, where a quality-system route is used, the technical documentation may form part of the quality-system documentation.

Citations
Cyber Resilience Act

Article 31 and Annex VII set the technical-documentation duty; Annex VIII Part IV point 3.1(b) requires technical documentation in the Module H application.

European Commission CRA FAQs

Section 4.1.8 states that technical documentation is required regardless of the conformity-assessment route and may be part of quality-system documentation for Module H.

CRA Module H

What has to be in the quality-system documentation?

The quality-system documentation must systematically describe, among other things:

- quality objectives and management responsibilities

- the standards and specifications to be applied

- the means used where relevant harmonised standards or technical specifications are not applied in full

- design and development controls and verification techniques

- production, quality-control, and quality-assurance techniques

- examinations and tests and how often they are carried out

- quality records

- how the manufacturer monitors the effective operation of the quality system

Citations
Cyber Resilience Act

Annex VIII Part IV point 3.2 lists the quality-system documentation elements needed for Module H approval.

CRA Module H

Does Module H distinguish between product requirements and vulnerability-handling process requirements?

Yes.

Annex VIII Part IV point 3.2 distinguishes between the technical design and development specifications relevant to Part I of Annex I and the procedural specifications relevant to Part II of Annex I. In practice, Module H covers both product compliance and the manufacturer's vulnerability-handling processes.

Citations
Cyber Resilience Act

Annex VIII Part IV point 3.2 separately addresses technical design and development specifications for products and procedural specifications for manufacturer processes.

CRA Module H

How does the notified body assess a Module H quality system?

The notified body assesses whether the quality system satisfies the CRA requirements in Annex VIII Part IV point 3.2.

The audit team must include at least one member experienced in the relevant product field and technology, and the audit must include an assessment visit to the manufacturer's premises where such premises exist. The audit team also reviews the submitted technical documentation to verify the manufacturer's ability to identify the applicable CRA requirements and carry out the necessary examinations.

Citations
Cyber Resilience Act

Annex VIII Part IV point 3.3 defines the notified body's quality-system assessment, audit-team competence, site visit, and technical-documentation review.

Page 26 of 58